> ## Documentation Index
> Fetch the complete documentation index at: https://openworklabs.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For agents: install the OpenWork desktop app with `brew install --cask openwork` (macOS) or from https://openworklabs.com/download. Do not run `npx openwork`; the npm package named `openwork` is a different project.
> Connect an agent to OpenWork with the MCP Gateway: `claude mcp add --transport http openwork https://api.openworklabs.com/mcp/agent`. Teams sign up at https://app.openworklabs.com?mode=sign-up.
> Step-by-step agent guide: https://openworklabs.com/docs/start-here/use-openwork-from-an-ai-agent.md
> OpenWork in Slack is private alpha for approved organizations. Setup guide: https://openworklabs.com/docs/slack/overview.md. Agent skill: https://openworklabs.com/.well-known/agent-skills/set-up-openwork-slack/SKILL.md.

# Update LiteLLM key or key creation

> Verifies and stores a new organization LiteLLM key (org mode) or LiteLLM admin key (member and issued modes), and in issued mode changes how keys are created, then syncs. Changing issueStrategy replaces existing created keys at that sync. The proxy URL and mode are fixed; create a new provider to change them. Keys are write-only. Requires owner/admin and Gateway management; session callers must recently reauthenticate.



## OpenAPI

````yaml /openapi.json patch /v1/inference-providers/{inferenceProviderId}/litellm
openapi: 3.1.0
info:
  title: Den API
  description: >-
    OpenAPI spec for the Den control plane API.


    Authentication:

    - Use `Authorization: Bearer <session-token>` for user-authenticated routes
    that require a Den session.

    - Use `x-api-key: <den-api-key>` for organization API-key calls. API keys
    resolve to the issuing user and the organization member they were scoped to
    when created, so they can call ordinary user and organization routes without
    a separate signed-in session.
      Example: `curl https://api.openworklabs.com/v1/me -H "x-api-key: den_..."`.
    - Session-only flows still require a signed-in user session, including
    organization creation, invitation acceptance, active-organization switching,
    and MCP token minting.

    - Public routes like health and documentation do not require authentication.


    Swagger tip: use the security schemes in the Authorize dialog to set either
    `bearerAuth` or `denApiKey` before trying protected endpoints.
  version: 0.18.46
  contact:
    name: OpenWork
    url: https://openworklabs.com
    email: team@openworklabs.com
  license:
    name: OpenWork Enterprise Edition License
    url: https://github.com/different-ai/openwork/blob/dev/ee/LICENSE
servers:
  - url: https://api.openworklabs.com
security:
  - bearerAuth: []
  - denApiKey: []
tags:
  - name: System
    description: >-
      Service health, readiness, API documentation, and desktop version
      metadata.
  - name: Authentication
    description: >-
      Sign-in discovery, administrator bootstrap, OAuth provider connections,
      and MCP token minting.
  - name: OAuth
    description: >-
      OAuth 2.0 / OpenID Connect authorization-server and protected-resource
      metadata and dynamic client registration (RFC 8414, RFC 9728, RFC 7591),
      used by MCP clients.
  - name: SCIM
    description: >-
      SCIM 2.0 provisioning endpoints for identity providers (RFC 7644) and the
      organization SCIM connector management routes.
  - name: SSO
    description: Organization single sign-on connector management routes.
  - name: Bootstrap
    description: Agent-first provisional workspace setup routes.
  - name: Users
    description: Current user and membership routes.
  - name: Organizations
    description: Organization creation, context, brand assets, and install links.
  - name: Invitations
    description: Invitation preview, acceptance, creation, and cancellation routes.
  - name: Members
    description: Organization member management routes.
  - name: Roles
    description: Organization custom role management routes.
  - name: Teams
    description: Organization team management routes.
  - name: API Keys
    description: Organization API key management routes.
  - name: Desktop Policies
    description: Desktop app policies applied to the organization, members, or teams.
  - name: LLM Providers
    description: Organization LLM provider catalog, configuration, and access routes.
