REST API
LLM & Search Credentials
On this page
Credentials are stored with AES-256-GCM envelope encryption. Only the last four characters and a status are ever readable back — the plaintext key cannot be retrieved through the API by anyone, including an org owner.
These credentials let Evigauge's own reconstruction engines call an LLM on your behalf. Evigauge never proxies or routes your application's LLM calls.
Get LLM credentials
GET /v1/observ/orgs/{org}/llm-credentials
Auth: API key or JWT · Role: dev (org-scoped)
Response 200 — not schema-modelled
{
"configured": true,
"provider": "anthropic",
"model_id": "claude-opus-4-6",
"api_key_last4": "9f2c",
"api_base": null,
"fallback_enabled": true
}
Examples
c = evigauge.get("/v1/observ/orgs/{org}/llm-credentials")
print(f"{c['provider']}/{c['model_id']} key=…{c['api_key_last4']}")
const c = await evigauge.get("/v1/observ/orgs/{org}/llm-credentials");
console.log(`${c.provider}/${c.model_id} key=…${c.api_key_last4}`);
Set LLM credentials
PUT /v1/observ/orgs/{org}/llm-credentials
Any provider reachable through LiteLLM is supported.
Auth: API key or JWT · Role: dev (org-scoped)
Request body — CredentialIn
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
provider | string | ✅ | — | Provider key, e.g. anthropic, openai, bedrock |
model_id | string | ✅ | — | Model identifier for that provider |
api_key | string | null | ➖ | null | Secret. Omit to keep the stored key and change only other fields. |
api_base | string | null | ➖ | null | Custom endpoint for self-hosted or proxied providers |
provider_config | object | ➖ | {} | Extra provider-specific settings |
Examples
evigauge.put("/v1/observ/orgs/{org}/llm-credentials", json={
"provider": "anthropic",
"model_id": "claude-opus-4-6",
"api_key": "sk-ant-...",
})
# Rotate the model but keep the stored key: omit api_key entirely.
evigauge.put("/v1/observ/orgs/{org}/llm-credentials", json={
"provider": "anthropic",
"model_id": "claude-sonnet-4-6",
})
await evigauge.put("/v1/observ/orgs/{org}/llm-credentials", {
provider: "anthropic",
model_id: "claude-opus-4-6",
api_key: "sk-ant-...",
});
// Rotate the model but keep the stored key: omit api_key entirely.
await evigauge.put("/v1/observ/orgs/{org}/llm-credentials", {
provider: "anthropic",
model_id: "claude-sonnet-4-6",
});
Delete LLM credentials
DELETE /v1/observ/orgs/{org}/llm-credentials
Auth: API key or JWT · Role: dev (org-scoped)
Engines that need an LLM stop producing new results once the credential is removed. Existing results are retained.
Examples
evigauge.delete("/v1/observ/orgs/{org}/llm-credentials")
await evigauge.del("/v1/observ/orgs/{org}/llm-credentials");
Toggle credential fallback
PATCH /v1/observ/orgs/{org}/llm-credentials/fallback
When enabled, engines fall back to the platform default model if your configured provider is unreachable.
Auth: API key or JWT · Role: dev (org-scoped)
Request body — FallbackIn
| Field | Type | Required | Description |
|---|---|---|---|
enabled | boolean | ✅ | Enable or disable fallback |
Examples
evigauge.patch("/v1/observ/orgs/{org}/llm-credentials/fallback", json={"enabled": True})
await evigauge.patch("/v1/observ/orgs/{org}/llm-credentials/fallback", { enabled: true });
Get search credential
GET /v1/observ/orgs/{org}/search-credentials
The web-search key (Exa) used for open-web claim verification.
Auth: API key or JWT · Role: dev (org-scoped)
Examples
print(evigauge.get("/v1/observ/orgs/{org}/search-credentials"))
console.log(await evigauge.get("/v1/observ/orgs/{org}/search-credentials"));
Set search credential
PUT /v1/observ/orgs/{org}/search-credentials
Auth: API key or JWT · Role: dev (org-scoped)
Request body — SearchCredentialIn
| Field | Type | Required | Description |
|---|---|---|---|
api_key | string | ✅ | Search-provider API key |
Examples
evigauge.put("/v1/observ/orgs/{org}/search-credentials", json={"api_key": "exa-..."})
await evigauge.put("/v1/observ/orgs/{org}/search-credentials", { api_key: "exa-..." });
Required for broaden-sources and the External Cross-Check engine. Without it both stay in closed-KB mode.
Delete search credential
DELETE /v1/observ/orgs/{org}/search-credentials
Auth: API key or JWT · Role: dev (org-scoped)
Examples
evigauge.delete("/v1/observ/orgs/{org}/search-credentials")
await evigauge.del("/v1/observ/orgs/{org}/search-credentials");