curl --request GET \
--url https://app.thinnest.ai/api/v1/byok \
--header 'Authorization: Bearer <token>'const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://app.thinnest.ai/api/v1/byok', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.thinnest.ai/api/v1/byok"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text){
"enabled": true,
"using": "own",
"complete": true,
"credentials": [
{
"kind": "stt",
"provider": "deepgram",
"label": "Deepgram",
"key": "…k9z2",
"fields": {
"model": "nova-3-general"
},
"model": "nova-3-general",
"models": [
"flux-general-en",
"nova-3-general",
"nova-3-medical",
"nova-2-general"
],
"verifiedAt": "2026-10-06T10:00:12.441Z",
"updatedAt": "2026-10-06T10:00:12.441Z"
},
{
"kind": "llm",
"provider": "openai",
"label": "OpenAI",
"key": "…Qw7m",
"fields": {
"model": "gpt-5.4-nano"
},
"model": "gpt-5.4-nano",
"models": [
"gpt-5.4",
"gpt-5.4-mini",
"gpt-5.4-nano",
"gpt-4.1-mini"
],
"verifiedAt": "2026-10-06T10:01:40.902Z",
"updatedAt": "2026-10-06T10:01:40.902Z"
},
{
"kind": "tts",
"provider": "elevenlabs",
"label": "ElevenLabs",
"key": "…3c1d",
"fields": {
"model": "eleven_flash_v2_5"
},
"model": "eleven_flash_v2_5",
"models": [
"eleven_flash_v2_5",
"eleven_turbo_v2_5",
"eleven_multilingual_v2"
],
"verifiedAt": "2026-10-06T10:02:05.117Z",
"updatedAt": "2026-10-06T10:02:05.117Z"
}
]
}{
"error": "Send a valid API key as `Authorization: Bearer <key>`."
}{
"error": "Over 240 requests a minute. Slow down and retry."
}Get BYOK Status
Whether your workspace runs on its own keys, whose keys are in use (own, or developer for a customer using its developer’s), whether your three keys are complete enough to switch on, and each key, masked to its last four characters.
curl --request GET \
--url https://app.thinnest.ai/api/v1/byok \
--header 'Authorization: Bearer <token>'const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://app.thinnest.ai/api/v1/byok', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.thinnest.ai/api/v1/byok"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text){
"enabled": true,
"using": "own",
"complete": true,
"credentials": [
{
"kind": "stt",
"provider": "deepgram",
"label": "Deepgram",
"key": "…k9z2",
"fields": {
"model": "nova-3-general"
},
"model": "nova-3-general",
"models": [
"flux-general-en",
"nova-3-general",
"nova-3-medical",
"nova-2-general"
],
"verifiedAt": "2026-10-06T10:00:12.441Z",
"updatedAt": "2026-10-06T10:00:12.441Z"
},
{
"kind": "llm",
"provider": "openai",
"label": "OpenAI",
"key": "…Qw7m",
"fields": {
"model": "gpt-5.4-nano"
},
"model": "gpt-5.4-nano",
"models": [
"gpt-5.4",
"gpt-5.4-mini",
"gpt-5.4-nano",
"gpt-4.1-mini"
],
"verifiedAt": "2026-10-06T10:01:40.902Z",
"updatedAt": "2026-10-06T10:01:40.902Z"
},
{
"kind": "tts",
"provider": "elevenlabs",
"label": "ElevenLabs",
"key": "…3c1d",
"fields": {
"model": "eleven_flash_v2_5"
},
"model": "eleven_flash_v2_5",
"models": [
"eleven_flash_v2_5",
"eleven_turbo_v2_5",
"eleven_multilingual_v2"
],
"verifiedAt": "2026-10-06T10:02:05.117Z",
"updatedAt": "2026-10-06T10:02:05.117Z"
}
]
}{
"error": "Send a valid API key as `Authorization: Bearer <key>`."
}{
"error": "Over 240 requests a minute. Slow down and retry."
}Authorizations
Your API key (ta_live_…) from Settings → API keys, sent as Authorization: Bearer <key>. Keep it on a server: it can message every customer you have. A key is full, build or read-only; a request its level does not allow is refused with 403.
Headers
Developers only: the customer workspace this request acts in — its org_… id from POST /customers. Leave it out to act in your own workspace.
"org_3fKq9TzQ1mN8vB2xR7cLpA"
Response
The workspace's BYOK state.
Whether this workspace has switched its own keys on.
Whose keys calls and replies use right now: this workspace's, its developer's (a customer inheriting them), or none.
own, developer, none Whether this workspace's own three keys are verified and each has a model — what turning BYOK on needs.
This workspace's own keys, masked.
Show child attributes
Show child attributes