openapi: 3.1.0 info: contact: email: support@konghq.com name: Kong Inc url: https://konghq.com description: 'OpenAPI 3.0 spec for Kong Gateway''s Admin API. You can learn more about Kong Gateway at [developer.konghq.com](https://developer.konghq.com). Give Kong a star at the [Kong/kong](https://github.com/kong/kong) repository.' license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0.html title: Kong Enterprise Admin ACLs Partials API version: 3.14.0 servers: - description: Default Admin API URL url: '{protocol}://{hostname}:{port}{path}' variables: hostname: default: localhost description: Hostname for Kong's Admin API path: default: / description: Base path for Kong's Admin API port: default: '8001' description: Port for Kong's Admin API protocol: default: http description: Protocol for requests to Kong's Admin API enum: - http - https security: - adminToken: [] tags: - description: Some entities in Kong Gateway share common configuration settings that often need to be repeated. For example, multiple plugins that connect to Redis may require the same connection settings. Without Partials, you would need to replicate this configuration across all plugins. If the settings change, you would need to update each plugin individually. name: Partials paths: /{workspace}/partials: post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: Partial#create operationId: create-partial summary: Create a new Partial description: Create a new Partial parameters: - $ref: '#/components/parameters/Workspace' requestBody: description: Description of the new Partial for creation required: true content: application/json: schema: $ref: '#/components/schemas/Partial' responses: '201': description: Successfully created Partial content: application/json: schema: $ref: '#/components/schemas/Partial' '401': $ref: '#/components/responses/HTTP401Error' tags: - Partials /{workspace}/partials/{PartialId}: parameters: - $ref: '#/components/parameters/PartialId' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: Partial#delete operationId: delete-partial summary: Delete a Partial description: Delete a Partial parameters: - $ref: '#/components/parameters/PartialId' - $ref: '#/components/parameters/Workspace' responses: '204': description: Successfully deleted Partial or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Partials get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: Partial#read operationId: get-partial summary: Get a Partial description: Get a Partial using ID. parameters: - $ref: '#/components/parameters/Workspace' responses: '200': description: Successfully fetched Partial content: application/json: schema: $ref: '#/components/schemas/Partial' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Partials put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: Partial#update operationId: upsert-partial summary: Upsert a Partial description: Create or Update Partial using ID. parameters: - $ref: '#/components/parameters/Workspace' requestBody: description: Description of the Partial required: true content: application/json: schema: $ref: '#/components/schemas/Partial' responses: '200': description: Successfully upserted Partial content: application/json: schema: $ref: '#/components/schemas/Partial' '401': $ref: '#/components/responses/HTTP401Error' tags: - Partials /v2/control-planes/{controlPlaneId}/core-entities/partials: parameters: - $ref: '#/components/parameters/controlPlaneId' get: operationId: list-partial summary: List all Partials description: List all Partials parameters: - $ref: '#/components/parameters/PaginationSize' - $ref: '#/components/parameters/PaginationOffset' - $ref: '#/components/parameters/PaginationTagsFilter' responses: '200': description: A successful response listing Partials content: application/json: schema: type: object properties: data: type: array items: $ref: '#/components/schemas/Partial_2' next: $ref: '#/components/schemas/PaginationNextResponse' offset: $ref: '#/components/schemas/PaginationOffsetResponse' '401': $ref: '#/components/responses/HTTP401Error_2' tags: - Partials post: operationId: create-partial summary: Create a new Partial description: Create a new Partial requestBody: description: Description of the new Partial for creation required: true content: application/json: schema: $ref: '#/components/schemas/Partial_2' responses: '201': description: Successfully created Partial content: application/json: schema: $ref: '#/components/schemas/Partial_2' '401': $ref: '#/components/responses/HTTP401Error_2' tags: - Partials /v2/control-planes/{controlPlaneId}/core-entities/partials/{PartialId}: parameters: - $ref: '#/components/parameters/PartialId_2' - $ref: '#/components/parameters/controlPlaneId' delete: operationId: delete-partial summary: Delete a Partial description: Delete a Partial parameters: - $ref: '#/components/parameters/PartialId_2' responses: '204': description: Successfully deleted Partial or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error_2' tags: - Partials get: operationId: get-partial summary: Get a Partial description: Get a Partial using ID. responses: '200': description: Successfully fetched Partial content: application/json: schema: $ref: '#/components/schemas/Partial_2' '401': $ref: '#/components/responses/HTTP401Error_2' '404': description: Resource does not exist tags: - Partials put: operationId: upsert-partial summary: Upsert a Partial description: Create or Update Partial using ID. requestBody: description: Description of the Partial required: true content: application/json: schema: $ref: '#/components/schemas/Partial_2' responses: '200': description: Successfully upserted Partial content: application/json: schema: $ref: '#/components/schemas/Partial_2' '401': $ref: '#/components/responses/HTTP401Error_2' tags: - Partials components: schemas: Partial: x-speakeasy-entity: Partial type: object discriminator: mapping: embeddings: '#/components/schemas/PartialEmbeddings' model: '#/components/schemas/PartialModel' redis-ce: '#/components/schemas/PartialRedisCe' redis-ee: '#/components/schemas/PartialRedisEe' vectordb: '#/components/schemas/PartialVectordb' propertyName: type oneOf: - $ref: '#/components/schemas/PartialRedisCe' - $ref: '#/components/schemas/PartialRedisEe' - $ref: '#/components/schemas/PartialVectordb' - $ref: '#/components/schemas/PartialEmbeddings' - $ref: '#/components/schemas/PartialModel' PartialRedisEe_2: type: object properties: config: type: object properties: cloud_authentication: description: Cloud auth related configs for connecting to a Cloud Provider's Redis instance. type: object properties: auth_provider: description: Auth providers to be used to authenticate to a Cloud Provider's Redis instance. type: string enum: - aws - azure - gcp x-referenceable: true x-speakeasy-unknown-values: allow aws_access_key_id: description: AWS Access Key ID to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true aws_assume_role_arn: description: The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens. type: string x-encrypted: true x-referenceable: true aws_cache_name: description: The name of the AWS Elasticache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_is_serverless: description: This flag specifies whether the cluster is serverless when auth_provider is set to `aws`. type: boolean default: true aws_region: description: The region of the AWS ElastiCache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_role_session_name: description: The session name for the temporary credentials when assuming the IAM role. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: AWS Secret Access Key to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true azure_client_id: description: Azure Client ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_client_secret: description: Azure Client Secret to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: Azure Tenant ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true gcp_service_account_json: description: GCP Service Account JSON to be used for authentication when `auth_provider` is set to `gcp`. type: string x-encrypted: true x-referenceable: true cluster_max_redirections: description: Maximum retry attempts for redirection. type: integer default: 5 cluster_nodes: description: Cluster addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element. type: array items: properties: ip: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 connect_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 connection_is_proxied: description: If the connection to Redis is proxied (e.g. Envoy), set it `true`. Set the `host` and `port` to point to the proxy address. type: boolean default: false database: description: Database to use for the Redis connection when using the `redis` strategy type: integer default: 0 host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 x-referenceable: true keepalive_backlog: description: Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return `nil`. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than `keepalive_pool_size`. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than `keepalive_pool_size`. type: integer maximum: 2147483646 minimum: 0 keepalive_pool_size: description: The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither `keepalive_pool_size` nor `keepalive_backlog` is specified, no pool is created. If `keepalive_pool_size` isn't specified but `keepalive_backlog` is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. type: integer default: 256 maximum: 2147483646 minimum: 1 password: description: Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis. type: string x-encrypted: true x-referenceable: true port: description: An integer representing a port number between 0 and 65535, inclusive. type: - integer - string default: 6379 maximum: 65535 minimum: 0 x-referenceable: true read_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 send_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 sentinel_master: description: Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel. type: string sentinel_nodes: description: Sentinel node addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element. type: array items: properties: host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 sentinel_password: description: Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels. type: string x-encrypted: true x-referenceable: true sentinel_role: description: Sentinel role to use for Redis connections when the `redis` strategy is defined. Defining this value implies using Redis Sentinel. type: string enum: - any - master - slave x-speakeasy-unknown-values: allow sentinel_username: description: Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+. type: string x-referenceable: true server_name: description: A string representing an SNI (server name indication) value for TLS. type: string x-referenceable: true ssl: description: If set to true, uses SSL to connect to Redis. type: boolean default: false ssl_verify: description: If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure `lua_ssl_trusted_certificate` in `kong.conf` to specify the CA (or server) certificate used by your Redis server. You may also need to configure `lua_ssl_verify_depth` accordingly. type: boolean default: true username: description: Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to `default`. type: string x-referenceable: true created_at: description: Unix epoch when the resource was created. type: integer nullable: true id: description: A string representing a UUID (universally unique identifier). type: string nullable: true name: description: A unique string representing a UTF-8 encoded name. type: string nullable: true tags: description: A set of strings representing tags. type: array items: description: A string representing a tag. type: string nullable: true type: type: string const: redis-ee updated_at: description: Unix epoch when the resource was last updated. type: integer nullable: true example: config: cluster_nodes: - ip: 192.168.1.10 port: 6380 connect_timeout: 2000 database: 0 host: localhost keepalive_pool_size: 256 password: password port: 6379 read_timeout: 1000 send_timeout: 1000 sentinel_nodes: - host: sentinel1.redis.server port: 26379 server_name: redis-ee ssl: false ssl_verify: false username: username type: redis-ee additionalProperties: false required: - type - config PartialVectordb_2: type: object properties: config: type: object properties: dimensions: description: the desired dimensionality for the vectors type: integer distance_metric: description: the distance metric to use for vector searches type: string enum: - cosine - euclidean x-speakeasy-unknown-values: allow pgvector: type: object properties: database: description: the database of the pgvector database type: string default: kong-pgvector host: description: the host of the pgvector database type: string default: 127.0.0.1 password: description: the password of the pgvector database type: string x-encrypted: true x-referenceable: true port: description: the port of the pgvector database type: integer default: 5432 ssl: description: whether to use ssl for the pgvector database type: boolean default: false ssl_cert: description: the path of ssl cert to use for the pgvector database type: string ssl_cert_key: description: the path of ssl cert key to use for the pgvector database type: string ssl_required: description: whether ssl is required for the pgvector database type: boolean default: false ssl_verify: description: whether to verify ssl for the pgvector database type: boolean default: true ssl_version: description: the ssl version to use for the pgvector database type: string default: tlsv1_2 enum: - any - tlsv1_2 - tlsv1_3 x-speakeasy-unknown-values: allow timeout: description: the timeout of the pgvector database type: number default: 5000 user: description: the user of the pgvector database type: string default: postgres x-referenceable: true redis: type: object properties: cloud_authentication: description: Cloud auth related configs for connecting to a Cloud Provider's Redis instance. type: object properties: auth_provider: description: Auth providers to be used to authenticate to a Cloud Provider's Redis instance. type: string enum: - aws - azure - gcp x-referenceable: true x-speakeasy-unknown-values: allow aws_access_key_id: description: AWS Access Key ID to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true aws_assume_role_arn: description: The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens. type: string x-encrypted: true x-referenceable: true aws_cache_name: description: The name of the AWS Elasticache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_is_serverless: description: This flag specifies whether the cluster is serverless when auth_provider is set to `aws`. type: boolean default: true aws_region: description: The region of the AWS ElastiCache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_role_session_name: description: The session name for the temporary credentials when assuming the IAM role. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: AWS Secret Access Key to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true azure_client_id: description: Azure Client ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_client_secret: description: Azure Client Secret to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: Azure Tenant ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true gcp_service_account_json: description: GCP Service Account JSON to be used for authentication when `auth_provider` is set to `gcp`. type: string x-encrypted: true x-referenceable: true cluster_max_redirections: description: Maximum retry attempts for redirection. type: integer default: 5 cluster_nodes: description: Cluster addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element. type: array items: properties: ip: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 connect_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 connection_is_proxied: description: If the connection to Redis is proxied (e.g. Envoy), set it `true`. Set the `host` and `port` to point to the proxy address. type: boolean default: false database: description: Database to use for the Redis connection when using the `redis` strategy type: integer default: 0 host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 x-referenceable: true keepalive_backlog: description: Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return `nil`. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than `keepalive_pool_size`. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than `keepalive_pool_size`. type: integer maximum: 2147483646 minimum: 0 keepalive_pool_size: description: The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither `keepalive_pool_size` nor `keepalive_backlog` is specified, no pool is created. If `keepalive_pool_size` isn't specified but `keepalive_backlog` is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. type: integer default: 256 maximum: 2147483646 minimum: 1 password: description: Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis. type: string x-encrypted: true x-referenceable: true port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 x-referenceable: true read_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 send_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 sentinel_master: description: Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel. type: string sentinel_nodes: description: Sentinel node addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element. type: array items: properties: host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 sentinel_password: description: Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels. type: string x-encrypted: true x-referenceable: true sentinel_role: description: Sentinel role to use for Redis connections when the `redis` strategy is defined. Defining this value implies using Redis Sentinel. type: string enum: - any - master - slave x-speakeasy-unknown-values: allow sentinel_username: description: Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+. type: string x-referenceable: true server_name: description: A string representing an SNI (server name indication) value for TLS. type: string x-referenceable: true ssl: description: If set to true, uses SSL to connect to Redis. type: boolean default: false ssl_verify: description: If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure `lua_ssl_trusted_certificate` in `kong.conf` to specify the CA (or server) certificate used by your Redis server. You may also need to configure `lua_ssl_verify_depth` accordingly. type: boolean default: true username: description: Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to `default`. type: string x-referenceable: true strategy: description: which vector database driver to use type: string enum: - pgvector - redis x-speakeasy-unknown-values: allow threshold: description: the default similarity threshold for accepting semantic search results (float). Higher threshold means more results are considered similar. type: number required: - dimensions - distance_metric - strategy created_at: description: Unix epoch when the resource was created. type: integer nullable: true id: description: A string representing a UUID (universally unique identifier). type: string nullable: true name: description: A unique string representing a UTF-8 encoded name. type: string nullable: true tags: description: A set of strings representing tags. type: array items: description: A string representing a tag. type: string nullable: true type: type: string const: vectordb updated_at: description: Unix epoch when the resource was last updated. type: integer nullable: true example: config: dimensions: 1536 distance_metric: cosine pgvector: database: kong-pgvector host: 127.0.0.1 password: password port: 5432 user: postgres strategy: pgvector type: vectordb additionalProperties: false required: - type - config PartialModel: type: object properties: config: type: object properties: auth: type: object properties: allow_override: description: If enabled, the authorization header or parameter can be overridden in the request by the value configured in the plugin. type: boolean default: false aws_access_key_id: description: Set this if you are using an AWS provider (Bedrock) and you are authenticating using static IAM User credentials. Setting this will override the AWS_ACCESS_KEY_ID environment variable for this plugin instance. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: Set this if you are using an AWS provider (Bedrock) and you are authenticating using static IAM User credentials. Setting this will override the AWS_SECRET_ACCESS_KEY environment variable for this plugin instance. type: string x-encrypted: true x-referenceable: true azure_client_id: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the client ID. type: string x-referenceable: true azure_client_secret: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the client secret. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the tenant ID. type: string x-referenceable: true azure_use_managed_identity: description: Set true to use the Azure Cloud Managed Identity (or user-assigned identity) to authenticate with Azure-provider models. type: boolean default: false gcp_metadata_url: description: Custom metadata URL for GCP authentication. Useful for restricted network environments or custom GCP endpoints. If null, Kong will use the default Google metadata endpoint. type: string x-referenceable: true gcp_oauth_token_url: description: Custom OAuth token URL for GCP authentication. Useful for restricted network environments or custom GCP endpoints. If null, Kong will use the default Google OAuth token endpoint. type: string x-referenceable: true gcp_service_account_json: description: Set this field to the full JSON of the GCP service account to authenticate, if required. If null (and gcp_use_service_account is true), Kong will attempt to read from environment variable `GCP_SERVICE_ACCOUNT`. type: string x-encrypted: true x-referenceable: true gcp_use_service_account: description: Use service account auth for GCP-based providers and models. type: boolean default: false header_name: description: If AI model requires authentication via Authorization or API key header, specify its name here. type: string x-referenceable: true header_value: description: Specify the full auth header value for 'header_name', for example 'Bearer key' or just 'key'. type: string x-encrypted: true x-referenceable: true param_location: description: Specify whether the 'param_name' and 'param_value' options go in a query string, or the POST form/JSON body. type: string enum: - body - query param_name: description: If AI model requires authentication via query parameter, specify its name here. type: string x-referenceable: true param_value: description: Specify the full parameter value for 'param_name'. type: string x-encrypted: true x-referenceable: true description: description: The semantic description of the target, required if using semantic load balancing. Specially, setting this to 'CATCHALL' will indicate such target to be used when no other targets match the semantic threshold. Only used by ai-proxy-advanced. type: string logging: type: object properties: log_payloads: description: If enabled, will log the request and response body into the Kong log plugin(s) output.Furthermore if Opentelemetry instrumentation is enabled the traces will contain this data as well. type: boolean default: false log_statistics: description: If enabled and supported by the driver, will add model usage and token metrics into the Kong log plugin(s) output. type: boolean default: false metadata: description: 'For internal use only. ' type: object additionalProperties: true nullable: true x-speakeasy-type-override: any model: type: object properties: model_alias: description: The model name parameter from the request that this model should map to. type: string name: description: Model name to execute. type: string options: description: Key/value settings for the model type: object properties: anthropic_version: description: Defines the schema/API version, if using Anthropic provider. type: string azure_api_version: description: '''api-version'' for Azure OpenAI instances.' type: string default: '2023-05-15' azure_deployment_id: description: Deployment ID for Azure OpenAI instances. type: string azure_instance: description: Instance name for Azure OpenAI hosted models. type: string bedrock: type: object properties: aws_assume_role_arn: description: If using AWS providers (Bedrock) you can assume a different role after authentication with the current IAM context is successful. type: string aws_region: description: If using AWS providers (Bedrock) you can override the `AWS_REGION` environment variable by setting this option. type: string aws_role_session_name: description: If using AWS providers (Bedrock), set the identifier of the assumed role session. type: string aws_sts_endpoint_url: description: If using AWS providers (Bedrock), override the STS endpoint URL when assuming a different role. type: string batch_bucket_prefix: description: S3 URI prefix (s3://bucket/prefix/) where Bedrock will get input files from and store results to for native batch API. type: string batch_role_arn: description: AWS role arn used for calling batch API. Try to get the value from request if ommited. type: string embeddings_normalize: description: If using AWS providers (Bedrock), set to true to normalize the embeddings. type: boolean default: false performance_config_latency: description: Force the client's performance configuration 'latency' for all requests. Leave empty to let the consumer select the performance configuration. type: string video_output_s3_uri: description: S3 URI (s3://bucket/prefix) where