> ## Documentation Index
> Fetch the complete documentation index at: https://docs.endorlabs.com/llms.txt
> Use this file to discover all available pages before exploring further.

# CreateAIProviderKey

> Creates a new AI provider key in the root namespace of a tenant. The
credential is validated, encrypted with a server-side key and stored;
read APIs never return it.



## OpenAPI

````yaml /api-reference/openapi.v3.json post /v1/namespaces/{tenant_meta.namespace}/ai-provider-keys
openapi: 3.0.3
info:
  description: Integrate your application with Endor Labs using the REST API.
  title: Endor Labs REST API Reference
  version: '1.0'
servers:
  - description: US (default)
    url: https://api.endorlabs.com
  - description: EU (data residency)
    url: https://api.eu.endorlabs.com
security: []
tags:
  - name: AIProviderKeyService
  - name: AISastCustomerContextService
  - name: APIKeyService
  - name: APIKeyValidatorService
  - name: AgentTelemetryService
  - name: ArtifactSignatureService
  - name: AsyncJobService
  - name: AuditLogService
  - name: AuthenticationLogService
  - name: AuthenticationService
  - name: AuthorizationPolicyService
  - name: BatchFileSegmentsService
  - name: BatchNotificationService
  - name: CallGraphDataService
  - name: CodeOwnersService
  - name: DependencyMetadataService
  - name: EndorIgnoreEntryService
  - name: ExporterService
  - name: FindingLogService
  - name: FindingService
  - name: HuggingFaceModelService
  - name: HuggingFaceOrganizationService
  - name: IPAddressPolicyService
  - name: IdentityProviderService
  - name: InstallationService
  - name: InvitationService
  - name: LicenseDependencyService
  - name: LicenseNoticesReportService
  - name: LicenseSummaryService
  - name: LinterResultService
  - name: MalwareExposureQueryService
  - name: MalwareExposureService
  - name: MalwareService
  - name: MetricService
  - name: NamespaceService
  - name: NotificationService
  - name: NotificationTargetService
  - name: OnPremSchedulerService
  - name: PRCommentConfigService
  - name: PackageFirewallLogService
  - name: PackageLicenseOverrideService
  - name: PackageLicenseQueryService
  - name: PackageLicenseService
  - name: PackageManagerService
  - name: PackageVersionService
  - name: PluginBinaryService
  - name: PolicyService
  - name: PolicyTemplateService
  - name: ProjectService
  - name: ProvisioningResultService
  - name: QueryMalwareService
  - name: QueryService
  - name: QuerySimilarPackagesService
  - name: QueryVulnerabilityService
  - name: RegistryIngestionCheckpointService
  - name: RepositoryService
  - name: RepositoryVersionService
  - name: RuleSetImportService
  - name: SBOMExportService
  - name: SBOMImportService
  - name: SCMCredentialService
  - name: SavedQueryService
  - name: ScanCreditUsageService
  - name: ScanLogRequestService
  - name: ScanProfileService
  - name: ScanResultService
  - name: ScanWorkflowResultService
  - name: ScanWorkflowService
  - name: SecretRuleService
  - name: SemgrepRuleService
  - name: SystemConfigService
  - name: TenantService
  - name: VEXExportService
  - name: VectorStoreService
  - name: VersionUpgradeService
  - name: VulnerabilityService
paths:
  /v1/namespaces/{tenant_meta.namespace}/ai-provider-keys:
    post:
      tags:
        - AIProviderKeyService
      summary: CreateAIProviderKey
      description: |-
        Creates a new AI provider key in the root namespace of a tenant. The
        credential is validated, encrypted with a server-side key and stored;
        read APIs never return it.
      operationId: AIProviderKeyService_CreateAIProviderKey
      parameters:
        - description: >-
            Namespaces are a way to organize organizational units into virtual

            groupings of resources. Namespaces must be a fully qualified name,

            for example, the child namespace of namespace "endor.prod" called
            "app"

            is called "endor.prod.app".
          in: path
          name: tenant_meta.namespace
          required: true
          schema:
            type: string
          x-endor-name: Namespace
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AIProviderKeyServiceCreateAIProviderKeyBody'
        required: true
        x-originalParamName: body
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v1AIProviderKey'
          description: A successful response.
        default:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/googlerpcStatus'
          description: An unexpected error response.
