Skip to main content

ApiKey — TypeScript SDK

Bring-your-own-key management for upstream providers.

Overview​

The ApiKey resource manages BYOK (bring-your-own-key) credentials that the gateway uses to call upstream providers (Dashscope, OpenRouter, etc.) on your behalf. CRUD operations are paired with a status toggle, an upstream connectivity test, and a provider catalog endpoint.

Accessed via client.apiKeys.

Available Operations​

MethodDescription
list()List BYOK keys with pagination
create()Create a new BYOK key
update()Update a BYOK key (e.g. rename)
delete()Delete a BYOK key
changeStatus()Enable or disable a BYOK key
testConnect()Test connectivity to the upstream provider
providers()Provider list for BYOK

list​

List BYOK keys with pagination and optional provider/timezone filters.

Example Usage​

import { WltClient } from 'wlt-platform';

const client = new WltClient({ apiKey: 'your-api-key', baseUrl: 'https://console.example.com' });

const result = await client.apiKeys.list({ pageNum: 1, pageSize: 10 });
for (const key of result.apiKeys.list) {
console.log(key.id, key.name, key.provider, key.status);
}

// Filter by provider
const filtered = await client.apiKeys.list({ provider: 'dashscope' });

Parameters​

ParameterTypeRequiredDefaultDescription
pageNumnumberNo1Page number, starting from 1
pageSizenumberNo10Items per page
providerstringNo—Filter by provider identifier
timezonestringNo—Timezone for time-field localization, e.g. "Asia/Shanghai"

Response​

Returns ApiKeyResultVO:

FieldTypeDescription
totalApiCallsnumberTotal API call count
activeKeysnumberNumber of active keys
apiKeysPageInfo<ApikeyVO>Paginated API key data

ApikeyVO:

FieldTypeDescription
idstringApiKey ID
namestringKey name
keystringKey content (masked)
providerstringProvider name
providerIdstringProvider ID
accountstringAccount info
accountIdstringAccount ID
projectIDstringProject ID
createdstringCreation time (ISO 8601)
lastUsedAtstringLast used time (ISO 8601)
statusstringStatus
accessKeyIDstringAccessKey ID (masked)
accessKeySecretstringAccessKey Secret (masked)
resaleStatusstringResale status

Errors​

CodeErrorWhen
2000 / 2002Authentication failureAPI Key invalid
2007Permission deniedToken lacks permission
3001Token expiredRefresh failed

create​

Example Usage​

client.apiKeys.create(params: {
provider: string;
keyName?: string;
status?: number;
accessKeyID?: string;
accessKeySecret?: string;
tpmLimit?: string;
tokenLimit?: string;
})

Create a new BYOK key.

const newKey = await client.apiKeys.create({
provider: 'dashscope',
keyName: 'my-dashscope-key',
accessKeyID: 'LTAI5t...',
accessKeySecret: 'your-access-key-secret',
tpmLimit: '100000',
tokenLimit: '5000000',
});
console.log(`Created key ID: ${newKey.id}`);
console.log(`Key name: ${newKey.name}`);

Parameters​

ParameterTypeRequiredDefaultDescription
providerstringYes—Provider id from apiKeys.providers() (NOT display name)
keyNamestringNo—Key name
statusnumberNo—Initial status
accessKeyIDstringNo—AccessKey ID
accessKeySecretstringNo—AccessKey Secret
tpmLimitstringNo—TPM (tokens per minute) limit
tokenLimitstringNo—Total token limit

Response​

Returns ApikeyVO. See list() for field definitions.

Errors​

CodeErrorWhen
1001Validation errorInvalid parameters
3000Invalid providerDisplay name passed instead of provider id
2000 / 2002Authentication failureAPI Key invalid
2007Permission deniedToken lacks permission
3001Token expiredRefresh failed

update​

Update a BYOK key (e.g. rename, adjust limits).

Example Usage​

const ok = await client.apiKeys.update('456', {
id: 456,
keyName: 'renamed-key',
tpmLimit: '200000',
});
console.log(`Success: ${ok}`); // true

Parameters​

ParameterTypeRequiredDefaultDescription
id (path)stringYes—ApiKey ID (URL path, for routing)
id (body)numberNo—ApiKey database primary key (used to locate the record)
providerstringNo—Provider (must be a valid BYOK provider if provided)
keyNamestringNo—Key name
aliyunAccountIdstringNo—Aliyun account ID
statusnumberNo—Status
accessKeyIDstringNo—AccessKey ID
accessKeySecretstringNo—AccessKey Secret
resaleStatusstringNo—Resale status
tpmLimitstringNo—TPM limit
tokenLimitstringNo—Total token limit

Response​

Returns boolean — true on success.

Errors​

CodeErrorWhen
1001Validation errorInvalid parameters
1002Data not foundApiKey ID does not exist
2000 / 2002Authentication failureAPI Key invalid
2007Permission deniedToken lacks permission
3001Token expiredRefresh failed

delete​

Delete a BYOK key.

Example Usage​

const ok = await client.apiKeys.delete('456');
console.log(`Success: ${ok}`); // true

Parameters​

ParameterTypeRequiredDefaultDescription
idstringYes—ApiKey ID

Response​

Returns boolean — true on success.

Errors​

CodeErrorWhen
1002Data not foundApiKey ID does not exist
2000 / 2002Authentication failureAPI Key invalid
2007Permission deniedToken lacks permission
3001Token expiredRefresh failed

changeStatus​

Enable or disable a BYOK key. status: 1 = enable, 0 = disable.

Example Usage​

// Disable
await client.apiKeys.changeStatus('456', 0);

// Enable
await client.apiKeys.changeStatus('456', 1);

Parameters​

ParameterTypeRequiredDefaultDescription
idstringYes—ApiKey ID
statusnumberYes—Target status: 1=enable, 0=disable

Response​

Returns boolean — true on success.

Errors​

CodeErrorWhen
1001Validation errorInvalid status value
1002Data not foundApiKey ID does not exist
2000 / 2002Authentication failureAPI Key invalid
2007Permission deniedToken lacks permission
3001Token expiredRefresh failed

testConnect​

Test connectivity to the upstream provider with the supplied credentials.

Example Usage​

const ok = await client.apiKeys.testConnect({
provider: 'dashscope',
accessKeyID: 'LTAI5t...',
accessKeySecret: 'your-access-key-secret',
});
console.log(ok ? 'Connection successful' : 'Connection failed');

Parameters​

ParameterTypeRequiredDefaultDescription
aliyunAccountIdstringNo—Aliyun account ID (for providers that require it)
accessKeyIDstringNo—AccessKey ID
accessKeySecretstringNo—AccessKey Secret
providerstringNo—Provider identifier

Response​

Returns boolean — true if the connection is successful.

Errors​

CodeErrorWhen
1001Validation errorInvalid parameters
2000 / 2002Authentication failureAPI Key invalid
2007Permission deniedToken lacks permission
3001Token expiredRefresh failed

providers​

Get the provider list available for BYOK.

Example Usage​

const providers = await client.apiKeys.providers();
for (const p of providers) {
console.log(p.id, p.name);
}

Parameters​

None.

Response​

Returns ProviderVO[]:

FieldTypeDescription
idstringProvider identifier
namestringProvider display name

Errors​

CodeErrorWhen
2000 / 2002Authentication failureAPI Key invalid
2007Permission deniedToken lacks permission
3001Token expiredRefresh failed