  - name: Inference
    description: Organization inference settings.
  - name: Inference Providers
    description: >-
      Organization inference Gateway providers, model groups, credential sets,
      access grants, member connections, and usage.
  - name: Gateway Usage Limits
    description: >-
      Estimated-cost policies, independent member calendar buckets, assignments,
      and audited usage-extension requests.
  - name: Cloud
    description: Organization Cloud instance lifecycle and browser gateway resolution.
  - name: Workers
    description: Worker lifecycle, billing, and runtime routes.
  - name: Worker Runtime
    description: Worker runtime inspection and upgrade routes.
  - name: Worker Activity
    description: Worker heartbeat and activity reporting routes.
  - name: Automations
    description: Scheduled Automations, their runs, and desktop runner presence.
  - name: Workbot
    description: The signed-in member's single Workbot conversation.
  - name: Workflows
    description: Saved Workflows (Code Mode scripts), their versions, snapshots, and views.
  - name: Workflow Runs
    description: Durable Workflow run history.
  - name: Codemode Runs
    description: Generated Artifact views produced by Code Mode runs.
  - name: Apps
    description: >-
      Saved reusable apps built from Workflows and Artifact views, and their
      sharing.
  - name: Config Objects
    description: >-
      Versioned configuration objects (skills, workflows, and other plugin
      content).
  - name: Plugins
    description: Plugin packages, access grants, and imports.
  - name: Marketplaces
    description: Marketplaces that distribute plugins to members and teams.
  - name: Resources
    description: >-
      Aggregated snapshot of the resources and marketplace capabilities
      available to the caller.
  - name: Dashboards
    description: Shared dashboards and their access grants.
  - name: Capability Sources
    description: >-
      Native provider capabilities (Google Workspace, Microsoft 365) and
      external MCP connections executed as the calling member.
  - name: Direct uploads
    description: Multipart uploads that stream workspace files straight to a provider.
  - name: Connectors
    description: >-
      Connector accounts and instances (GitHub and other sources) and their sync
      state.
  - name: GitHub
    description: >-
      GitHub App installation, repository discovery, and plugin import from
      GitHub.
  - name: Diagnostics
    description: Controlled egress diagnostics for self-hosted deployments.
  - name: Webhooks
    description: Signed inbound webhooks from third-party providers.
  - name: Admin
    description: Platform administration routes for allowlisted OpenWork administrators.
  - name: Deprecated
    description: Removed features that answer with 410 or an empty result for old clients.
paths:
  /v1/inference-providers/{inferenceProviderId}/litellm:
    patch:
      tags:
        - Inference Providers
      summary: Update LiteLLM key or key creation
      description: >-
        Verifies and stores a new organization LiteLLM key (org mode) or LiteLLM
        admin key (member and issued modes), and in issued mode changes how keys
        are created, then syncs. Changing issueStrategy replaces existing
        created keys at that sync. The proxy URL and mode are fixed; create a
        new provider to change them. Keys are write-only. Requires owner/admin
        and Gateway management; session callers must recently reauthenticate.
      operationId: patchV1InferenceProvidersByInferenceProviderIdLitellm
      parameters:
        - in: path
          name: inferenceProviderId
          schema:
            format: typeid
            type: string
            minLength: 30
            maxLength: 30
          required: true
          description: Den TypeID with 'ipr_' prefix and a 26-character base32 suffix.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                apiKey:
                  type: string
                  minLength: 1
                  maxLength: 4096
                issueStrategy:
                  type: string
                  enum:
                    - per_team
                    - mirror
                  description: >-
                    issued mode. per_team: one key per LiteLLM team the person
                    belongs to, or one key without a team when they are in none.
                    mirror: a copy of their oldest active key (team, models,
                    aliases, tags, expiry; never key-level budgets or rate
                    limits).
                mirrorFallback:
                  type: string
                  enum:
                    - per_team
                    - error
                  description: >-
                    issued + mirror: for someone with no key to copy, create
                    per-team keys, or report them and create nothing.
