> ## Documentation Index > Fetch the complete documentation index at: https://openrouter.ai/docs/llms.txt > Use this file to discover all available pages before exploring further. # BYOKKey ## Example Usage ```typescript theme={null} import { BYOKKey } from "@openrouter/sdk/models"; let value: BYOKKey = { allowedApiKeyHashes: null, allowedModels: null, allowedUserIds: null, createdAt: "2025-08-24T10:30:00Z", disabled: false, id: "11111111-2222-3333-4444-555555555555", isByokOnly: false, isFallback: false, isRequired: false, label: "sk-...AbCd", provider: "openai", sortOrder: 0, workspaceId: "550e8400-e29b-41d4-a716-446655440000", }; ``` ## Fields | Field | Type | Required | Description | Example | | --------------------- | --------------------------------------------------------- | -------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------- | | `allowedApiKeyHashes` | *string*\[] | :heavy\_check\_mark: | Optional allowlist of OpenRouter API key hashes (`api_keys.hash`) that may use this credential. `null` means no restriction. | \[
"f01d52606dc8f0a8303a7b5cc3fa07109c2e346cec7c0a16b40de462992ce943"
] | | `allowedModels` | *string*\[] | :heavy\_check\_mark: | Optional allowlist of model slugs this credential may be used for. `null` means no restriction. | null | | `allowedUserIds` | *string*\[] | :heavy\_check\_mark: | Optional allowlist of user IDs that may use this credential. `null` means no restriction. | null | | `createdAt` | *string* | :heavy\_check\_mark: | ISO timestamp of when the credential was created. | 2025-08-24T10:30:00Z | | `disabled` | *boolean* | :heavy\_check\_mark: | Whether this credential is currently disabled. | false | | `id` | *string* | :heavy\_check\_mark: | Stable public identifier for this BYOK credential. | 11111111-2222-3333-4444-555555555555 | | `isByokOnly` | *boolean* | :heavy\_check\_mark: | Whether OpenRouter's shared endpoints on this provider are removed for every model, including models outside `allowed_models` and after all of your keys for the provider fail. The provider is skipped instead of spending OpenRouter credits. Only valid on non-fallback credentials. | false | | `isFallback` | *boolean* | :heavy\_check\_mark: | Whether this credential is treated as a fallback — used only after non-fallback keys for the same provider have been tried. Cannot be combined with `is_byok_only`. | false | | `isRequired` | *boolean* | :heavy\_check\_mark: | Whether OpenRouter's shared endpoints on this provider are removed for the models this credential applies to (its `allowed_models`, or every model when `null`). Requests for those models run only on your keys; models outside the allowlist may still fall back to shared capacity on this provider. | false | | `label` | *string* | :heavy\_check\_mark: | Short masked snippet of the key (e.g. the first/last few characters) used to identify it in the UI. | sk-...AbCd | | `name` | *string* | :heavy\_minus\_sign: | Optional human-readable name for the credential. | Production OpenAI Key | | `provider` | [models.BYOKProviderSlug](../models/byokproviderslug.mdx) | :heavy\_check\_mark: | The upstream provider this credential authenticates against, as a lowercase slug (e.g. `openai`, `anthropic`, `amazon-bedrock`). | openai | | `sortOrder` | *number* | :heavy\_check\_mark: | Position within the provider — credentials are tried in ascending sort order. | 0 | | `workspaceId` | *string* | :heavy\_check\_mark: | The workspace this credential is scoped to, or `null` when it is global — usable across every workspace in the account. A `null` value does not mean the default workspace. | 550e8400-e29b-41d4-a716-446655440000 |