import requests
url = "https://api.auriko.ai/v1/workspaces/{workspace_id}/byok-keys/{byok_key_id}"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.auriko.ai/v1/workspaces/{workspace_id}/byok-keys/{byok_key_id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));curl --request GET \
--url https://api.auriko.ai/v1/workspaces/{workspace_id}/byok-keys/{byok_key_id} \
--header 'Authorization: Bearer <token>'{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"workspace_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"provider": "<string>",
"name": "<string>",
"key_prefix": "<string>",
"is_default": true,
"disabled": true,
"validation_status": "valid",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z",
"account_tier": "<string>",
"account_tier_source": "auto_detected",
"last_validated_at": "2023-11-07T05:31:56Z",
"propagation_status": "pending"
}{
"error": {
"message": "API key is invalid.",
"type": "authentication_error",
"param": null,
"code": "invalid_api_key"
}
}{
"error": {
"message": "The requested resource was not found.",
"type": "not_found_error",
"param": null,
"code": "resource_not_found"
}
}Get BYOK key
Returns a BYOK key’s redacted metadata
import requests
url = "https://api.auriko.ai/v1/workspaces/{workspace_id}/byok-keys/{byok_key_id}"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.auriko.ai/v1/workspaces/{workspace_id}/byok-keys/{byok_key_id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));curl --request GET \
--url https://api.auriko.ai/v1/workspaces/{workspace_id}/byok-keys/{byok_key_id} \
--header 'Authorization: Bearer <token>'{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"workspace_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"provider": "<string>",
"name": "<string>",
"key_prefix": "<string>",
"is_default": true,
"disabled": true,
"validation_status": "valid",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z",
"account_tier": "<string>",
"account_tier_source": "auto_detected",
"last_validated_at": "2023-11-07T05:31:56Z",
"propagation_status": "pending"
}{
"error": {
"message": "API key is invalid.",
"type": "authentication_error",
"param": null,
"code": "invalid_api_key"
}
}{
"error": {
"message": "The requested resource was not found.",
"type": "not_found_error",
"param": null,
"code": "resource_not_found"
}
}byok:read scope. Naturally idempotent.
key_prefix and coarse validation_status, never the provider secret or provider diagnostics.propagation_status: "pending" while a change to this key’s provider takes effect (within about 5 minutes).Authorizations
API key authentication.
Keys start with ak_ prefix.
Example: Authorization: Bearer ak_live_xxxxxxxxxxxx
Path Parameters
Workspace identifier
BYOK key identifier
Response
OK
BYOK key metadata. Redacted — the provider secret is never returned.
Unique identifier for the BYOK key
Workspace this key belongs to
Provider identifier
Human-readable name for the key
Masked display prefix of the submitted secret
Whether this key is the provider's default for routing
Disabled keys are excluded from routing; the secret stays encrypted at rest
Coarse validation status (no provider diagnostics)
valid, pending, invalid, error Provider account tier used for rate-limit and data-policy routing
How the tier was determined
auto_detected, user_specified, fallback, null When the key last passed validation (null if never)
"pending" while a routing-affecting change for this key's provider is committed but edge propagation has not yet been applied
pending, null