              additionalProperties: false
      responses:
        '200':
          description: Update LiteLLM key or key creation
          content:
            application/json:
              schema:
                type: object
                properties:
                  inferenceProvider:
                    $ref: '#/components/schemas/GatewayProviderDetails'
                  sync:
                    type: object
                    properties:
                      modelCount:
                        type: integer
                        minimum: -9007199254740991
                        maximum: 9007199254740991
                      groupCount:
                        type: integer
                        minimum: -9007199254740991
                        maximum: 9007199254740991
                      teamCount:
                        type: integer
                        minimum: -9007199254740991
                        maximum: 9007199254740991
                      members:
                        type: object
                        properties:
                          matched:
                            type: integer
                            minimum: -9007199254740991
                            maximum: 9007199254740991
                          rejected:
                            type: integer
                            minimum: -9007199254740991
                            maximum: 9007199254740991
                          unavailable:
                            type: integer
                            minimum: -9007199254740991
                            maximum: 9007199254740991
                          removed:
                            type: integer
                            minimum: -9007199254740991
                            maximum: 9007199254740991
                        required:
                          - matched
                          - rejected
                          - unavailable
                          - removed
                      warnings:
                        type: array
                        items:
                          type: string
                      issued:
                        type: object
                        properties:
                          people:
                            type: integer
                            minimum: -9007199254740991
                            maximum: 9007199254740991
                          keys:
                            type: integer
                            minimum: -9007199254740991
                            maximum: 9007199254740991
                          notInLiteLlm:
                            type: integer
                            minimum: -9007199254740991
                            maximum: 9007199254740991
                          noKeyToMirror:
                            type: integer
                            minimum: -9007199254740991
                            maximum: 9007199254740991
                          noModels:
                            type: integer
                            minimum: -9007199254740991
                            maximum: 9007199254740991
                          errors:
                            type: integer
                            minimum: -9007199254740991
                            maximum: 9007199254740991
                          removed:
                            type: integer
                            minimum: -9007199254740991
                            maximum: 9007199254740991
                        required:
                          - people
                          - keys
                          - notInLiteLlm
                          - noKeyToMirror
                          - noModels
                          - errors
                          - removed
                    required:
                      - modelCount
                      - groupCount
                      - teamCount
                      - members
                      - warnings
                required:
                  - inferenceProvider
                  - sync
        '400':
          description: Invalid request or provider configuration.
          content:
            application/json:
              schema:
                anyOf:
                  - $ref: '#/components/schemas/InvalidRequestError'
                  - type: object
                    properties:
                      error:
                        type: string
                      message:
                        type: string
                    required:
                      - error
        '401':
          description: Sign-in required.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UnauthorizedError'
        '403':
          description: Access denied or Gateway management disabled.
          content:
            application/json:
              schema:
                anyOf:
                  - $ref: '#/components/schemas/ForbiddenError'
                  - type: object
                    properties:
                      error:
                        type: string
                        const: gateway_not_enabled
                      message:
                        type: string
                    required:
                      - error
                      - message
        '404':
          description: Resource not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/NotFoundError'
        '409':
          description: Selection or resource conflict.
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                  message:
                    type: string
                required:
                  - error
      security:
        - bearerAuth: []
        - denApiKey: []
components:
  schemas:
    GatewayProviderDetails:
      type: object
      properties:
        modelIds:
          maxItems: 500
          type: array
          items:
            type: string
            minLength: 1
            maxLength: 255
          description: >-
            Provider universe policy: [] follows all supported catalog models;
            nonempty restricts to these IDs. Does not grant group membership.
        pinnedModelIds:
          type: array
          items:
            type: string
          description: >-
            Ordered catalog model IDs in management responses; only
            caller-usable gwm aliases in public list/connect responses. Pins
            never grant access.
        catalogWarning:
          type: string
        id:
          description: Den TypeID with 'ipr_' prefix and a 26-character base32 suffix.