components:
  schemas:
    AIProviderKeyServiceCreateAIProviderKeyBody:
      description: |-
        AIProviderKey stores a customer-provided (bring-your-own-key) LLM
        credential and entry point for a specific AI provider. When one is
        configured and enabled, the platform routes the tenant's AI requests
        through the customer's own provider account instead of Endor-managed
        credentials.
      properties:
        meta:
          $ref: '#/components/schemas/v1Meta'
        spec:
          $ref: '#/components/schemas/v1AIProviderKeySpec'
        tenant_meta:
          description: The tenant metadata restricts access to a specific tenant.
          title: The tenant metadata restricts access to a specific tenant.
          type: object
        uuid:
          description: The UUID of the AI provider key.
          readOnly: true
          type: string
      required:
        - tenant_meta
        - meta
      type: object
    v1AIProviderKey:
      description: |-
        AIProviderKey stores a customer-provided (bring-your-own-key) LLM
        credential and entry point for a specific AI provider. When one is
        configured and enabled, the platform routes the tenant's AI requests
        through the customer's own provider account instead of Endor-managed
        credentials.
      properties:
        meta:
          $ref: '#/components/schemas/v1Meta'
        spec:
          $ref: '#/components/schemas/v1AIProviderKeySpec'
        tenant_meta:
          $ref: '#/components/schemas/v1TenantMeta'
        uuid:
          description: The UUID of the AI provider key.
          readOnly: true
          type: string
      required:
        - tenant_meta
        - meta
      type: object
    googlerpcStatus:
      description: >-
        The `Status` type defines a logical error model that is suitable for

        different programming environments, including REST APIs and RPC APIs. It
        is

        used by [gRPC](https://github.com/grpc). Each `Status` message contains

        three pieces of data: error code, error message, and error details.


        You can find out more about this error model and how to work with it in
        the

        [API Design Guide](https://cloud.google.com/apis/design/errors).
      properties:
        code:
          description: |-
            The status code, which should be an enum value of
            [google.rpc.Code][google.rpc.Code].
          format: int32
          type: integer
        details:
          description: >-
            A list of messages that carry the error details.  There is a common
            set of

            message types for APIs to use.
          items:
            $ref: '#/components/schemas/googleprotobufAny'
          type: array
        message:
          description: >-
            A developer-facing error message, which should be in English. Any

            user-facing error message should be localized and sent in the

            [google.rpc.Status.details][google.rpc.Status.details] field, or
            localized

            by the client.
          type: string
      type: object
    v1Meta:
      description: Common fields for all Endor Labs resources.
      properties:
        annotations:
          additionalProperties:
            type: string
          description: >-
            Annotations can be used to attach metadata to a resource message.

            Annotation values can be small or large, structured or unstructured,

            and may include characters not permitted by labels.

            The keys may contain alphanumerics, underscores (_), dots (.) and
            dashes

            (-). The values of an annotation must be 16384 bytes or smaller.
          type: object
        create_time:
          description: |-
            Time the resource was created.

            Format: 2017-01-15T01:30:15.01Z
            RFC 3339: https://www.ietf.org/rfc/rfc3339.txt.
          format: date-time
          readOnly: true
          type: string
        created_by:
          description: |-
            Name and authentication source of the user who created the object,
            for example, ewok@endor.ai@google@api-key.
          readOnly: true
          type: string
        description:
          description: Resource description. Must be less than 1024 bytes.
          type: string
        index_data:
          $ref: '#/components/schemas/v1IndexData'
        kind:
          description: >-
            Resource kind, for example, HelloResponse.

            Auto-generated using the protobuf message
            proto.MessageName().Name().
          readOnly: true
          type: string
        name:
          description: Resource name. Must be 63 characters or less.
          type: string
        parent_kind:
          description: Parent object resource kind, for example, Project.
          type: string
        parent_uuid:
          description: Parent object UUID.
          type: string
        references:
          additionalProperties:
            $ref: '#/components/schemas/googleprotobufAny'
          description: Map of objects referenced in a query API.
          readOnly: true
          type: object
        tags:
          description: >-
            List of tags attached to the resource.

            Tags can be used to select objects and to find collections of
            objects that

            satisfy certain conditions. A tag must be 255 characters or less.
          items:
            type: string
          type: array
        update_time:
          description: |-
            Time the resource was last updated.
