curl --request PATCH \
--url https://app.thinnest.ai/api/v1/byok/credentials/{kind} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"model": "gpt-5.4-mini",
"refreshModels": true
}
'const options = {
method: 'PATCH',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({model: 'gpt-5.4-mini', refreshModels: true})
};
fetch('https://app.thinnest.ai/api/v1/byok/credentials/{kind}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.thinnest.ai/api/v1/byok/credentials/{kind}"
payload = {
"model": "gpt-5.4-mini",
"refreshModels": True
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text){
"kind": "llm",
"provider": "openai",
"label": "OpenAI",
"key": "…Qw7m",
"fields": {
"model": "gpt-5.4-mini"
},
"model": "gpt-5.4-mini",
"models": [
"gpt-5.5",
"gpt-5.4",
"gpt-5.4-mini",
"gpt-5.4-nano"
],
"verifiedAt": "2026-10-06T10:01:40.902Z",
"updatedAt": "2026-10-06T11:18:03.226Z"
}Update BYOK Key Model
Changes the model a stored key runs without sending the key again. model must be on the key’s models; for a model the provider launched after you added the key, send refreshModels: true — alone, or with the new model, which is then checked against the fresh list. While BYOK is on, a refreshed list that drops the chosen model is refused. Needs a full key.
curl --request PATCH \
--url https://app.thinnest.ai/api/v1/byok/credentials/{kind} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"model": "gpt-5.4-mini",
"refreshModels": true
}
'const options = {
method: 'PATCH',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({model: 'gpt-5.4-mini', refreshModels: true})
};
fetch('https://app.thinnest.ai/api/v1/byok/credentials/{kind}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.thinnest.ai/api/v1/byok/credentials/{kind}"
payload = {
"model": "gpt-5.4-mini",
"refreshModels": True
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text){
"kind": "llm",
"provider": "openai",
"label": "OpenAI",
"key": "…Qw7m",
"fields": {
"model": "gpt-5.4-mini"
},
"model": "gpt-5.4-mini",
"models": [
"gpt-5.5",
"gpt-5.4",
"gpt-5.4-mini",
"gpt-5.4-nano"
],
"verifiedAt": "2026-10-06T10:01:40.902Z",
"updatedAt": "2026-10-06T11:18:03.226Z"
}Authorizations
Your API key (ta_live_…) from Settings → API keys, sent as Authorization: Bearer <key>. Keep it on a server: it can message every customer you have. A key is full, build or read-only; a request its level does not allow is refused with 403.
Headers
Developers only: the customer workspace this request acts in — its org_… id from POST /customers. Leave it out to act in your own workspace.
"org_3fKq9TzQ1mN8vB2xR7cLpA"
Path Parameters
Which key: stt (speech-to-text), llm or tts (voice).
stt, llm, tts Body
Response
The key after the change, masked.
One of your own provider keys, masked.
Its job: speech-to-text, LLM or voice.
stt, llm, tts The provider's id, e.g. deepgram.
The provider's name as the console shows it.
The key's last four characters after … — never more.
"…k9z2"
The key's other settings, as stored: model, region, endpoint or baseUrl. The secret is never among them.
Show child attributes
Show child attributes
The model this key runs, or null while one is still to be chosen (or for a provider with no model to choose, such as Azure Speech).
What the provider offered this key when it was added or last refreshed.
When the provider last accepted the key.
When the key or its model last changed.