Secret — Python SDK
Manage the API secrets your apps use to call the gateway.
Overview
The Secret resource covers the full lifecycle of API secrets: listing, inspecting, creating, editing, enabling/disabling/deleting, and querying per-model usage. It also exposes the supporting model and provider catalogues used when binding a secret to a specific subset of upstream services.
Accessed via client.secrets.
Available Operations
| Method | Description |
|---|---|
list() | List secrets with pagination and optional filters |
detail() | Get a single secret's details by ID |
create() | Create a new secret and return the generated API key |
edit() | Edit an existing secret |
action() | Enable, disable, or delete a secret |
usageByModel() | Query secret usage breakdown by model |
modelList() | List available models for secret binding |
providers() | List providers available for secrets |
list
List secrets with pagination and optional filters.
Example Usage
from wlt import WltClient
client = WltClient(api_key="your-api-key", base_url="https://console.example.com")
# Basic listing
result = client.secrets.list()
print(f"Total secrets: {result.data.totalKeys}")
for secret in result.data.pageInfo.list:
print(secret.id, secret.name, secret.status)
# With filters
result = client.secrets.list(page_num=1, page_size=5, status=1)
Parameters
| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
| page_num | int | No | 1 | Page number, starting from 1 |
| page_size | int | No | 10 | Items per page |
| status | int | No | None | Status filter: 1=active, 0=disabled |
| expired_before_utc | datetime | No | None | Expiry time upper bound (UTC), filter secrets expiring before this time |
Response
Returns BaseResponse[SecretPageResultVO].
SecretPageResultVO fields:
| Field | Type | Description |
|---|---|---|
| totalKeys | int | Total number of secrets |
| activeKeys | int | Number of active secrets |
| totalRequest | int | Total request count |
| avgQps | float | Average QPS |
| pageInfo | PageInfo[SecretVO] | Paginated secret data |
PageInfo fields:
| Field | Type | Description |
|---|---|---|
| total | int | Total record count |
| totalPages | int | Total number of pages |
| currentPage | int | Current page number |
| pageSize | int | Items per page |
| list | list[SecretVO] | Data list |
SecretVO fields:
| Field | Type | Description |
|---|---|---|
| id | int | Secret ID |
| name | str | Secret name |
| keyId | str | Key identifier |
| status | str | Status |
| createdAt | datetime | Creation time |
| lastUsed | datetime | Last used time |
| expiredFlag | bool | Whether expired |
| allowedModels | list[str] | Allowed model list |
| allowedProviders | list[str] | Allowed provider list |
| ipWhiteList | list[str] | IP whitelist |
| minuteTokensQuota | int | Per-minute token quota |
| annualTokensQuota | int | Annual token quota |
| description | str | Description |
| expiredAtUtc | datetime | Expiry time (UTC) |
| byokList | list[ApikeyVO] | Associated BYOK key list |
| defaultSecret | int | Whether default secret: 1=yes, 0=no |
| createUser | str | Creator |
Errors
| Code | Exception | When |
|---|---|---|
2000 / 2002 | AuthenticationError | API Key invalid |
2007 | PermissionError | Permission denied |
3001 | AuthenticationError | Token expired and refresh failed |
detail
Get a single secret's details by ID.
Example Usage
from wlt import WltClient
client = WltClient(api_key="your-api-key", base_url="https://console.example.com")
detail = client.secrets.detail(id=123)
print(detail.data.name)
print(detail.data.allowedModels)
print(detail.data.allowedProviders)
Parameters
| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
| id | int | Yes | -- | Secret ID |
Response
Returns BaseResponse[SecretVO].
SecretVO fields: see
client.secrets.list()above.
Errors
| Code | Exception | When |
|---|---|---|
1001 | ValidationError | Invalid request parameters |
1002 | NotFoundError | Secret not found |
2000 / 2002 | AuthenticationError | API Key invalid |
2007 | PermissionError | Permission denied |
3001 | AuthenticationError | Token expired and refresh failed |
create
Create a new secret. Returns the generated API key string.
create() does not return the database row's numeric id. To resolve it, call client.secrets.list(...) and match by name — see the lookup at the end of the example below.