            Note: Updated on all create/patch/delete operations.

            Format: 2017-01-15T01:30:15.01Z
            RFC 3339: https://www.ietf.org/rfc/rfc3339.txt.
          format: date-time
          readOnly: true
          type: string
        updated_by:
          description: >-
            Name and authentication source of the last user who updated the
            object,

            for example, vulnerabilityingestor@endor.ai@x509.
          readOnly: true
          type: string
        upsert_time:
          description: |-
            Time the resource was last upserted.

            Note:
            create_time is only set the first time the resource is created.
            upsert_time is set every time the resource is upseted.

            Format: 2017-01-15T01:30:15.01Z
            RFC 3339: https://www.ietf.org/rfc/rfc3339.txt.
          format: date-time
          readOnly: true
          type: string
        version:
          description: Message version.
          readOnly: true
          type: string
      required:
        - name
      type: object
    v1AIProviderKeySpec:
      properties:
        api_key:
          description: >-
            Credential used to call the provider: an API key for OpenAI-family
            and

            Gemini providers, or an express-mode API key for Vertex AI. Stored
            in

            the platform secret manager (secure annotation); read APIs return
            the

            redacted placeholder rather than the stored value.
          type: string
        api_version:
          description: |-
            Azure OpenAI api-version query parameter to use. Defaults to the
            platform's version when unset; only meaningful for
            PROVIDER_AZURE_OPENAI.
          type: string
        disabled:
          description: Pauses routing through this credential without deleting it.
          type: boolean
        endpoint:
          description: >-
            Entry point requests are sent to. Required for PROVIDER_AZURE_OPENAI

            (the Azure resource endpoint, e.g.
            https://<resource>.openai.azure.com),

            optional for PROVIDER_OPENAI (defaults to the OpenAI platform; set
            it

            to target an OpenAI-compatible gateway), optional for

            PROVIDER_VERTEX_AI (defaults to the global endpoint; set a regional

            endpoint, e.g. https://us-central1-aiplatform.googleapis.com, to pin
            a

            region) and unused for PROVIDER_GEMINI. Stored in the platform
            secret

            manager and redacted in read APIs.
          type: string
        model_aliases:
          description: >-
            Models the credential can serve and the names the customer's
            provider

            serves them under. Each listed model may be served by only one of
            the

            tenant's keys for the provider, and together the provider's keys
            must

            cover the models the platform requires. Leave empty to make this key

            the provider's single catch-all, serving every model under its own

            name; keys listing a model explicitly take precedence over the

            catch-all.
          items:
            $ref: '#/components/schemas/SpecModelAlias'
          type: array
        provider:
          $ref: '#/components/schemas/SpecProvider'
      required:
        - provider
      type: object
    v1TenantMeta:
      description: Tenant related data for the tenant containing the resource.
      properties:
        namespace:
          description: >-
            Namespaces are a way to organize organizational units into virtual

            groupings of resources. Namespaces must be a fully qualified name,

            for example, the child namespace of namespace "endor.prod" called
            "app"

            is called "endor.prod.app".
          type: string
      required:
        - namespace
      type: object
    googleprotobufAny:
      additionalProperties: {}
      description: >-
        `Any` contains an arbitrary serialized protocol buffer message along
        with a

        URL that describes the type of the serialized message.


        Protobuf library provides support to pack/unpack Any values in the form

        of utility functions or additional generated methods of the Any type.


        Example 1: Pack and unpack a message in C++.

            Foo foo = ...;
            Any any;
            any.PackFrom(foo);
            ...
            if (any.UnpackTo(&foo)) {
              ...
            }

        Example 2: Pack and unpack a message in Java.

            Foo foo = ...;
            Any any = Any.pack(foo);
            ...
            if (any.is(Foo.class)) {
              foo = any.unpack(Foo.class);
            }
            // or ...
            if (any.isSameTypeAs(Foo.getDefaultInstance())) {
              foo = any.unpack(Foo.getDefaultInstance());
            }

         Example 3: Pack and unpack a message in Python.

            foo = Foo(...)
            any = Any()
            any.Pack(foo)
            ...
            if any.Is(Foo.DESCRIPTOR):
              any.Unpack(foo)
              ...

