ApiKey — TypeScript SDK
Bring-your-own-key management for upstream providers.
Overview
The ApiKey resource manages BYOK (bring-your-own-key) credentials that the gateway uses to call upstream providers (Dashscope, OpenRouter, etc.) on your behalf. CRUD operations are paired with a status toggle, an upstream connectivity test, and a provider catalog endpoint.
Accessed via client.apiKeys.
Available Operations
| Method | Description |
|---|---|
list() | List BYOK keys with pagination |
create() | Create a new BYOK key |
update() | Update a BYOK key (e.g. rename) |
delete() | Delete a BYOK key |
changeStatus() | Enable or disable a BYOK key |
testConnect() | Test connectivity to the upstream provider |
providers() | Provider list for BYOK |
list
List BYOK keys with pagination and optional provider/timezone filters.
Example Usage
import { WltClient } from 'wlt-platform';
const client = new WltClient({ apiKey: 'your-api-key', baseUrl: 'https://console.example.com' });
const result = await client.apiKeys.list({ pageNum: 1, pageSize: 10 });
for (const key of result.apiKeys.list) {
console.log(key.id, key.name, key.provider, key.status);
}
// Filter by provider
const filtered = await client.apiKeys.list({ provider: 'dashscope' });
Parameters
| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
pageNum | number | No | 1 | Page number, starting from 1 |
pageSize | number | No | 10 | Items per page |
provider | string | No | — | Filter by provider identifier |
timezone | string | No | — | Timezone for time-field localization, e.g. "Asia/Shanghai" |
Response
Returns ApiKeyResultVO:
| Field | Type | Description |
|---|---|---|
totalApiCalls | number | Total API call count |
activeKeys | number | Number of active keys |
apiKeys | PageInfo<ApikeyVO> | Paginated API key data |
ApikeyVO:
| Field | Type | Description |
|---|---|---|
id | string | ApiKey ID |
name | string | Key name |
key | string | Key content (masked) |
provider | string | Provider name |
providerId | string | Provider ID |
account | string | Account info |
accountId | string | Account ID |
projectID | string | Project ID |
created | string | Creation time (ISO 8601) |
lastUsedAt | string | Last used time (ISO 8601) |
status | string | Status |
accessKeyID | string | AccessKey ID (masked) |
accessKeySecret | string | AccessKey Secret (masked) |
resaleStatus | string | Resale status |
Errors
| Code | Error | When |
|---|---|---|
2000 / 2002 | Authentication failure | API Key invalid |
2007 | Permission denied | Token lacks permission |
3001 | Token expired | Refresh failed |
create
Example Usage
client.apiKeys.create(params: {
provider: string;
keyName?: string;
status?: number;
accessKeyID?: string;
accessKeySecret?: string;
tpmLimit?: string;
tokenLimit?: string;
})
Create a new BYOK key.
const newKey = await client.apiKeys.create({
provider: 'dashscope',
keyName: 'my-dashscope-key',
accessKeyID: 'LTAI5t...',
accessKeySecret: 'your-access-key-secret',
tpmLimit: '100000',
tokenLimit: '5000000',
});
console.log(`Created key ID: ${newKey.id}`);
console.log(`Key name: ${newKey.name}`);
Parameters
| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
provider | string | Yes | — | Provider id from apiKeys.providers() (NOT display name) |
keyName | string | No | — | Key name |
status | number | No | — | Initial status |
accessKeyID | string | No | — | AccessKey ID |
accessKeySecret | string | No | — | AccessKey Secret |
tpmLimit | string | No | — | TPM (tokens per minute) limit |
tokenLimit | string | No | — | Total token limit |
Response
Returns ApikeyVO. See list() for field definitions.
Errors
| Code | Error | When |
|---|---|---|
1001 | Validation error | Invalid parameters |
3000 | Invalid provider | Display name passed instead of provider id |
2000 / 2002 | Authentication failure | API Key invalid |
2007 | Permission denied | Token lacks permission |
3001 | Token expired | Refresh failed |
update
Update a BYOK key (e.g. rename, adjust limits).
