> ## Documentation Index
> Fetch the complete documentation index at: https://openworklabs.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# List organization inference gateway providers

> Defaults to scope=usable: returns active providers granted to the caller through active model groups and credential sets, with usable model aliases and any member authorization requests. A granted provider can remain discoverable with no usable models. scope=manageable requires owner/admin permission and enabled Gateway management, and returns provider details including disabled providers; credential secrets are never returned.



## OpenAPI

````yaml /openapi.json get /v1/inference-providers
openapi: 3.1.0
info:
  title: Den API
  description: >-
    OpenAPI spec for the Den control plane API.


    Authentication:

    - Use `Authorization: Bearer <session-token>` for user-authenticated routes
    that require a Den session.

    - Use `x-api-key: <den-api-key>` for organization API-key calls. API keys
    resolve to the issuing user and the organization member they were scoped to
    when created, so they can call ordinary user and organization routes without
    a separate signed-in session.
      Example: `curl https://api.openworklabs.com/v1/me -H "x-api-key: den_..."`.
    - Session-only flows still require a signed-in user session, including
    organization creation, invitation acceptance, active-organization switching,
    and MCP token minting.

    - Public routes like health and documentation do not require authentication.


    Swagger tip: use the security schemes in the Authorize dialog to set either
    `bearerAuth` or `denApiKey` before trying protected endpoints.
  version: 0.18.46
  contact:
    name: OpenWork
    url: https://openworklabs.com
    email: team@openworklabs.com
  license:
    name: OpenWork Enterprise Edition License
    url: https://github.com/different-ai/openwork/blob/dev/ee/LICENSE
servers:
  - url: https://api.openworklabs.com
security:
  - bearerAuth: []
  - denApiKey: []
tags:
  - name: System
    description: >-
      Service health, readiness, API documentation, and desktop version
      metadata.
  - name: Authentication
    description: >-
      Sign-in discovery, administrator bootstrap, OAuth provider connections,
      and MCP token minting.
  - name: OAuth
    description: >-
      OAuth 2.0 / OpenID Connect authorization-server and protected-resource
      metadata and dynamic client registration (RFC 8414, RFC 9728, RFC 7591),
      used by MCP clients.
  - name: SCIM
    description: >-
      SCIM 2.0 provisioning endpoints for identity providers (RFC 7644) and the
      organization SCIM connector management routes.
  - name: SSO
    description: Organization single sign-on connector management routes.
  - name: Bootstrap
    description: Agent-first provisional workspace setup routes.
  - name: Users
    description: Current user and membership routes.
  - name: Organizations
    description: Organization creation, context, brand assets, and install links.
  - name: Invitations
    description: Invitation preview, acceptance, creation, and cancellation routes.
  - name: Members
    description: Organization member management routes.
  - name: Roles
    description: Organization custom role management routes.
  - name: Teams
    description: Organization team management routes.
  - name: API Keys
    description: Organization API key management routes.
  - name: Desktop Policies
    description: Desktop app policies applied to the organization, members, or teams.
  - name: LLM Providers
    description: Organization LLM provider catalog, configuration, and access routes.
  - name: Inference
    description: Organization inference settings.
  - name: Inference Providers
    description: >-
      Organization inference Gateway providers, model groups, credential sets,
      access grants, member connections, and usage.
  - name: Cloud
    description: Organization Cloud instance lifecycle and browser gateway resolution.
  - name: Workers
    description: Worker lifecycle, billing, and runtime routes.
  - name: Worker Runtime
    description: Worker runtime inspection and upgrade routes.
  - name: Worker Activity
    description: Worker heartbeat and activity reporting routes.
  - name: Automations
    description: Scheduled Automations, their runs, and desktop runner presence.
  - name: Workflows
    description: Saved Workflows (Code Mode scripts), their versions, snapshots, and views.
  - name: Workflow Runs
    description: Durable Workflow run history.