         Example 4: Pack and unpack a message in Go

             foo := &pb.Foo{...}
             any, err := anypb.New(foo)
             if err != nil {
               ...
             }
             ...
             foo := &pb.Foo{}
             if err := any.UnmarshalTo(foo); err != nil {
               ...
             }

        The pack methods provided by protobuf library will by default use

        'type.googleapis.com/full.type.name' as the type URL and the unpack

        methods only use the fully qualified type name after the last '/'

        in the type URL, for example "foo.bar.com/x/y.z" will yield type

        name "y.z".


        JSON

        ====

        The JSON representation of an `Any` value uses the regular

        representation of the deserialized, embedded message, with an

        additional field `@type` which contains the type URL. Example:

            package google.profile;
            message Person {
              string first_name = 1;
              string last_name = 2;
            }

            {
              "@type": "type.googleapis.com/google.profile.Person",
              "firstName": <string>,
              "lastName": <string>
            }

        If the embedded message type is well-known and has a custom JSON

        representation, that representation will be embedded adding a field

        `value` which holds the custom JSON in addition to the `@type`

        field. Example (for message [google.protobuf.Duration][]):

            {
              "@type": "type.googleapis.com/google.protobuf.Duration",
              "value": "1.212s"
            }
      properties:
        '@type':
          description: >-
            A URL/resource name that uniquely identifies the type of the
            serialized

            protocol buffer message. This string must contain at least

            one "/" character. The last segment of the URL's path must represent

            the fully qualified name of the type (as in

            `path/google.protobuf.Duration`). The name should be in a canonical
            form

            (e.g., leading "." is not accepted).


            In practice, teams usually precompile into the binary all types that
            they

            expect it to use in the context of Any. However, for URLs which use
            the

            scheme `http`, `https`, or no scheme, one can optionally set up a
            type

            server that maps type URLs to message definitions as follows:


            * If no scheme is provided, `https` is assumed.

            * An HTTP GET on the URL must yield a [google.protobuf.Type][]
              value in binary format, or produce an error.
            * Applications are allowed to cache lookup results based on the
              URL, or have them precompiled into a binary to avoid any
              lookup. Therefore, binary compatibility needs to be preserved
              on changes to types. (Use versioned type names to manage
              breaking changes.)

            Note: this functionality is not currently available in the official

            protobuf release, and it is not used for type URLs beginning with

            type.googleapis.com. As of May 2023, there are no widely used type
            server

            implementations and no plans to implement one.


            Schemes other than `http`, `https` (or the empty scheme) might be

            used with implementation specific semantics.
          type: string
      type: object
    v1IndexData:
      description: |-
        IndexData is used to index the resource for search. It's an internal
        object.
      properties:
        data:
          items:
            type: string
          readOnly: true
          type: array
        search_score:
          description: >-
            search_score is the score of the resource for search. Internal use
            only.
          format: float
          readOnly: true
          type: number
        tenant:
          readOnly: true
          type: string
        will_be_deleted_at:
          description: Time that the resource will be deleted.
          format: date-time
          readOnly: true
          type: string
      type: object
    SpecModelAlias:
      description: |-
        ModelAlias maps a platform model to the name the customer's provider
        serves it under.
      properties:
        alias:
          description: |-
            Name the customer's provider serves the model under, e.g. an Azure
            OpenAI deployment name. Defaults to the model's own name when unset.
          type: string
        model:
          $ref: '#/components/schemas/SpecAvailableLLM'
      required:
        - model
      type: object
    SpecProvider:
      default: PROVIDER_UNSPECIFIED
      description: |-
        AI providers that support customer-supplied credentials.

         - PROVIDER_UNSPECIFIED: No provider selected.
         - PROVIDER_AZURE_OPENAI: OpenAI-family models served from the customer's Azure OpenAI resource.
         - PROVIDER_OPENAI: OpenAI platform (api.openai.com) or an OpenAI-compatible endpoint.
         - PROVIDER_VERTEX_AI: Gemini-family models served from the customer's GCP project through
        Vertex AI.