          format: typeid
          type: string
          minLength: 30
          maxLength: 30
        providerId:
          type: string
        name:
          type: string
        source:
          type: string
          const: openwork_gateway
        credentialMode:
          type: string
          enum:
            - org
            - member
        credentialStatus:
          type: string
          enum:
            - ready
            - member_auth_required
            - org_credential_missing
        authUrl:
          anyOf:
            - type: string
            - type: 'null'
        status:
          type: string
          enum:
            - active
            - disabled
        updatedAt:
          type: string
          format: date-time
          pattern: >-
            ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
        providerConfig:
          type: object
          propertyNames:
            type: string
          additionalProperties: {}
        models:
          type: array
          items:
            type: object
            properties:
              id:
                type: string
              name:
                type: string
              config:
                type: object
                properties:
                  id:
                    type: string
                required:
                  - id
                additionalProperties: {}
              upstreamModelId:
                type: string
              modelGroupId:
                description: >-
                  Den TypeID with 'gmg_' prefix and a 26-character base32
                  suffix.
                format: typeid
                type: string
                minLength: 30
                maxLength: 30
              modelGroupName:
                type: string
              credentialSetId:
                description: >-
                  Den TypeID with 'gcs_' prefix and a 26-character base32
                  suffix.
                format: typeid
                type: string
                minLength: 30
                maxLength: 30
              credentialSetName:
                type: string
            required:
              - id
              - name
              - config
              - upstreamModelId
              - modelGroupId
              - modelGroupName
              - credentialSetId
              - credentialSetName
        authorizationRequests:
          type: array
          items:
            type: object
            properties:
              credentialSetId:
                description: >-
                  Den TypeID with 'gcs_' prefix and a 26-character base32
                  suffix.
                format: typeid
                type: string
                minLength: 30
                maxLength: 30
              name:
                type: string
              authUrl:
                type: string
              models:
                type: array
                items:
                  type: object
                  properties:
                    id:
                      type: string
                    name:
                      type: string
                    config:
                      type: object
                      properties:
                        id:
                          type: string
                      required:
                        - id
                      additionalProperties: {}
                    upstreamModelId:
                      type: string
                    modelGroupId:
                      description: >-
                        Den TypeID with 'gmg_' prefix and a 26-character base32
                        suffix.
                      format: typeid
                      type: string
                      minLength: 30
                      maxLength: 30
                    modelGroupName:
                      type: string
                    credentialSetId:
                      description: >-
                        Den TypeID with 'gcs_' prefix and a 26-character base32
                        suffix.
                      format: typeid
                      type: string
                      minLength: 30
                      maxLength: 30
                    credentialSetName:
                      type: string
                  required:
                    - id
                    - name
                    - config
                    - upstreamModelId
                    - modelGroupId
                    - modelGroupName
                    - credentialSetId
                    - credentialSetName
            required:
              - credentialSetId
              - name
              - authUrl
        migration:
          type: object
          properties:
            llmProviderId:
              description: Den TypeID with 'lpr_' prefix and a 26-character base32 suffix.
              format: typeid
              type: string
              minLength: 30
              maxLength: 30
            runtimeEnvNames:
              type: array
              items:
                type: string
          required:
            - llmProviderId
            - runtimeEnvNames
        litellm:
          $ref: '#/components/schemas/GatewayLiteLlmStatus'
        settings:
          type: object
          propertyNames:
            type: string
          additionalProperties: {}
        modelGroups:
          type: array
          items:
            type: object
            properties:
              name:
                type: string
                minLength: 1
                maxLength: 255
              description:
                anyOf:
                  - type: string
                  - type: 'null'
              modelIds:
                maxItems: 500
                type: array
                items:
                  type: string
                  minLength: 1
                  maxLength: 255
              status:
                type: string
                enum:
                  - active
                  - disabled
              id:
                description: >-
                  Den TypeID with 'gmg_' prefix and a 26-character base32
                  suffix.
                format: typeid
                type: string
                minLength: 30
                maxLength: 30
            required:
              - name
              - description
              - modelIds
              - status
              - id
            additionalProperties: false
        credentialSets:
          type: array
          items:
            type: object
            properties:
              id:
                description: >-
                  Den TypeID with 'gcs_' prefix and a 26-character base32
                  suffix.
                format: typeid
                type: string
                minLength: 30
                maxLength: 30
              name:
                type: string
              createdAt:
                type: string
                format: date-time
                pattern: >-
                  ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
              createdBy:
                anyOf:
                  - type: object
                    properties:
                      id:
                        description: >-
                          Den TypeID with 'om_' prefix and a 26-character base32
                          suffix.