  - name: Codemode Runs
    description: Generated Artifact views produced by Code Mode runs.
  - name: Apps
    description: >-
      Saved reusable apps built from Workflows and Artifact views, and their
      sharing.
  - name: Config Objects
    description: >-
      Versioned configuration objects (skills, workflows, and other plugin
      content).
  - name: Plugins
    description: Plugin packages, access grants, and imports.
  - name: Marketplaces
    description: Marketplaces that distribute plugins to members and teams.
  - name: Resources
    description: >-
      Aggregated snapshot of the resources and marketplace capabilities
      available to the caller.
  - name: Dashboards
    description: Shared dashboards and their access grants.
  - name: Capability Sources
    description: >-
      Native provider capabilities (Google Workspace, Microsoft 365) and
      external MCP connections executed as the calling member.
  - name: Direct uploads
    description: Multipart uploads that stream workspace files straight to a provider.
  - name: Connectors
    description: >-
      Connector accounts and instances (GitHub and other sources) and their sync
      state.
  - name: GitHub
    description: >-
      GitHub App installation, repository discovery, and plugin import from
      GitHub.
  - name: Diagnostics
    description: Controlled egress diagnostics for self-hosted deployments.
  - name: Telemetry
    description: Telemetry event ingestion and adoption analytics.
  - name: Webhooks
    description: Signed inbound webhooks from third-party providers.
  - name: Admin
    description: Platform administration routes for allowlisted OpenWork administrators.
  - name: Deprecated
    description: Removed features that answer with 410 or an empty result for old clients.
paths:
  /v1/inference-providers:
    get:
      tags:
        - Inference Providers
      summary: List organization inference gateway providers
      description: >-
        Defaults to scope=usable: returns active providers granted to the caller
        through active model groups and credential sets, with usable model
        aliases and any member authorization requests. A granted provider can
        remain discoverable with no usable models. scope=manageable requires
        owner/admin permission and enabled Gateway management, and returns
        provider details including disabled providers; credential secrets are
        never returned.
      operationId: getV1InferenceProviders
      parameters:
        - in: query
          name: scope
          schema:
            default: usable
            type: string
            enum:
              - usable
              - manageable
      responses:
        '200':
          description: List organization inference gateway providers
          content:
            application/json:
              schema:
                type: object
                properties:
                  inferenceProviders:
                    type: array
                    items:
                      anyOf:
                        - $ref: '#/components/schemas/GatewayProviderDetails'
                        - $ref: '#/components/schemas/GatewayProviderSummary'
                required:
                  - inferenceProviders
        '400':
          description: Invalid request or provider configuration.
          content:
            application/json:
              schema:
                anyOf:
                  - $ref: '#/components/schemas/InvalidRequestError'
                  - type: object
                    properties:
                      error:
                        type: string
                      message:
                        type: string
                    required:
                      - error
        '401':
          description: Sign-in required.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UnauthorizedError'
        '403':
          description: Access denied or Gateway management disabled.
          content:
            application/json:
              schema:
                anyOf:
                  - $ref: '#/components/schemas/ForbiddenError'
                  - type: object
                    properties:
                      error:
                        type: string
                        const: gateway_not_enabled
                      message:
                        type: string
                    required:
                      - error
                      - message
        '404':
          description: Resource not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/NotFoundError'
        '409':
          description: Selection or resource conflict.
