REST APIProviders

Get provider

Get a provider.

GET/v1/providers/:id

Overview

A provider stores the API key your agents use to call a model vendor such as OpenRouter. Blazing Agents encrypts the key and never returns it. List a provider's models to pick an ID for your agent; listing makes no model call, and the same list checks the model whenever you configure an agent.

List a model's thinking levels to see which thinkingLevel values an agent can use with it. known: false means the capabilities could not be looked up; a known empty list means only the provider's default is available. See Thinking level for how levels are chosen.

Endpoints

List providersGET/v1/providers

List providers.

Lists your tenant's providers, most recently updated first. Items leave out the base URL and key fragment; get a single provider to see them.

Request

Requires bearer authentication.

There are no parameters and no request body.

Response

The provider.

Providerobjectrequired

The provider.

Returns 200 OK as application/json. Your tenant's providers.

Response schema: ProviderList.

{
  "providers": [
    {
      "id": "prv_7Tn4Kd9QwE2sLx5R",
      "name": "Production OpenRouter",
      "providerType": "openrouter",
      "createdAt": "2026-07-10T10:00:00.000Z",
      "updatedAt": "2026-07-10T10:00:00.000Z"
    }
  ]
}

Errors

StatusCodesDescription
401unauthorizedThe credential is missing or invalid
402subscription_requiredAn active subscription or usage credit is required

See REST errors for the error envelope and shared codes.

cURL

curl "$BLAZING_AGENTS_BASE_URL/v1/providers" \
  --header "Authorization: Bearer $BLAZING_AGENTS_API_KEY"

Create providerPOST/v1/providers

Create a provider.

Stores a model vendor API key for your agents to use. Names are unique within your tenant, and your tenant can hold up to 20 providers. The key is never returned; only its last characters appear as keyFragment. Send baseUrl for a custom provider, and leave it out for vercel_ai_gateway. Only the name can change later, so create a new provider to change the type, key, or base URL.

Request

Requires bearer authentication and a JSON body.

FieldTypeLocationRequiredDescription
namestringbodyrequiredDisplay name, unique within your tenant. 1–80 characters.
providerTypestringbodyrequiredThe model vendor. Cannot be changed later. One of openai, anthropic, openrouter, google, vercel_ai_gateway, custom.
baseUrlstring | nullbodyEndpoint override. Required for custom, not accepted for vercel_ai_gateway, and optional otherwise. Cannot be changed later. Defaults to null.
apiKeystringbodyrequiredThe vendor API key. It is stored encrypted, never returned, and cannot be changed later.

Response

The provider.

Providerobjectrequired

The provider.

Returns 201 Created as application/json. The created provider.

Response schema: Provider.

{
  "id": "prv_7Tn4Kd9QwE2sLx5R",
  "name": "Production OpenRouter",
  "providerType": "openrouter",
  "baseUrl": null,
  "keyFragment": "9f2c",
  "createdAt": "2026-07-10T10:00:00.000Z",
  "updatedAt": "2026-07-10T10:00:00.000Z"
}

Errors

StatusCodesDescription
400validation_failed, invalid_request, provider_limit_reachedThe request is invalid
401unauthorizedThe credential is missing or invalid
402subscription_requiredAn active subscription or usage credit is required
409provider_name_conflictThe request conflicts with the resource's current state

See REST errors for the error envelope and shared codes.

cURL

curl --request POST "$BLAZING_AGENTS_BASE_URL/v1/providers" \
  --header "Authorization: Bearer $BLAZING_AGENTS_API_KEY" \
  --header "Content-Type: application/json" \
  --data '{"name":"Production OpenRouter","providerType":"openrouter","baseUrl":null,"apiKey":"sk-or-v1-3b7e...9f2c"}'

List provider modelsGET/v1/providers/:id/models

List a provider's models.

Lists the model IDs the provider offers right now, trimmed, deduplicated, and sorted. Listing makes no model call. Vercel AI Gateway uses its public catalog without your key, so a listed model does not prove your key can use it. Custom providers do not support listing. Creating or updating an agent checks its model against this same list.

Request

Requires bearer authentication.

FieldTypeLocationRequiredDescription
idstringpathrequiredID of the provider.

Response

The provider.

Providerobjectrequired

The provider.

Returns 200 OK as application/json. The provider's model IDs.

Response schema: ProviderModelList.

{
  "models": [
    {
      "id": "openai/gpt-6-luna"
    }
  ]
}

Errors

StatusCodesDescription
400validation_failedThe request is invalid
401unauthorizedThe credential is missing or invalid
402subscription_requiredAn active subscription or usage credit is required
404provider_not_foundThe resource was not found
422model_discovery_unsupportedThe request was understood but rejected
503model_validation_unavailableThe service is temporarily unavailable

See REST errors for the error envelope and shared codes.

cURL

curl "$BLAZING_AGENTS_BASE_URL/v1/providers/prv_1234567890ABCDEF/models" \
  --header "Authorization: Bearer $BLAZING_AGENTS_API_KEY"

List thinking levelsGET/v1/providers/:id/thinking-levels

List a model's thinking levels.