                        format: typeid
                        type: string
                        minLength: 29
                        maxLength: 29
                      name:
                        anyOf:
                          - type: string
                          - type: 'null'
                      email:
                        anyOf:
                          - type: string
                          - type: 'null'
                    required:
                      - id
                      - name
                      - email
                  - type: 'null'
              credentialMode:
                type: string
                enum:
                  - org
                  - member
              status:
                type: string
                enum:
                  - active
                  - disabled
              configured:
                type: boolean
              credentialStatus:
                type: string
                enum:
                  - ready
                  - member_auth_required
                  - org_credential_missing
              oauthClientId:
                anyOf:
                  - type: string
                  - type: 'null'
              hasOauthClientSecret:
                type: boolean
            required:
              - id
              - name
              - credentialMode
              - status
              - configured
              - credentialStatus
        accessGrants:
          type: array
          items:
            type: object
            properties:
              modelGroupId:
                description: >-
                  Den TypeID with 'gmg_' prefix and a 26-character base32
                  suffix.
                format: typeid
                type: string
                minLength: 30
                maxLength: 30
              credentialSetId:
                description: >-
                  Den TypeID with 'gcs_' prefix and a 26-character base32
                  suffix.
                format: typeid
                type: string
                minLength: 30
                maxLength: 30
              audience:
                oneOf:
                  - type: object
                    properties:
                      type:
                        type: string
                        const: organization
                    required:
                      - type
                    additionalProperties: false
                  - type: object
                    properties:
                      type:
                        type: string
                        const: team
                      teamId:
                        description: >-
                          Den TypeID with 'tem_' prefix and a 26-character
                          base32 suffix.
                        format: typeid
                        type: string
                        minLength: 30
                        maxLength: 30
                    required:
                      - type
                      - teamId
                    additionalProperties: false
                  - type: object
                    properties:
                      type:
                        type: string
                        const: member
                      memberId:
                        description: >-
                          Den TypeID with 'om_' prefix and a 26-character base32
                          suffix.
                        format: typeid
                        type: string
                        minLength: 29
                        maxLength: 29
                    required:
                      - type
                      - memberId
                    additionalProperties: false
              id:
                description: >-
                  Den TypeID with 'ipa_' prefix and a 26-character base32
                  suffix.
                format: typeid
                type: string
                minLength: 30
                maxLength: 30
            required:
              - modelGroupId
              - credentialSetId
              - audience
              - id
            additionalProperties: false
        oauthCallbackUrl:
          type: string
        credentials:
          type: array
          items:
            type: object
            properties:
              id:
                description: >-
                  Den TypeID with 'ipc_' prefix and a 26-character base32
                  suffix.
                format: typeid
                type: string
                minLength: 30
                maxLength: 30
              credentialSetId:
                description: >-
                  Den TypeID with 'gcs_' prefix and a 26-character base32
                  suffix.
                format: typeid
                type: string
                minLength: 30
                maxLength: 30
              subject:
                type: string
              orgMembershipId:
                anyOf:
                  - description: >-
                      Den TypeID with 'om_' prefix and a 26-character base32
                      suffix.