Example Usage
const ok = await client.apiKeys.update('456', {
id: 456,
keyName: 'renamed-key',
tpmLimit: '200000',
});
console.log(`Success: ${ok}`); // true
Parameters
| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
id (path) | string | Yes | — | ApiKey ID (URL path, for routing) |
id (body) | number | No | — | ApiKey database primary key (used to locate the record) |
provider | string | No | — | Provider (must be a valid BYOK provider if provided) |
keyName | string | No | — | Key name |
aliyunAccountId | string | No | — | Aliyun account ID |
status | number | No | — | Status |
accessKeyID | string | No | — | AccessKey ID |
accessKeySecret | string | No | — | AccessKey Secret |
resaleStatus | string | No | — | Resale status |
tpmLimit | string | No | — | TPM limit |
tokenLimit | string | No | — | Total token limit |
Response
Returns boolean — true on success.
Errors
| Code | Error | When |
|---|---|---|
1001 | Validation error | Invalid parameters |
1002 | Data not found | ApiKey ID does not exist |
2000 / 2002 | Authentication failure | API Key invalid |
2007 | Permission denied | Token lacks permission |
3001 | Token expired | Refresh failed |
delete
Delete a BYOK key.
Example Usage
const ok = await client.apiKeys.delete('456');
console.log(`Success: ${ok}`); // true
Parameters
| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
id | string | Yes | — | ApiKey ID |
Response
Returns boolean — true on success.
Errors
| Code | Error | When |
|---|---|---|
1002 | Data not found | ApiKey ID does not exist |
2000 / 2002 | Authentication failure | API Key invalid |
2007 | Permission denied | Token lacks permission |
3001 | Token expired | Refresh failed |
changeStatus
Enable or disable a BYOK key. status: 1 = enable, 0 = disable.
Example Usage
// Disable
await client.apiKeys.changeStatus('456', 0);
// Enable
await client.apiKeys.changeStatus('456', 1);
Parameters
| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
id | string | Yes | — | ApiKey ID |
status | number | Yes | — | Target status: 1=enable, 0=disable |
Response
Returns boolean — true on success.
Errors
| Code | Error | When |
|---|---|---|
1001 | Validation error | Invalid status value |
1002 | Data not found | ApiKey ID does not exist |
2000 / 2002 | Authentication failure | API Key invalid |
2007 | Permission denied | Token lacks permission |
3001 | Token expired | Refresh failed |
testConnect
Test connectivity to the upstream provider with the supplied credentials.
Example Usage
const ok = await client.apiKeys.testConnect({
provider: 'dashscope',
accessKeyID: 'LTAI5t...',
accessKeySecret: 'your-access-key-secret',
});
console.log(ok ? 'Connection successful' : 'Connection failed');
Parameters
| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
aliyunAccountId | string | No | — | Aliyun account ID (for providers that require it) |
accessKeyID | string | No | — | AccessKey ID |
accessKeySecret | string | No | — | AccessKey Secret |
provider | string | No | — | Provider identifier |
Response
Returns boolean — true if the connection is successful.
Errors
| Code | Error | When |
|---|---|---|
1001 | Validation error | Invalid parameters |
2000 / 2002 | Authentication failure | API Key invalid |
2007 | Permission denied | Token lacks permission |
3001 | Token expired | Refresh failed |
providers
Get the provider list available for BYOK.
Example Usage
const providers = await client.apiKeys.providers();
for (const p of providers) {
console.log(p.id, p.name);
}
Parameters
None.
Response
Returns ProviderVO[]:
| Field | Type | Description |
|---|---|---|
id | string | Provider identifier |
name | string | Provider display name |
Errors
| Code | Error | When |
|---|---|---|
2000 / 2002 | Authentication failure | API Key invalid |
2007 | Permission denied | Token lacks permission |
3001 | Token expired | Refresh failed |