> ## Documentation Index > Fetch the complete documentation index at: https://openrouter.ai/docs/llms.txt > Use this file to discover all available pages before exploring further. # CreateBYOKKeyRequest ## Fields | Field | Type | Required | Description | Example | | --------------------- | --------------------------------------------------------------------------- | -------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------- | | `AllowedAPIKeyHashes` | optionalnullable.OptionalNullable\[\[]`string`] | :heavy\_minus\_sign: | Optional allowlist of OpenRouter API key hashes (`api_keys.hash`) that may use this credential. `null` means no restriction. Must contain at least one hash if provided. Hashes that do not belong to your account return a 400. | \[
"f01d52606dc8f0a8303a7b5cc3fa07109c2e346cec7c0a16b40de462992ce943"
] | | `AllowedModels` | optionalnullable.OptionalNullable\[\[]`string`] | :heavy\_minus\_sign: | Optional allowlist of model slugs this credential may be used for. `null` means no restriction. | null | | `AllowedUserIds` | optionalnullable.OptionalNullable\[\[]`string`] | :heavy\_minus\_sign: | Optional allowlist of user IDs that may use this credential. `null` means no restriction. | null | | `Disabled` | `*bool` | :heavy\_minus\_sign: | Whether this credential should be created in a disabled state. | false | | `IsBYOKOnly` | `*bool` | :heavy\_minus\_sign: | Whether OpenRouter's shared endpoints on this provider are removed for every model, including models outside `allowed_models` and after all of your keys for the provider fail. The provider is skipped instead of spending OpenRouter credits. Only valid on non-fallback credentials. Defaults to `false`. | false | | `IsFallback` | `*bool` | :heavy\_minus\_sign: | Whether this credential is treated as a fallback — used only after non-fallback keys for the same provider have been tried. Cannot be combined with `is_byok_only`. | false | | `IsRequired` | `*bool` | :heavy\_minus\_sign: | Whether OpenRouter's shared endpoints on this provider are removed for the models this credential applies to (its `allowed_models`, or every model when `null`). Requests for those models run only on your keys; models outside the allowlist may still fall back to shared capacity on this provider. Defaults to `false`. | false | | `Key` | `string` | :heavy\_check\_mark: | The raw provider API key or credential. This value is encrypted at rest and never returned in API responses. | sk-proj-abc123... | | `Name` | optionalnullable.OptionalNullable\[`string`] | :heavy\_minus\_sign: | Optional human-readable name for the credential. | Production OpenAI Key | | `Provider` | [components.BYOKProviderSlug](../../models/components/byokproviderslug.mdx) | :heavy\_check\_mark: | The upstream provider this credential authenticates against, as a lowercase slug (e.g. `openai`, `anthropic`, `amazon-bedrock`). | openai | | `WorkspaceID` | `*string` | :heavy\_minus\_sign: | Optional workspace ID to scope the credential to. When omitted, the credential is created in the account's default workspace; if that default has been deleted, the request returns a 400 and you must pass `workspace_id` explicitly. | 550e8400-e29b-41d4-a716-446655440000 |