         - PROVIDER_GEMINI: Gemini API accessed with a Google AI Studio API key.
      enum:
        - PROVIDER_UNSPECIFIED
        - PROVIDER_AZURE_OPENAI
        - PROVIDER_OPENAI
        - PROVIDER_VERTEX_AI
        - PROVIDER_GEMINI
      type: string
    SpecAvailableLLM:
      default: AVAILABLE_LLM_UNSPECIFIED
      description: |-
        LLMs available to AgentConfig.

         - AVAILABLE_LLM_OPENAI_GPT_5_CHAT: GPT-5 chat is a variant of GPT-5 that is optimized for chat use cases and
        does not support reasoning.
         - AVAILABLE_LLM_OPENAI_GPT_5_6_LUNA: GPT-5.6 Luna is the cost-efficient GPT-5.6 tier.
         - AVAILABLE_LLM_OPENAI_GPT_5_6_SOL: GPT-5.6 Sol is the highest-capability GPT-5.6 tier.
         - AVAILABLE_LLM_OPENAI_GPT_5_6_TERRA: GPT-5.6 Terra balances GPT-5.6 cost and capability.
         - AVAILABLE_LLM_GOOGLE_GEMINI_FLASH_2_5_PREVIEW: deprecated: use AVAILABLE_LLM_GOOGLE_GEMINI_FLASH_2_5_LITE instead.
         - AVAILABLE_LLM_GOOGLE_GEMINI_FLASH_LITE_LATEST: NEVER USE: use AVAILABLE_LLM_GOOGLE_GEMINI_FLASH_2_5_LITE instead.
         - AVAILABLE_LLM_GOOGLE_GEMINI_3_1_FLASH_LITE_PREVIEW: deprecated: use AVAILABLE_LLM_GOOGLE_GEMINI_3_1_FLASH_LITE instead.
         - AVAILABLE_LLM_GOOGLE_GEMINI_3_1_FLASH_LITE: GA Gemini 3.1 Flash Lite; in the EU it is served from the eu.rep data-residency endpoint.
         - AVAILABLE_LLM_GOOGLE_GEMINI_3_5_FLASH_LITE: Generally available Gemini 3.5 Flash Lite model on Vertex AI: the
        high-throughput tier of the 3.5 generation.
         - AVAILABLE_LLM_GOOGLE_GEMINI_3_5_FLASH: Generally available Gemini 3.5 Flash model on Vertex AI.
         - AVAILABLE_LLM_GOOGLE_GEMINI_3_6_FLASH: Generally available Gemini 3.6 Flash model on Vertex AI: the successor to
        3.5 Flash.
         - AVAILABLE_LLM_GOOGLE_GEMINI_3_7_FLASH: Generally available Gemini 3.7 Flash model on Vertex AI: the successor to
        3.6 Flash.
      enum:
        - AVAILABLE_LLM_UNSPECIFIED
        - AVAILABLE_LLM_OPENAI_GPT_5
        - AVAILABLE_LLM_OPENAI_GPT_5_MINI
        - AVAILABLE_LLM_OPENAI_GPT_5_NANO
        - AVAILABLE_LLM_OPENAI_GPT_5_CHAT
        - AVAILABLE_LLM_OPENAI_GPT_5_1
        - AVAILABLE_LLM_OPENAI_GPT_5_1_CHAT
        - AVAILABLE_LLM_OPENAI_GPT_5_1_CODEX
        - AVAILABLE_LLM_OPENAI_GPT_5_1_CODEX_MINI
        - AVAILABLE_LLM_OPENAI_GPT_5_2_CODEX
        - AVAILABLE_LLM_OPENAI_GPT_5_2
        - AVAILABLE_LLM_OPENAI_GPT_5_3_CODEX
        - AVAILABLE_LLM_OPENAI_GPT_5_3_CHAT
        - AVAILABLE_LLM_OPENAI_GPT_5_4_MINI
        - AVAILABLE_LLM_OPENAI_GPT_5_4_NANO
        - AVAILABLE_LLM_OPENAI_GPT_5_4