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                  message:
                    type: string
                required:
                  - error
      security:
        - bearerAuth: []
        - denApiKey: []
components:
  schemas:
    GatewayProviderDetails:
      type: object
      properties:
        modelIds:
          maxItems: 500
          type: array
          items:
            type: string
            minLength: 1
            maxLength: 255
          description: >-
            Provider universe policy: [] follows all supported catalog models;
            nonempty restricts to these IDs. Does not grant group membership.
        catalogWarning:
          type: string
        id:
          description: Den TypeID with 'ipr_' prefix and a 26-character base32 suffix.
          format: typeid
          type: string
          minLength: 30
          maxLength: 30
        providerId:
          type: string
        name:
          type: string
        source:
          type: string
          const: openwork_gateway
        credentialMode:
          type: string
          enum:
            - org
            - member
        credentialStatus:
          type: string
          enum:
            - ready
            - member_auth_required
            - org_credential_missing
        authUrl:
          anyOf:
            - type: string
            - type: 'null'
        status:
          type: string
          enum:
            - active
            - disabled
        updatedAt:
          type: string
          format: date-time
          pattern: >-
            ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
        providerConfig:
          type: object
          propertyNames:
            type: string
          additionalProperties: {}
        models:
          type: array
          items:
            type: object
            properties:
              id:
                type: string
              name:
                type: string
              config:
                type: object
                properties:
                  id:
                    type: string
                required:
                  - id
                additionalProperties: {}
              upstreamModelId:
                type: string
              modelGroupId:
                description: >-
                  Den TypeID with 'gmg_' prefix and a 26-character base32
                  suffix.
                format: typeid
                type: string
                minLength: 30
                maxLength: 30
              modelGroupName:
                type: string
              credentialSetId:
                description: >-
                  Den TypeID with 'gcs_' prefix and a 26-character base32
                  suffix.
                format: typeid
                type: string
                minLength: 30
                maxLength: 30
              credentialSetName:
                type: string
            required:
              - id
              - name
              - config
              - upstreamModelId
              - modelGroupId
              - modelGroupName
              - credentialSetId
              - credentialSetName
        authorizationRequests:
          type: array
          items:
            type: object
            properties:
              credentialSetId:
                description: >-
                  Den TypeID with 'gcs_' prefix and a 26-character base32
                  suffix.
                format: typeid
                type: string
                minLength: 30
                maxLength: 30
              name:
                type: string
              authUrl:
                type: string
            required:
              - credentialSetId
              - name
              - authUrl
        migration:
          type: object
          properties:
            llmProviderId:
              description: Den TypeID with 'lpr_' prefix and a 26-character base32 suffix.
              format: typeid
              type: string
              minLength: 30
              maxLength: 30
            runtimeEnvNames:
              type: array
              items:
                type: string
          required:
            - llmProviderId
            - runtimeEnvNames
        settings:
          type: object
          propertyNames:
            type: string
          additionalProperties: {}
        modelGroups:
          type: array
          items:
            type: object
            properties:
              name:
                type: string
                minLength: 1
                maxLength: 255
              description:
                anyOf:
                  - type: string
                  - type: 'null'
              modelIds:
                maxItems: 500
                type: array
                items:
                  type: string
                  minLength: 1
                  maxLength: 255
              status:
                type: string
                enum:
                  - active
                  - disabled
              id:
                description: >-
                  Den TypeID with 'gmg_' prefix and a 26-character base32
                  suffix.
                format: typeid
                type: string
                minLength: 30
                maxLength: 30
            required:
              - name
              - description
              - modelIds
              - status
              - id
            additionalProperties: false
        credentialSets:
          type: array
          items:
            type: object
            properties:
              id:
                description: >-
                  Den TypeID with 'gcs_' prefix and a 26-character base32
                  suffix.
                format: typeid
                type: string
                minLength: 30
                maxLength: 30
              name:
                type: string
              createdAt:
                type: string
                format: date-time
                pattern: >-
                  ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
              createdBy:
                anyOf:
                  - type: object
                    properties:
                      id:
                        description: >-
                          Den TypeID with 'om_' prefix and a 26-character base32
                          suffix.