Example Usage
from wlt import WltClient
from datetime import datetime, timezone, timedelta
client = WltClient(api_key="your-api-key", base_url="https://console.example.com")
# Minimal creation
result = client.secrets.create(name="my-secret")
print(f"New API key: {result.data}")
# Full creation with all options
result = client.secrets.create(
name="production-key",
allowed_models=["qwen-turbo", "qwen-plus"],
allowed_providers=["dashscope"],
ip_white_list=["10.0.0.0/8"],
minute_tokens_quota=100000,
annual_tokens_quota=50000000,
expired_at_utc=datetime(2027, 1, 1, tzinfo=timezone.utc),
byok_ids=[1, 2],
)
print(f"New API key: {result.data}")
# To obtain the new secret's DB id, look it up by name via list():
page = client.secrets.list(page_num=1, page_size=100)
new_id = next(s.id for s in page.data.list if s.name == "production-key")
Parameters
| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
| name | str | No | None | Secret name |
| allowed_models | list[str] | No | None | List of allowed model names |
| allowed_providers | list[str] | No | None | List of allowed provider names |
| ip_white_list | list[str] | No | None | IP whitelist (CIDR notation) |
| minute_tokens_quota | int | No | None | Per-minute token quota |
| annual_tokens_quota | int | No | None | Annual token quota |
| expired_at_utc | datetime | No | None | Expiry time in UTC |
| byok_ids | list[int] | No | None | List of BYOK key IDs to associate |
Response
Returns BaseResponse[str]. The data field contains the generated API key string (the secret key value -- save it now, the backend will not return it again).
Errors
| Code | Exception | When |
|---|---|---|
2000 / 2002 | AuthenticationError | API Key invalid |
2007 | PermissionError | Permission denied |
3001 | AuthenticationError | Token expired and refresh failed |
edit
Edit an existing secret.
Example Usage
from wlt import WltClient
client = WltClient(api_key="your-api-key", base_url="https://console.example.com")
result = client.secrets.edit(
id=123,
name="updated-secret-name",
allowed_models=["qwen-turbo", "qwen-max"],
minute_tokens_quota=200000,
)
print(f"Success: {result.data}") # True
Parameters
| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
| id | int | Yes | -- | Secret ID |
| name | str | No | None | Updated name |
| allowed_models | list[str] | No | None | Updated allowed model list |
| allowed_providers | list[str] | No | None | Updated allowed provider list |
| ip_white_list | list[str] | No | None | Updated IP whitelist |
| minute_tokens_quota | int | No | None | Updated per-minute token quota |
| annual_tokens_quota | int | No | None | Updated annual token quota |
| expired_at_utc | datetime | No | None | Updated expiry time (UTC) |
| byok_ids | list[int] | No | None | Updated BYOK key IDs |
Response
Returns BaseResponse[bool]. data=True on success.
Errors
| Code | Exception | When |
|---|---|---|
1001 | ValidationError | Invalid request parameters |
1002 | NotFoundError | Secret not found |
2000 / 2002 | AuthenticationError | API Key invalid |
2007 | PermissionError | Permission denied |
3001 | AuthenticationError | Token expired and refresh failed |
action
Perform an action on a secret: "ENABLE", "DISABLE", or "DELETE".
Example Usage
from wlt import WltClient
client = WltClient(api_key="your-api-key", base_url="https://console.example.com")
# Disable a secret
result = client.secrets.action(id=123, status="DISABLE")
print(f"Success: {result.data}") # True
# Enable a secret
result = client.secrets.action(id=123, status="ENABLE")
# Delete a secret
result = client.secrets.action(id=123, status="DELETE")
Parameters
| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
| id | int | Yes | -- | Secret ID |
| status | str | Yes | -- | Action: "ENABLE", "DISABLE", or "DELETE" |
Response
Returns BaseResponse[bool]. data=True on success.
Errors
| Code | Exception | When |
|---|---|---|
1001 | ValidationError | Invalid request parameters |
1002 | NotFoundError | Secret not found |
2000 / 2002 | AuthenticationError | API Key invalid |
2007 | PermissionError | Permission denied |
3001 | AuthenticationError | Token expired and refresh failed |
usageByModel
Query secret usage breakdown by model with pagination.
Example Usage
from wlt import WltClient
from datetime import datetime
client = WltClient(api_key="your-api-key", base_url="https://console.example.com")
result = client.secrets.usage_by_model(
secret_id=123,
start_time=datetime(2026, 4, 1),
end_time=datetime(2026, 4, 21),
page_num=1,
page_size=10,
)
for item in result.data.list:
print(item.model, item.promptTokens, item.completionTokens)
Parameters
| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
| secret_id | int | Yes | -- | Secret ID |
| start_time | datetime | No | None | Query start time |
| end_time | datetime | No | None | Query end time |
| page_num | int | No | 1 | Page number |
| page_size | int | No | 10 | Items per page |
Response
Returns BaseResponse[PageInfo[SecretModelUsageVO]].
