ai.keys.save
Save or replace this organization's key for one AI provider, at the current revision (0 for the first key). Oatmilk checks the key with the provider first and saves it encrypted. Administrators only, from the dashboard.
/api/v1/accounting/ai.keys.savePermissions
Who can call it
Retries
MCP
Fields
providerenumRequiredtypesafe-aigatewayopenaigooglezaiapiKeystringRequired8–500 characters · Matches ^\S+$
expectedRevisionintegerRequiredThe record's current revision, from the last time you read it. If someone changed the record since, the request is refused with a conflict so you can reload and check before trying again.
0 to 9007199254740991
idempotencyKeystringRequiredAny unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match.
8–200 characters
Example
curl https://app.getoatmilk.com/api/v1/accounting/ai.keys.save \
-H "Authorization: Bearer $OATMILK_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: $(uuidgen)" \
-d '{
"provider": "typesafe-ai",
"apiKey": "api_key",
"expectedRevision": 3
}'{
"data": { … }
}This action checks your data too, so replace the example values with your own before sending it.
Try it
Try it
Checks your input with this action’s real schema and answers like the API, with synthetic data. No key needed, and nothing changes.
curl https://app.getoatmilk.com/api/v1/accounting/ai.keys.save \
-H "Authorization: Bearer $OATMILK_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: $(uuidgen)" \
-d '{
"provider": "typesafe-ai",
"apiKey": "api_key",
"expectedRevision": 3
}'More in AI and memory.