                        format: typeid
                        type: string
                        minLength: 29
                        maxLength: 29
                      name:
                        anyOf:
                          - type: string
                          - type: 'null'
                      email:
                        anyOf:
                          - type: string
                          - type: 'null'
                    required:
                      - id
                      - name
                      - email
                  - type: 'null'
              credentialMode:
                type: string
                enum:
                  - org
                  - member
              status:
                type: string
                enum:
                  - active
                  - disabled
              configured:
                type: boolean
              credentialStatus:
                type: string
                enum:
                  - ready
                  - member_auth_required
                  - org_credential_missing
              oauthClientId:
                anyOf:
                  - type: string
                  - type: 'null'
              hasOauthClientSecret:
                type: boolean
            required:
              - id
              - name
              - credentialMode
              - status
              - configured
              - credentialStatus
        accessGrants:
          type: array
          items:
            type: object
            properties:
              modelGroupId:
                description: >-
                  Den TypeID with 'gmg_' prefix and a 26-character base32
                  suffix.
                format: typeid
                type: string
                minLength: 30
                maxLength: 30
              credentialSetId:
                description: >-
                  Den TypeID with 'gcs_' prefix and a 26-character base32
                  suffix.
                format: typeid
                type: string
                minLength: 30
                maxLength: 30
              audience:
                oneOf:
                  - type: object
                    properties:
                      type:
                        type: string
                        const: organization
                    required:
                      - type
                    additionalProperties: false
                  - type: object
                    properties:
                      type:
                        type: string
                        const: team
                      teamId:
                        description: >-
                          Den TypeID with 'tem_' prefix and a 26-character
                          base32 suffix.
                        format: typeid
                        type: string
                        minLength: 30
                        maxLength: 30
                    required:
                      - type
                      - teamId
                    additionalProperties: false
                  - type: object
                    properties:
                      type:
                        type: string
                        const: member
                      memberId:
                        description: >-
                          Den TypeID with 'om_' prefix and a 26-character base32
                          suffix.
                        format: typeid
                        type: string
                        minLength: 29
                        maxLength: 29
                    required:
                      - type
                      - memberId
                    additionalProperties: false
              id:
                description: >-
                  Den TypeID with 'ipa_' prefix and a 26-character base32
                  suffix.
                format: typeid
                type: string
                minLength: 30
                maxLength: 30
            required:
              - modelGroupId
              - credentialSetId
              - audience
              - id
            additionalProperties: false
        oauthCallbackUrl:
          type: string
        credentials:
          type: array
          items:
            type: object
            properties:
              id:
                description: >-
                  Den TypeID with 'ipc_' prefix and a 26-character base32
                  suffix.
                format: typeid
                type: string
                minLength: 30
                maxLength: 30
              credentialSetId:
                description: >-
                  Den TypeID with 'gcs_' prefix and a 26-character base32
                  suffix.
                format: typeid
                type: string
                minLength: 30
                maxLength: 30
              subject:
                type: string
              orgMembershipId:
                anyOf:
                  - description: >-
                      Den TypeID with 'om_' prefix and a 26-character base32
                      suffix.
                    format: typeid
                    type: string
                    minLength: 29
                    maxLength: 29
                  - type: 'null'
              memberName:
                anyOf:
                  - type: string
                  - type: 'null'
              memberEmail:
                anyOf:
                  - type: string
                  - type: 'null'
              kind:
                type: string
                enum:
                  - api_key
                  - api_key_map
                  - aws_keys
                  - gcp_service_account
                  - oauth_google
                  - oauth_azure
              status:
                type: string
                enum:
                  - active
                  - revoked
                  - refresh_failed
              expiresAt:
                anyOf:
                  - type: string
                    format: date-time
                    pattern: >-
                      ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
                  - type: 'null'
            required:
              - id
              - credentialSetId
              - subject
              - orgMembershipId
              - memberName
              - memberEmail
              - kind
              - status
              - expiresAt
      required:
        - modelIds
        - id
        - providerId
        - name
        - source
        - credentialMode
        - credentialStatus
        - authUrl
        - status
        - updatedAt
        - providerConfig
        - models
        - authorizationRequests
        - settings
        - modelGroups
        - credentialSets
        - accessGrants
    GatewayProviderSummary:
      type: object
      properties:
        modelIds:
          maxItems: 500
          type: array
          items:
            type: string
            minLength: 1
            maxLength: 255
          description: >-
            Provider universe policy: [] follows all supported catalog models;
            nonempty restricts to these IDs. Does not grant group membership.
