DEVELOPER DOCS

REST API

LLM & Search Credentials

On this page

Credentials are stored with AES-256-GCM envelope encryption. Only the last four characters and a status are ever readable back — the plaintext key cannot be retrieved through the API by anyone, including an org owner.

These credentials let Evigauge's own reconstruction engines call an LLM on your behalf. Evigauge never proxies or routes your application's LLM calls.


Get LLM credentials

HTTP
GET /v1/observ/orgs/{org}/llm-credentials

Auth: API key or JWT · Role: dev (org-scoped)

Response 200 — not schema-modelled

JSON
{
  "configured": true,
  "provider": "anthropic",
  "model_id": "claude-opus-4-6",
  "api_key_last4": "9f2c",
  "api_base": null,
  "fallback_enabled": true
}

Examples

c = evigauge.get("/v1/observ/orgs/{org}/llm-credentials")
print(f"{c['provider']}/{c['model_id']} key=…{c['api_key_last4']}")

Set LLM credentials

HTTP
PUT /v1/observ/orgs/{org}/llm-credentials

Any provider reachable through LiteLLM is supported.

Auth: API key or JWT · Role: dev (org-scoped)

Request body — CredentialIn

FieldTypeRequiredDefaultDescription
providerstring✅—Provider key, e.g. anthropic, openai, bedrock
model_idstring✅—Model identifier for that provider
api_keystring | null➖nullSecret. Omit to keep the stored key and change only other fields.
api_basestring | null➖nullCustom endpoint for self-hosted or proxied providers
provider_configobject➖{}Extra provider-specific settings

Examples

evigauge.put("/v1/observ/orgs/{org}/llm-credentials", json={
    "provider": "anthropic",
    "model_id": "claude-opus-4-6",
    "api_key": "sk-ant-...",
})

# Rotate the model but keep the stored key: omit api_key entirely.
evigauge.put("/v1/observ/orgs/{org}/llm-credentials", json={
    "provider": "anthropic",
    "model_id": "claude-sonnet-4-6",
})

Delete LLM credentials

HTTP
DELETE /v1/observ/orgs/{org}/llm-credentials

Auth: API key or JWT · Role: dev (org-scoped)

Engines that need an LLM stop producing new results once the credential is removed. Existing results are retained.

Examples

evigauge.delete("/v1/observ/orgs/{org}/llm-credentials")

Toggle credential fallback

HTTP
PATCH /v1/observ/orgs/{org}/llm-credentials/fallback

When enabled, engines fall back to the platform default model if your configured provider is unreachable.

Auth: API key or JWT · Role: dev (org-scoped)

Request body — FallbackIn

FieldTypeRequiredDescription
enabledboolean✅Enable or disable fallback

Examples

evigauge.patch("/v1/observ/orgs/{org}/llm-credentials/fallback", json={"enabled": True})

Get search credential

HTTP
GET /v1/observ/orgs/{org}/search-credentials

The web-search key (Exa) used for open-web claim verification.

Auth: API key or JWT · Role: dev (org-scoped)

Examples

print(evigauge.get("/v1/observ/orgs/{org}/search-credentials"))

Set search credential

HTTP
PUT /v1/observ/orgs/{org}/search-credentials

Auth: API key or JWT · Role: dev (org-scoped)

Request body — SearchCredentialIn

FieldTypeRequiredDescription
api_keystring✅Search-provider API key

Examples

evigauge.put("/v1/observ/orgs/{org}/search-credentials", json={"api_key": "exa-..."})

Required for broaden-sources and the External Cross-Check engine. Without it both stay in closed-KB mode.


Delete search credential

HTTP
DELETE /v1/observ/orgs/{org}/search-credentials

Auth: API key or JWT · Role: dev (org-scoped)

Examples

evigauge.delete("/v1/observ/orgs/{org}/search-credentials")