        - AVAILABLE_LLM_OPENAI_GPT_5_5
        - AVAILABLE_LLM_OPENAI_GPT_5_6_LUNA
        - AVAILABLE_LLM_OPENAI_GPT_5_6_SOL
        - AVAILABLE_LLM_OPENAI_GPT_5_6_TERRA
        - AVAILABLE_LLM_OPENAI_GPT_4
        - AVAILABLE_LLM_OPENAI_GPT_4O_MINI
        - AVAILABLE_LLM_OPENAI_GPT_4_1
        - AVAILABLE_LLM_OPENAI_GPT_4_1_MINI
        - AVAILABLE_LLM_OPENAI_GPT_4_1_NANO
        - AVAILABLE_LLM_OPENAI_O1
        - AVAILABLE_LLM_OPENAI_O3
        - AVAILABLE_LLM_OPENAI_GPT_4O
        - AVAILABLE_LLM_OPENAI_O3_MINI
        - AVAILABLE_LLM_OPENAI_O4_MINI
        - AVAILABLE_LLM_GOOGLE_GEMINI_FLASH_2_0
        - AVAILABLE_LLM_GOOGLE_GEMINI_FLASH_LATEST
        - AVAILABLE_LLM_GOOGLE_GEMINI_FLASH_2_5
        - AVAILABLE_LLM_GOOGLE_GEMINI_FLASH_2_5_PREVIEW
        - AVAILABLE_LLM_GOOGLE_GEMINI_FLASH_2_5_LITE
        - AVAILABLE_LLM_GOOGLE_GEMINI_FLASH_2_0_LITE
        - AVAILABLE_LLM_GOOGLE_GEMINI_FLASH_LITE_LATEST
        - AVAILABLE_LLM_GOOGLE_GEMINI_2_5_PRO
        - AVAILABLE_LLM_GOOGLE_GEMINI_3_PRO_PREVIEW
        - AVAILABLE_LLM_GOOGLE_GEMINI_3_1_PRO_PREVIEW
        - AVAILABLE_LLM_GOOGLE_GEMINI_3_1_FLASH_LITE_PREVIEW
        - AVAILABLE_LLM_GOOGLE_GEMINI_3_1_FLASH_LITE
        - AVAILABLE_LLM_GOOGLE_GEMINI_3_5_FLASH_LITE
        - AVAILABLE_LLM_GOOGLE_GEMINI_3_5_FLASH
        - AVAILABLE_LLM_GOOGLE_GEMINI_3_6_FLASH
        - AVAILABLE_LLM_GOOGLE_GEMINI_3_7_FLASH
        - AVAILABLE_LLM_GOOGLE_GEMINI_3_FLASH_PREVIEW
        - AVAILABLE_LLM_ANTHROPIC_CLAUDE_3_5_SONNET
        - AVAILABLE_LLM_ANTHROPIC_CLAUDE_4_5_SONNET
        - AVAILABLE_LLM_ANTHROPIC_CLAUDE_4_5_HAIKU
        - AVAILABLE_LLM_GROQ_LLAMA_3_2_90B
        - AVAILABLE_LLM_GROQ_COMPOUND
        - AVAILABLE_LLM_GROQ_COMPOUND_MINI
        - AVAILABLE_LLM_GROQ_LLAMA_3_3_70B_VERSATILE
        - AVAILABLE_LLM_GROQ_LLAMA_4_MAVERICK_17B
        - AVAILABLE_LLM_GROQ_LLAMA_4_SCOUT_17B
        - AVAILABLE_LLM_GROQ_OPENAI_GPT_OSS_20B
        - AVAILABLE_LLM_GROQ_OPENAI_GPT_OSS_120B
        - AVAILABLE_LLM_GROQ_OPENAI_GPT_OSS_SAFEGUARD_20B
        - AVAILABLE_LLM_GROQ_QWEN_3_32B
        - AVAILABLE_LLM_GROQ_LLAMA_PROMPT_GUARD_2_22M
        - AVAILABLE_LLM_GROQ_LLAMA_PROMPT_GUARD_2_86M
        - AVAILABLE_LLM_GROQ_LLAMA_GUARD_4_12B
        - AVAILABLE_LLM_ENDOR_DEEPSEEK_R1
        - AVAILABLE_LLM_GOOGLE_GEMMA_4_26B_A4B_IT
        - AVAILABLE_LLM_GOOGLE_GEMINI_R2D2_LATEST
        - AVAILABLE_LLM_FIREWORKS_GPT_OSS_20B
        - AVAILABLE_LLM_FIREWORKS_GPT_OSS_120B
        - AVAILABLE_LLM_FIREWORKS_KIMI_K25
        - AVAILABLE_LLM_FIREWORKS_MINIMAX_M27
        - AVAILABLE_LLM_FIREWORKS_QWEN_3_6_PLUS
      type: string

````