                    format: typeid
                    type: string
                    minLength: 29
                    maxLength: 29
                  - type: 'null'
              memberName:
                anyOf:
                  - type: string
                  - type: 'null'
              memberEmail:
                anyOf:
                  - type: string
                  - type: 'null'
              kind:
                type: string
                enum:
                  - api_key
                  - api_key_map
                  - aws_keys
                  - gcp_service_account
                  - oauth_google
                  - oauth_azure
              status:
                type: string
                enum:
                  - active
                  - revoked
                  - refresh_failed
              expiresAt:
                anyOf:
                  - type: string
                    format: date-time
                    pattern: >-
                      ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
                  - type: 'null'
            required:
              - id
              - credentialSetId
              - subject
              - orgMembershipId
              - memberName
              - memberEmail
              - kind
              - status
              - expiresAt
      required:
        - modelIds
        - pinnedModelIds
        - id
        - providerId
        - name
        - source
        - credentialMode
        - credentialStatus
        - authUrl
        - status
        - updatedAt
        - providerConfig
        - models
        - authorizationRequests
        - settings
        - modelGroups
        - credentialSets
        - accessGrants
    InvalidRequestError:
      type: object
      properties:
        error:
          type: string
          const: invalid_request
        message:
          type: string
        details:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
              path:
                type: array
                items:
                  anyOf:
                    - type: string
                    - type: number
            required:
              - message
            additionalProperties: {}
        capability:
          type: string
      required:
        - error
        - details
    UnauthorizedError:
      type: object
      properties:
        error:
          type: string
          const: unauthorized
      required:
        - error
    ForbiddenError:
      type: object
      properties:
        error:
          type: string
          enum:
            - forbidden
            - reauth
        reason:
          type: string
        message:
          type: string
      required:
        - error
    NotFoundError:
      type: object
      properties:
        error:
          type: string
        message:
          type: string
      required:
        - error
    GatewayLiteLlmStatus:
      type: object
      properties:
        mode:
          type: string
          enum:
            - org
            - member
        keySource:
          anyOf:
            - type: string
              enum:
                - personal
                - issued
            - type: 'null'
        issueStrategy:
          anyOf:
            - type: string
              enum:
                - per_team
                - mirror
            - type: 'null'
        mirrorFallback:
          anyOf:
            - type: string
              enum:
                - per_team
                - error
            - type: 'null'
        issuedMemberCount:
          type: integer
          minimum: -9007199254740991
          maximum: 9007199254740991
        attentionCount:
          type: integer
          minimum: -9007199254740991
          maximum: 9007199254740991
        attention:
          type: array
          items:
            type: object
            properties:
              memberId:
                description: Den TypeID with 'om_' prefix and a 26-character base32 suffix.
                format: typeid
                type: string
                minLength: 29
                maxLength: 29
              name:
                anyOf:
                  - type: string
                  - type: 'null'
              email:
                anyOf:
                  - type: string
                  - type: 'null'
              reason:
                type: string
                enum:
                  - not_in_litellm
                  - no_key_to_mirror
                  - no_models
                  - error
            required:
              - memberId
              - name
              - email
              - reason
        baseUrl:
          anyOf:
            - type: string
            - type: 'null'
        spendTracking:
          type: boolean
        hasSyncKey:
          type: boolean
        lastSyncedAt:
          anyOf:
            - type: string
              format: date-time
              pattern: >-
                ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
            - type: 'null'
        lastSyncError:
          anyOf:
            - type: string
            - type: 'null'
        modelCount:
          type: integer
          minimum: -9007199254740991
          maximum: 9007199254740991
        teamCount:
          type: integer
          minimum: -9007199254740991
          maximum: 9007199254740991
        connectedMemberCount:
          type: integer
          minimum: -9007199254740991
          maximum: 9007199254740991
      required:
        - mode
        - keySource
        - issueStrategy
        - mirrorFallback
        - issuedMemberCount
        - attentionCount
        - attention
        - baseUrl
        - spendTracking
        - hasSyncKey
        - lastSyncedAt
        - lastSyncError
        - modelCount
        - teamCount
        - connectedMemberCount
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: session-token
      description: >-
        Session token passed as `Authorization: Bearer <session-token>` for
        user-authenticated Den routes.
    denApiKey:
      type: apiKey
      in: header
      name: x-api-key
      description: >-
        Organization API key passed as the `x-api-key` header. The raw key is
        the header value; do not prefix it with `Bearer`.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.