Lists the thinking levels a model supports on this provider. It works for model IDs you typed yourself and for custom providers. known is false, with no levels, when the model's capabilities cannot be looked up. A known empty list means only the provider's default is available.

Request

Requires bearer authentication.

FieldTypeLocationRequiredDescription
idstringpathrequiredID of the provider.
modelstringqueryrequiredThe provider's own model ID.

Response

The provider.

Providerobjectrequired

The provider.

Returns 200 OK as application/json. The model's supported thinking levels.

Response schema: ProviderThinkingLevels.

{
  "known": true,
  "levels": [
    "off",
    "low",
    "medium",
    "high"
  ]
}

Errors

StatusCodesDescription
400validation_failedThe request is invalid
401unauthorizedThe credential is missing or invalid
402subscription_requiredAn active subscription or usage credit is required
404provider_not_foundThe resource was not found

See REST errors for the error envelope and shared codes.

cURL

curl "$BLAZING_AGENTS_BASE_URL/v1/providers/prv_1234567890ABCDEF/thinking-levels?model=openai%2Fgpt-6-luna" \
  --header "Authorization: Bearer $BLAZING_AGENTS_API_KEY"

Get providerGET/v1/providers/:id

Get a provider.

Returns a provider, including its base URL and keyFragment, the last characters of its key. The key itself is never returned.

Request

Requires bearer authentication.

FieldTypeLocationRequiredDescription
idstringpathrequiredID of the provider.

Response

The provider.

Providerobjectrequired

The provider.

Returns 200 OK as application/json. The provider.

Response schema: Provider.

{
  "id": "prv_7Tn4Kd9QwE2sLx5R",
  "name": "Production OpenRouter",
  "providerType": "openrouter",
  "baseUrl": null,
  "keyFragment": "9f2c",
  "createdAt": "2026-07-10T10:00:00.000Z",
  "updatedAt": "2026-07-10T10:00:00.000Z"
}

Errors

StatusCodesDescription
400validation_failedThe request is invalid
401unauthorizedThe credential is missing or invalid
402subscription_requiredAn active subscription or usage credit is required
404provider_not_foundThe resource was not found

See REST errors for the error envelope and shared codes.

cURL

curl "$BLAZING_AGENTS_BASE_URL/v1/providers/prv_1234567890ABCDEF" \
  --header "Authorization: Bearer $BLAZING_AGENTS_API_KEY"

Update providerPATCH/v1/providers/:id

Rename a provider.

Renames a provider. Only name can change. To rotate a key or change the type or base URL, create a new provider, point your agents at it, then delete the old one.

Request

Requires bearer authentication and a JSON body.

FieldTypeLocationRequiredDescription
idstringpathrequiredID of the provider.
namestringbodyrequiredNew display name, unique within your tenant. 1–80 characters.

Response

The provider.

Providerobjectrequired

The provider.

Returns 200 OK as application/json. The renamed provider.

Response schema: Provider.

{
  "id": "prv_7Tn4Kd9QwE2sLx5R",
  "name": "Primary OpenRouter",
  "providerType": "openrouter",
  "baseUrl": null,
  "keyFragment": "9f2c",
  "createdAt": "2026-07-10T10:00:00.000Z",
  "updatedAt": "2026-07-10T10:05:00.000Z"
}

Errors

StatusCodesDescription
400validation_failed, invalid_requestThe request is invalid
401unauthorizedThe credential is missing or invalid
402subscription_requiredAn active subscription or usage credit is required
404provider_not_foundThe resource was not found
409provider_name_conflictThe request conflicts with the resource's current state

See REST errors for the error envelope and shared codes.

cURL

curl --request PATCH "$BLAZING_AGENTS_BASE_URL/v1/providers/prv_1234567890ABCDEF" \
  --header "Authorization: Bearer $BLAZING_AGENTS_API_KEY" \
  --header "Content-Type: application/json" \
  --data '{"name":"Primary OpenRouter"}'

Delete providerDELETE/v1/providers/:id

Delete a provider.

Deletes a provider and its key. While a current agent uses the provider, deletion fails with provider_in_use and the agent IDs in details.agentIds; point those agents at another provider first. When only older agent versions, pinned sessions, or tasks use it, deletion fails with provider_historical_use and their IDs in details, unless you send confirmVersionInvalidation=true.

Request

Requires bearer authentication.

FieldTypeLocationRequiredDescription
idstringpathrequiredID of the provider.
confirmVersionInvalidationstringquerytrue confirms that pinned sessions, tasks, and version restores that use this provider may stop working. It never overrides use by a current agent. One of true, false. Defaults to false.

Response

The provider.

Providerobjectrequired

The provider.

Returns 204 No Content. The provider was deleted.

Errors

StatusCodesDescription
400validation_failedThe request is invalid
401unauthorizedThe credential is missing or invalid
402subscription_requiredAn active subscription or usage credit is required
404provider_not_foundThe resource was not found
409provider_in_use, provider_historical_useThe request conflicts with the resource's current state

See REST errors for the error envelope and shared codes.

cURL

curl --request DELETE "$BLAZING_AGENTS_BASE_URL/v1/providers/prv_1234567890ABCDEF" \
  --header "Authorization: Bearer $BLAZING_AGENTS_API_KEY"

Next