SecretModelUsageVO fields:
| Field | Type | Description |
|---|---|---|
| model | str | Model name |
| requests | int | Request count |
| totalTokens | int | Total token consumption |
| promptTokens | int | Prompt token count |
| completionTokens | int | Completion token count |
Errors
| Code | Exception | When |
|---|---|---|
1001 | ValidationError | Invalid request parameters |
1002 | NotFoundError | Secret not found |
2000 / 2002 | AuthenticationError | API Key invalid |
2007 | PermissionError | Permission denied |
3001 | AuthenticationError | Token expired and refresh failed |
modelList
Query available models for secret binding.
Example Usage
from wlt import WltClient
client = WltClient(api_key="your-api-key", base_url="https://console.example.com")
# List all inference models
models = client.secrets.model_list(usage_type="inference")
for m in models.data:
print(m.modelName, m.provider)
# Filter by provider
models = client.secrets.model_list(
provider="dashscope",
model_name="qwen",
tags=["New"],
)
for m in models.data:
print(m.modelName)
Parameters
| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
| model_name | str | No | None | Model name (fuzzy search) |
| provider | str | No | None | Provider identifier |
| series_provider | str | No | None | Series provider identifier |
| model_type | str | No | None | Model type |
| view_all_flag | int | No | None | View all flag (1=view all) |
| page_size | int | No | None | Items per page |
| page_num | int | No | None | Page number |
| usage_type | str | No | None | Usage type: "inference" or "train" |
| training_method | str | No | None | Training method: "sft" or "dpo" |
| tags | list[str] | No | None | Tag filter list, e.g. ["New"] |
| capability | str | No | None | Capability filter, e.g. "text_to_text" |
| model_type_list | list[str] | No | None | Model type list (multi-select) |
| origin_providers | list[str] | No | None | Origin provider list (multi-select) |
| inputs | list[str] | No | None | Input type list, e.g. ["text"] |
| outputs | list[str] | No | None | Output type list, e.g. ["image"] |
Response
Returns BaseResponse[list[ModelInfoVO]].
ModelInfoVO fields:
| Field | Type | Description |
|---|---|---|
| modelId | str | Model ID |
| modelName | str | Model name |
| modelImage | str | Model icon URL |
| isNew | int | Whether new model (1=yes) |
| provider | str | Provider identifier |
| providerName | str | Provider display name |
| originProvider | str | Origin provider identifier |
| seriesProvider | str | Series provider identifier |
| modelType | str | Model type |
| tags | list[str] | Tag list |
| modelSize | str | Model size |
| feature | str | Feature description |
| price | Decimal | Price |
| unit | str | Price unit |
| available | bool | Whether available |
| updated | datetime | Update time |
| deployPlatform | str | Deploy platform |
| regionId | str | Region ID |
| deployFrameworks | list[str] | Deploy framework list |
| labels | list[str] | Label list |
| capabilities | list[str] | Capability list (e.g. text_to_text) |
| inputs | list[str] | Input type set |
| outputs | list[str] | Output type set |
| priceExtend | PartnerApiPriceExtend | Extended price info |
| dataSource | str | Data source (model_card or model_router) |
Errors
| Code | Exception | When |
|---|---|---|
2000 / 2002 | AuthenticationError | API Key invalid |
2007 | PermissionError | Permission denied |
3001 | AuthenticationError | Token expired and refresh failed |
providers
Get the list of providers available for secrets.
Example Usage
from wlt import WltClient
client = WltClient(api_key="your-api-key", base_url="https://console.example.com")
providers = client.secrets.providers()
for p in providers.data:
print(p.id, p.name)
Parameters
None.
Response
Returns BaseResponse[list[ProviderVO]].
ProviderVO fields:
| Field | Type | Description |
|---|---|---|
| id | str | Provider identifier |
| name | str | Provider display name |
Errors
| Code | Exception | When |
|---|---|---|
2000 / 2002 | AuthenticationError | API Key invalid |
2007 | PermissionError | Permission denied |
3001 | AuthenticationError | Token expired and refresh failed |