        catalogWarning:
          type: string
        id:
          description: Den TypeID with 'ipr_' prefix and a 26-character base32 suffix.
          format: typeid
          type: string
          minLength: 30
          maxLength: 30
        providerId:
          type: string
        name:
          type: string
        source:
          type: string
          const: openwork_gateway
        credentialMode:
          type: string
          enum:
            - org
            - member
        credentialStatus:
          type: string
          enum:
            - ready
            - member_auth_required
            - org_credential_missing
        authUrl:
          anyOf:
            - type: string
            - type: 'null'
        status:
          type: string
          enum:
            - active
            - disabled
        updatedAt:
          type: string
          format: date-time
          pattern: >-
            ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
        providerConfig:
          type: object
          propertyNames:
            type: string
          additionalProperties: {}
        models:
          type: array
          items:
            type: object
            properties:
              id:
                type: string
              name:
                type: string
              config:
                type: object
                properties:
                  id:
                    type: string
                required:
                  - id
                additionalProperties: {}
              upstreamModelId:
                type: string
              modelGroupId:
                description: >-
                  Den TypeID with 'gmg_' prefix and a 26-character base32
                  suffix.
                format: typeid
                type: string
                minLength: 30
                maxLength: 30
              modelGroupName:
                type: string
              credentialSetId:
                description: >-
                  Den TypeID with 'gcs_' prefix and a 26-character base32
                  suffix.
                format: typeid
                type: string
                minLength: 30
                maxLength: 30
              credentialSetName:
                type: string
            required:
              - id
              - name
              - config
              - upstreamModelId
              - modelGroupId
              - modelGroupName
              - credentialSetId
              - credentialSetName
        authorizationRequests:
          type: array
          items:
            type: object
            properties:
              credentialSetId:
                description: >-
                  Den TypeID with 'gcs_' prefix and a 26-character base32
                  suffix.
                format: typeid
                type: string
                minLength: 30
                maxLength: 30
              name:
                type: string
              authUrl:
                type: string
            required:
              - credentialSetId
              - name
              - authUrl
        migration:
          type: object
          properties:
            llmProviderId:
              description: Den TypeID with 'lpr_' prefix and a 26-character base32 suffix.
              format: typeid
              type: string
              minLength: 30
              maxLength: 30
            runtimeEnvNames:
              type: array
              items:
                type: string
          required:
            - llmProviderId
            - runtimeEnvNames
      required:
        - modelIds
        - id
        - providerId
        - name
        - source
        - credentialMode
        - credentialStatus
        - authUrl
        - status
        - updatedAt
        - providerConfig
        - models
        - authorizationRequests
    InvalidRequestError:
      type: object
      properties:
        error:
          type: string
          const: invalid_request
        details:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
              path:
                type: array
                items:
                  anyOf:
                    - type: string
                    - type: number
            required:
              - message
            additionalProperties: {}
        capability:
          type: string
      required:
        - error
        - details
    UnauthorizedError:
      type: object
      properties:
        error:
          type: string
          const: unauthorized
      required:
        - error
    ForbiddenError:
      type: object
      properties:
        error:
          type: string
          enum:
            - forbidden
            - reauth
        reason:
          type: string
        message:
          type: string
      required:
        - error
    NotFoundError:
      type: object
      properties:
        error:
          type: string
        message:
          type: string
      required:
        - error
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: session-token
      description: >-
        Session token passed as `Authorization: Bearer <session-token>` for
        user-authenticated Den routes.
    denApiKey:
      type: apiKey
      in: header
      name: x-api-key
      description: >-
        Organization API key passed as the `x-api-key` header. The raw key is
        the header value; do not prefix it with `Bearer`.

````