Bedrock will store generated video files. Required for video generation. type: string cohere: type: object properties: embedding_input_type: description: The purpose of the input text to calculate embedding vectors. type: string default: classification enum: - classification - clustering - image - search_document - search_query wait_for_model: description: Wait for the model if it is not ready type: boolean dashscope: type: object properties: international: description: 'Two Dashscope endpoints are available, and the international endpoint will be used when this is set to `true`. It is recommended to set this to `true` when using international version of dashscope. ' type: boolean default: true databricks: type: object properties: workspace_instance_id: description: Workspace Instance ID ('dbc-xxx-yyy') for Databricks model serving. type: string embeddings_dimensions: description: If using embeddings models, set the number of dimensions to generate. type: integer gemini: type: object properties: api_endpoint: description: If running Gemini on Vertex, specify the regional API endpoint (hostname only). type: string endpoint_id: description: If running Gemini on Vertex Model Garden, specify the endpoint ID. type: string location_id: description: If running Gemini on Vertex, specify the location ID. type: string project_id: description: If running Gemini on Vertex, specify the project ID. type: string huggingface: type: object properties: use_cache: description: Use the cache layer on the inference API type: boolean wait_for_model: description: Wait for the model if it is not ready type: boolean input_cost: description: Defines the cost per 1M tokens in your prompt. type: number llama2_format: description: If using llama2 provider, select the upstream message format. type: string enum: - ollama - openai - raw max_tokens: description: Defines the max_tokens, if using chat or completion models. type: integer mistral_format: description: If using mistral provider, select the upstream message format. type: string enum: - ollama - openai output_cost: description: Defines the cost per 1M tokens in the output of the AI. type: number temperature: description: Defines the matching temperature, if using chat or completion models. type: number maximum: 5 minimum: 0 top_k: description: Defines the top-k most likely tokens, if supported. type: integer maximum: 500 minimum: 0 top_p: description: Defines the top-p probability mass, if supported. type: number maximum: 1 minimum: 0 upstream_path: description: Manually specify or override the AI operation path, used when e.g. using the 'preserve' route_type. type: string upstream_url: description: Manually specify or override the full URL to the AI operation endpoints, when calling (self-)hosted models, or for running via a private endpoint. type: string provider: description: AI provider request format - Kong translates requests to and from the specified backend compatible formats. type: string enum: - anthropic - azure - bedrock - cerebras - cohere - dashscope - databricks - deepseek - gemini - huggingface - llama2 - mistral - ollama - openai - vllm - xai required: - provider route_type: description: 'The model''s operation implementation, for this provider. ' type: string enum: - audio/v1/audio/speech - audio/v1/audio/transcriptions - audio/v1/audio/translations - image/v1/images/edits - image/v1/images/generations - llm/v1/assistants - llm/v1/batches - llm/v1/chat - llm/v1/completions - llm/v1/embeddings - llm/v1/files - llm/v1/responses - preserve - realtime/v1/realtime - video/v1/videos/generations weight: description: The weight this target gets within the upstream loadbalancer (1-65535). Only used by ai-proxy-advanced. type: integer default: 100 maximum: 65535 minimum: 1 required: - model - route_type created_at: description: Unix epoch when the resource was created. type: integer nullable: true id: description: A string representing a UUID (universally unique identifier). type: string nullable: true name: description: A unique string representing a UTF-8 encoded name. type: string nullable: true tags: description: A set of strings representing tags. type: array items: description: A string representing a tag. type: string nullable: true type: type: string const: model x-terraform-transform-const: true updated_at: description: Unix epoch when the resource was last updated. type: integer nullable: true example: config: auth: header_name: Authorization header_value: Bearer openai-api-key model: name: gpt-4 provider: openai route_type: llm/v1/chat type: model additionalProperties: false required: - type - config Partial_2: type: object discriminator: mapping: embeddings: '#/components/schemas/PartialEmbeddings' model: '#/components/schemas/PartialModel' redis-ce: '#/components/schemas/PartialRedisCe' redis-ee: '#/components/schemas/PartialRedisEe' vectordb: '#/components/schemas/PartialVectordb' propertyName: type oneOf: - $ref: '#/components/schemas/PartialRedisCe_2' - $ref: '#/components/schemas/PartialRedisEe_2' - $ref: '#/components/schemas/PartialVectordb_2' - $ref: '#/components/schemas/PartialEmbeddings_2' - $ref: '#/components/schemas/PartialModel_2' PartialRedisEe: type: object properties: config: type: object properties: cloud_authentication: description: Cloud auth related configs for connecting to a Cloud Provider's Redis instance. type: object properties: auth_provider: description: Auth providers to be used to authenticate to a Cloud Provider's Redis instance. type: string enum: - aws - azure - gcp x-referenceable: true aws_access_key_id: description: AWS Access Key ID to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true aws_assume_role_arn: description: The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens. type: string x-encrypted: true x-referenceable: true aws_cache_name: description: The name of the AWS Elasticache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_is_serverless: description: This flag specifies whether the cluster is serverless when auth_provider is set to `aws`. type: boolean default: true aws_region: description: The region of the AWS ElastiCache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_role_session_name: description: The session name for the temporary credentials when assuming the IAM role. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: AWS Secret Access Key to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true azure_client_id: description: Azure Client ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_client_secret: description: Azure Client Secret to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: Azure Tenant ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true gcp_service_account_json: description: GCP Service Account JSON to be used for authentication when `auth_provider` is set to `gcp`. type: string x-encrypted: true x-referenceable: true cluster_max_redirections: description: Maximum retry attempts for redirection. type: integer default: 5 cluster_nodes: description: Cluster addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element. type: array items: properties: ip: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 connect_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 connection_is_proxied: description: If the connection to Redis is proxied (e.g. Envoy), set it `true`. Set the `host` and `port` to point to the proxy address. type: boolean default: false database: description: Database to use for the Redis connection when using the `redis` strategy type: integer default: 0 host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 x-referenceable: true keepalive_backlog: description: Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return `nil`. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than `keepalive_pool_size`. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than `keepalive_pool_size`. type: integer maximum: 2147483646 minimum: 0 keepalive_pool_size: description: The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither `keepalive_pool_size` nor `keepalive_backlog` is specified, no pool is created. If `keepalive_pool_size` isn't specified but `keepalive_backlog` is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. type: integer default: 256 maximum: 2147483646 minimum: 1 password: description: Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis. type: string x-encrypted: true x-referenceable: true port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 x-referenceable: true read_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 send_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 sentinel_master: description: Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel. type: string sentinel_nodes: description: Sentinel node addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element. type: array items: properties: host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 sentinel_password: description: Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels. type: string x-encrypted: true x-referenceable: true sentinel_role: description: Sentinel role to use for Redis connections when the `redis` strategy is defined. Defining this value implies using Redis Sentinel. type: string enum: - any - master - slave sentinel_username: description: Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+. type: string x-referenceable: true server_name: description: A string representing an SNI (server name indication) value for TLS. type: string x-referenceable: true ssl: description: If set to true, uses SSL to connect to Redis. type: boolean default: false ssl_verify: description: If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure `lua_ssl_trusted_certificate` in `kong.conf` to specify the CA (or server) certificate used by your Redis server. You may also need to configure `lua_ssl_verify_depth` accordingly. type: boolean default: true username: description: Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to `default`. type: string x-referenceable: true created_at: description: Unix epoch when the resource was created. type: integer nullable: true id: description: A string representing a UUID (universally unique identifier). type: string nullable: true name: description: A unique string representing a UTF-8 encoded name. type: string nullable: true tags: description: A set of strings representing tags. type: array items: description: A string representing a tag. type: string nullable: true type: type: string const: redis-ee x-terraform-transform-const: true updated_at: description: Unix epoch when the resource was last updated. type: integer nullable: true example: config: cluster_nodes: - ip: 192.168.1.10 port: 6380 connect_timeout: 2000 database: 0 host: localhost keepalive_pool_size: 256 password: password port: 6379 read_timeout: 1000 send_timeout: 1000 sentinel_nodes: - host: sentinel1.redis.server port: 26379 server_name: redis-ee ssl: false ssl_verify: false username: username type: redis-ee additionalProperties: false required: - type - config PartialRedisCe: type: object properties: config: type: object properties: cloud_authentication: description: Cloud auth related configs for connecting to a Cloud Provider's Redis instance. type: object properties: auth_provider: description: Auth providers to be used to authenticate to a Cloud Provider's Redis instance. type: string enum: - aws - azure - gcp x-referenceable: true aws_access_key_id: description: AWS Access Key ID to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true aws_assume_role_arn: description: The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens. type: string x-encrypted: true x-referenceable: true aws_cache_name: description: The name of the AWS Elasticache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_is_serverless: description: This flag specifies whether the cluster is serverless when auth_provider is set to `aws`. type: boolean default: true aws_region: description: The region of the AWS ElastiCache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_role_session_name: description: The session name for the temporary credentials when assuming the IAM role. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: AWS Secret Access Key to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true azure_client_id: description: Azure Client ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_client_secret: description: Azure Client Secret to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: Azure Tenant ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true gcp_service_account_json: description: GCP Service Account JSON to be used for authentication when `auth_provider` is set to `gcp`. type: string x-encrypted: true x-referenceable: true database: description: Database to use for the Redis connection when using the `redis` strategy type: integer default: 0 host: description: A string representing a host name, such as example.com. type: string x-referenceable: true password: description: Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis. type: string x-encrypted: true x-referenceable: true port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 x-referenceable: true server_name: description: A string representing an SNI (server name indication) value for TLS. type: string x-referenceable: true ssl: description: If set to true, uses SSL to connect to Redis. type: boolean default: false ssl_verify: description: If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure `lua_ssl_trusted_certificate` in `kong.conf` to specify the CA (or server) certificate used by your Redis server. You may also need to configure `lua_ssl_verify_depth` accordingly. type: boolean default: true timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 username: description: Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to `default`. type: string x-referenceable: true created_at: description: Unix epoch when the resource was created. type: integer nullable: true id: description: A string representing a UUID (universally unique identifier). type: string nullable: true name: description: A unique string representing a UTF-8 encoded name. type: string nullable: true tags: description: A set of strings representing tags. type: array items: description: A string representing a tag. type: string nullable: true type: type: string const: redis-ce x-terraform-transform-const: true updated_at: description: Unix epoch when the resource was last updated. type: integer nullable: true example: config: database: 0 host: localhost password: password port: 6379 server_name: redis ssl: false ssl_verify: false timeout: 2000 username: username type: redis-ce additionalProperties: false required: - type - config PaginationNextResponse: description: URI to the next page (may be null) type: string PartialVectordb: type: object properties: config: type: object properties: dimensions: description: the desired dimensionality for the vectors type: integer distance_metric: description: the distance metric to use for vector searches type: string enum: - cosine - euclidean pgvector: type: object properties: database: description: the database of the pgvector database type: string default: kong-pgvector host: description: the host of the pgvector database type: string default: 127.0.0.1 password: description: the password of the pgvector database type: string x-encrypted: true x-referenceable: true port: description: the port of the pgvector database type: integer default: 5432 ssl: description: whether to use ssl for the pgvector database type: boolean default: false ssl_cert: description: the path of ssl cert to use for the pgvector database type: string ssl_cert_key: description: the path of ssl cert key to use for the pgvector database type: string ssl_required: description: whether ssl is required for the pgvector database type: boolean default: false ssl_verify: description: whether to verify ssl for the pgvector database type: boolean default: true ssl_version: description: the ssl version to use for the pgvector database type: string default: tlsv1_2 enum: - any - tlsv1_2 - tlsv1_3 timeout: description: the timeout of the pgvector database type: number default: 5000 user: description: the user of the pgvector database type: string default: postgres x-referenceable: true redis: type: object properties: cloud_authentication: description: Cloud auth related configs for connecting to a Cloud Provider's Redis instance. type: object properties: auth_provider: description: Auth providers to be used to authenticate to a Cloud Provider's Redis instance. type: string enum: - aws - azure - gcp x-referenceable: true aws_access_key_id: description: AWS Access Key ID to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true aws_assume_role_arn: description: The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens. type: string x-encrypted: true x-referenceable: true aws_cache_name: description: The name of the AWS Elasticache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_is_serverless: description: This flag specifies whether the cluster is serverless when auth_provider is set to `aws`. type: boolean default: true aws_region: description: The region of the AWS ElastiCache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_role_session_name: description: The session name for the temporary credentials when assuming the IAM role. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: AWS Secret Access Key to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true azure_client_id: description: Azure Client ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_client_secret: description: Azure Client Secret to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: Azure Tenant ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true gcp_service_account_json: description: GCP Service Account JSON to be used for authentication when `auth_provider` is set to `gcp`. type: string x-encrypted: true x-referenceable: true cluster_max_redirections: description: Maximum retry attempts for redirection. type: integer default: 5 cluster_nodes: description: Cluster addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element. type: array items: properties: ip: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 connect_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 connection_is_proxied: description: If the connection to Redis is proxied (e.g. Envoy), set it `true`. Set the `host` and `port` to point to the proxy address. type: boolean default: false database: description: Database to use for the Redis connection when using the `redis` strategy type: integer default: 0 host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 x-referenceable: true keepalive_backlog: description: Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return `nil`. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than `keepalive_pool_size`. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than `keepalive_pool_size`. type: integer maximum: 2147483646 minimum: 0 keepalive_pool_size: description: The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither `keepalive_pool_size` nor `keepalive_backlog` is specified, no pool is created. If `keepalive_pool_size` isn't specified but `keepalive_backlog` is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. type: integer default: 256 maximum: 2147483646 minimum: 1 password: description: Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis. type: string x-encrypted: true x-referenceable: true port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 x-referenceable: true read_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 send_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 sentinel_master: description: Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel. type: string sentinel_nodes: description: Sentinel node addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element. type: array items: properties: host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 sentinel_password: description: Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels. type: string x-encrypted: true x-referenceable: true sentinel_role: description: Sentinel role to use for Redis connections when the `redis` strategy is defined. Defining this value implies using Redis Sentinel. type: string enum: - any - master - slave sentinel_username: description: Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+. type: string x-referenceable: true server_name: description: A string representing an SNI (server name indication) value for TLS. type: string x-referenceable: true ssl: description: If set to true, uses SSL to connect to Redis. type: boolean default: false ssl_verify: description: If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure `lua_ssl_trusted_certificate` in `kong.conf` to specify the CA (or server) certificate used by your Redis server. You may also need to configure `lua_ssl_verify_depth` accordingly. type: boolean default: true username: description: Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to `default`. type: string x-referenceable: true strategy: description: which vector database driver to use type: string enum: - pgvector - redis threshold: description: the default similarity threshold for accepting semantic search results (float). Higher threshold means more results are considered similar. type: number required: - dimensions - distance_metric - strategy created_at: description: Unix epoch when the resource was created. type: integer nullable: true id: description: A string representing a UUID (universally unique identifier). type: string nullable: true name: description: A unique string representing a UTF-8 encoded name. type: string nullable: true tags: description: A set of strings representing tags. type: array items: description: A string representing a tag. type: string nullable: true type: type: string const: vectordb x-terraform-transform-const: true updated_at: description: Unix epoch when the resource was last updated. type: integer nullable: true example: config: dimensions: 1536 distance_metric: cosine pgvector: database: kong-pgvector host: 127.0.0.1 password: password port: 5432 user: postgres strategy: pgvector type: vectordb additionalProperties: false required: - type - config PartialRedisCe_2: type: object properties: config: type: object properties: cloud_authentication: description: Cloud auth related configs for connecting to a Cloud Provider's Redis instance. type: object properties: auth_provider: description: Auth providers to be used to authenticate to a Cloud Provider's Redis instance. type: string enum: - aws - azure - gcp x-referenceable: true x-speakeasy-unknown-values: allow aws_access_key_id: description: AWS Access Key ID to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true aws_assume_role_arn: description: The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens. type: string x-encrypted: true x-referenceable: true aws_cache_name: description: The name of the AWS Elasticache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_is_serverless: description: This flag specifies whether the cluster is serverless when auth_provider is set to `aws`. type: boolean default: true aws_region: description: The region of the AWS ElastiCache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_role_session_name: description: The session name for the temporary credentials when assuming the IAM role. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: AWS Secret Access Key to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true azure_client_id: description: Azure Client ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_client_secret: description: Azure Client Secret to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: Azure Tenant ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true gcp_service_account_json: description: GCP Service Account JSON to be used for authentication when `auth_provider` is set to `gcp`. type: string x-encrypted: true x-referenceable: true database: description: Database to use for the Redis connection when using the `redis` strategy type: integer default: 0 host: description: A string representing a host name, such as example.com. type: string x-referenceable: true password: description: Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis. type: string x-encrypted: true x-referenceable: true port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 x-referenceable: true server_name: description: A string representing an SNI (server name indication) value for TLS. type: string x-referenceable: true ssl: description: If set to true, uses SSL to connect to Redis. type: boolean default: false ssl_verify: description: If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure `lua_ssl_trusted_certificate` in `kong.conf` to specify the CA (or server) certificate used by your Redis server. You may also need to configure `lua_ssl_verify_depth` accordingly. type: boolean default: true timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 username: description: Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to `default`. type: string x-referenceable: true created_at: description: Unix epoch when the resource was created. type: integer nullable: true id: description: A string representing a UUID (universally unique identifier). type: string nullable: true name: description: A unique string representing a UTF-8 encoded name. type: string nullable: true tags: description: A set of strings representing tags. type: array items: description: A string representing a tag. type: string nullable: true type: type: string const: redis-ce updated_at: description: Unix epoch when the resource was last updated. type: integer nullable: true example: config: database: 0 host: localhost password: password port: 6379 server_name: redis ssl: false ssl_verify: false timeout: 2000 username: username type: redis-ce additionalProperties: false required: - type - config PartialEmbeddings: type: object properties: config: type: object properties: auth: type: object properties: allow_override: description: If enabled, the authorization header or parameter can be overridden in the request by the value configured in the plugin. type: boolean default: false aws_access_key_id: description: Set this if you are using an AWS provider (Bedrock) and you are authenticating using static IAM User credentials. Setting this will override the AWS_ACCESS_KEY_ID environment variable for this plugin instance. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: Set this if you are using an AWS provider (Bedrock) and you are authenticating using static IAM User credentials. Setting this will override the AWS_SECRET_ACCESS_KEY environment variable for this plugin instance. type: string x-encrypted: true x-referenceable: true azure_client_id: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the client ID. type: string x-referenceable: true azure_client_secret: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the client secret. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the tenant ID. type: string x-referenceable: true azure_use_managed_identity: description: Set true to use the Azure Cloud Managed Identity (or user-assigned identity) to authenticate with Azure-provider models. type: boolean default: false gcp_metadata_url: description: Custom metadata URL for GCP authentication. Useful for restricted network environments or custom GCP endpoints. If null, Kong will use the default Google metadata endpoint. type: string x-referenceable: true gcp_oauth_token_url: description: Custom OAuth token URL for GCP authentication. Useful for restricted network environments or custom GCP endpoints. If null, Kong will use the default Google OAuth token endpoint. type: string x-referenceable: true gcp_service_account_json: description: Set this field to the full JSON of the GCP service account to authenticate, if required. If null (and gcp_use_service_account is true), Kong will attempt to read from environment variable `GCP_SERVICE_ACCOUNT`. type: string x-encrypted: true x-referenceable: true gcp_use_service_account: description: Use service account auth for GCP-based providers and models. type: boolean default: false header_name: description: If AI model requires authentication via Authorization or API key header, specify its name here. type: string x-referenceable: true header_value: description: Specify the full auth header value for 'header_name', for example 'Bearer key' or just 'key'. type: string x-encrypted: true x-referenceable: true param_location: description: Specify whether the 'param_name' and 'param_value' options go in a query string, or the POST form/JSON body. type: string enum: - body - query param_name: description: If AI model requires authentication via query parameter, specify its name here. type: string x-referenceable: true param_value: description: Specify the full parameter value for 'param_name'. type: string x-encrypted: true x-referenceable: true model: type: object properties: name: description: Model name to execute. type: string options: description: Key/value settings for the model type: object properties: azure: type: object properties: api_version: description: '''api-version'' for Azure OpenAI instances.' type: string default: '2023-05-15' deployment_id: description: Deployment ID for Azure OpenAI instances. type: string instance: description: Instance name for Azure OpenAI hosted models. type: string bedrock: type: object properties: aws_assume_role_arn: description: If using AWS providers (Bedrock) you can assume a different role after authentication with the current IAM context is successful. type: string aws_region: description: If using AWS providers (Bedrock) you can override the `AWS_REGION` environment variable by setting this option. type: string aws_role_session_name: description: If using AWS providers (Bedrock), set the identifier of the assumed role session. type: string aws_sts_endpoint_url: description: If using AWS providers (Bedrock), override the STS endpoint URL when assuming a different role. type: string batch_bucket_prefix: description: S3 URI prefix (s3://bucket/prefix/) where Bedrock will get input files from and store results to for native batch API. type: string batch_role_arn: description: AWS role arn used for calling batch API. Try to get the value from request if ommited. type: string embeddings_normalize: description: If using AWS providers (Bedrock), set to true to normalize the embeddings. type: boolean default: false performance_config_latency: description: Force the client's performance configuration 'latency' for all requests. Leave empty to let the consumer select the performance configuration. type: string video_output_s3_uri: description: S3 URI (s3://bucket/prefix) where Bedrock will store generated video files. Required for video generation. type: string gemini: type: object properties: api_endpoint: description: If running Gemini on Vertex, specify the regional API endpoint (hostname only). type: string location_id: description: If running Gemini on Vertex, specify the location ID. type: string project_id: description: If running Gemini on Vertex, specify the project ID. type: string huggingface: type: object properties: use_cache: description: Use the cache layer on the inference API type: boolean wait_for_model: description: Wait for the model if it is not ready type: boolean upstream_url: description: upstream url for the embeddings type: string provider: description: AI provider format to use for embeddings API type: string enum: - azure - bedrock - gemini - huggingface - mistral - ollama - openai required: - name - provider required: - model created_at: description: Unix epoch when the resource was created. type: integer nullable: true id: description: A string representing a UUID (universally unique identifier). type: string nullable: true name: description: A unique string representing a UTF-8 encoded name. type: string nullable: true tags: description: A set of strings representing tags. type: array items: description: A string representing a tag. type: string nullable: true type: type: string const: embeddings x-terraform-transform-const: true updated_at: description: Unix epoch when the resource was last updated. type: integer nullable: true example: config: auth: header_name: Authorization header_value: Bearer openai-api-key model: name: text-embedding-3-small provider: openai type: embeddings additionalProperties: false required: - type - config PartialEmbeddings_2: type: object properties: config: type: object properties: auth: type: object properties: allow_override: description: If enabled, the authorization header or parameter can be overridden in the request by the value configured in the plugin. type: boolean default: false aws_access_key_id: description: Set this if you are using an AWS provider (Bedrock) and you are authenticating using static IAM User credentials. Setting this will override the AWS_ACCESS_KEY_ID environment variable for this plugin instance. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: Set this if you are using an AWS provider (Bedrock) and you are authenticating using static IAM User credentials. Setting this will override the AWS_SECRET_ACCESS_KEY environment variable for this plugin instance. type: string x-encrypted: true x-referenceable: true azure_client_id: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the client ID. type: string x-referenceable: true azure_client_secret: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the client secret. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the tenant ID. type: string x-referenceable: true azure_use_managed_identity: description: Set true to use the Azure Cloud Managed Identity (or user-assigned identity) to authenticate with Azure-provider models. type: boolean default: false gcp_metadata_url: description: Custom metadata URL for GCP authentication. Useful for restricted network environments or custom GCP endpoints. If null, Kong will use the default Google metadata endpoint. type: string x-referenceable: true gcp_oauth_token_url: description: Custom OAuth token URL for GCP authentication. Useful for restricted network environments or custom GCP endpoints. If null, Kong will use the default Google OAuth token endpoint. type: string x-referenceable: true gcp_service_account_json: description: Set this field to the full JSON of the GCP service account to authenticate, if required. If null (and gcp_use_service_account is true), Kong will attempt to read from environment variable `GCP_SERVICE_ACCOUNT`. type: string x-encrypted: true x-referenceable: true gcp_use_service_account: description: Use service account auth for GCP-based providers and models. type: boolean default: false header_name: description: If AI model requires authentication via Authorization or API key header, specify its name here. type: string x-referenceable: true header_value: description: Specify the full auth header value for 'header_name', for example 'Bearer key' or just 'key'. type: string x-encrypted: true x-referenceable: true param_location: description: Specify whether the 'param_name' and 'param_value' options go in a query string, or the POST form/JSON body. type: string enum: - body - query x-speakeasy-unknown-values: allow param_name: description: If AI model requires authentication via query parameter, specify its name here. type: string x-referenceable: true param_value: description: Specify the full parameter value for 'param_name'. type: string x-encrypted: true x-referenceable: true model: type: object properties: name: description: Model name to execute. type: string options: description: Key/value settings for the model type: object properties: azure: type: object properties: api_version: description: '''api-version'' for Azure OpenAI instances.' type: string default: '2023-05-15' deployment_id: description: Deployment ID for Azure OpenAI instances. type: string instance: description: Instance name for Azure OpenAI hosted models. type: string bedrock: type: object properties: aws_assume_role_arn: description: If using AWS providers (Bedrock) you can assume a different role after authentication with the current IAM context is successful. type: string aws_region: description: If using AWS providers (Bedrock) you can override the `AWS_REGION` environment variable by setting this option. type: string aws_role_session_name: description: If using AWS providers (Bedrock), set the identifier of the assumed role session. type: string aws_sts_endpoint_url: description: If using AWS providers (Bedrock), override the STS endpoint URL when assuming a different role. type: string batch_bucket_prefix: description: S3 URI prefix (s3://bucket/prefix/) where Bedrock will get input files from and store results to for native batch API. type: string batch_role_arn: description: AWS role arn used for calling batch API. Try to get the value from request if ommited. type: string embeddings_normalize: description: If using AWS providers (Bedrock), set to true to normalize the embeddings. type: boolean default: false performance_config_latency: description: Force the client's performance configuration 'latency' for all requests. Leave empty to let the consumer select the performance configuration. type: string video_output_s3_uri: description: S3 URI (s3://bucket/prefix) where Bedrock will store generated video files. Required for video generation. type: string gemini: type: object properties: api_endpoint: description: If running Gemini on Vertex, specify the regional API endpoint (hostname only). type: string location_id: description: If running Gemini on Vertex, specify the location ID. type: string project_id: description: If running Gemini on Vertex, specify the project ID. type: string huggingface: type: object properties: use_cache: description: Use the cache layer on the inference API type: boolean wait_for_model: description: Wait for the model if it is not ready type: boolean upstream_url: description: upstream url for the embeddings type: string provider: description: AI provider format to use for embeddings API type: string enum: - azure - bedrock - gemini - huggingface - mistral - ollama - openai x-speakeasy-unknown-values: allow required: - name - provider required: - model created_at: description: Unix epoch when the resource was created. type: integer nullable: true id: description: A string representing a UUID (universally unique identifier). type: string nullable: true name: description: A unique string representing a UTF-8 encoded name. type: string nullable: true tags: description: A set of strings representing tags. type: array items: description: A string representing a tag. type: string nullable: true type: type: string const: embeddings updated_at: description: Unix epoch when the resource was last updated. type: integer nullable: true example: config: auth: header_name: Authorization header_value: Bearer openai-api-key model: name: text-embedding-3-small provider: openai type: embeddings additionalProperties: false required: - type - config PaginationOffsetResponse: description: Offset is used to paginate through the API. Provide this value to the next list operation to fetch the next page type: string PartialModel_2: type: object properties: config: type: object properties: auth: type: object properties: allow_override: description: If enabled, the authorization header or parameter can be overridden in the request by the value configured in the plugin. type: boolean default: false aws_access_key_id: description: Set this if you are using an AWS provider (Bedrock) and you are authenticating using static IAM User credentials. Setting this will override the AWS_ACCESS_KEY_ID environment variable for this plugin instance. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: Set this if you are using an AWS provider (Bedrock) and you are authenticating using static IAM User credentials. Setting this will override the AWS_SECRET_ACCESS_KEY environment variable for this plugin instance. type: string x-encrypted: true x-referenceable: true azure_client_id: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the client ID. type: string x-referenceable: true azure_client_secret: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the client secret. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the tenant ID. type: string x-referenceable: true azure_use_managed_identity: description: Set true to use the Azure Cloud Managed Identity (or user-assigned identity) to authenticate with Azure-provider models. type: boolean default: false gcp_metadata_url: description: Custom metadata URL for GCP authentication. Useful for restricted network environments or custom GCP endpoints. If null, Kong will use the default Google metadata endpoint. type: string x-referenceable: true gcp_oauth_token_url: description: Custom OAuth token URL for GCP authentication. Useful for restricted network environments or custom GCP endpoints. If null, Kong will use the default Google OAuth token endpoint. type: string x-referenceable: true gcp_service_account_json: description: Set this field to the full JSON of the GCP service account to authenticate, if required. If null (and gcp_use_service_account is true), Kong will attempt to read from environment variable `GCP_SERVICE_ACCOUNT`. type: string x-encrypted: true x-referenceable: true gcp_use_service_account: description: Use service account auth for GCP-based providers and models. type: boolean default: false header_name: description: If AI model requires authentication via Authorization or API key header, specify its name here. type: string x-referenceable: true header_value: description: Specify the full auth header value for 'header_name', for example 'Bearer key' or just 'key'. type: string x-encrypted: true x-referenceable: true param_location: description: Specify whether the 'param_name' and 'param_value' options go in a query string, or the POST form/JSON body. type: string enum: - body - query x-speakeasy-unknown-values: allow param_name: description: If AI model requires authentication via query parameter, specify its name here. type: string x-referenceable: true param_value: description: Specify the full parameter value for 'param_name'. type: string x-encrypted: true x-referenceable: true description: description: The semantic description of the target, required if using semantic load balancing. Specially, setting this to 'CATCHALL' will indicate such target to be used when no other targets match the semantic threshold. Only used by ai-proxy-advanced. type: string logging: type: object properties: log_payloads: description: If enabled, will log the request and response body into the Kong log plugin(s) output.Furthermore if Opentelemetry instrumentation is enabled the traces will contain this data as well. type: boolean default: false log_statistics: description: If enabled and supported by the driver, will add model usage and token metrics into the Kong log plugin(s) output. type: boolean default: false metadata: description: 'For internal use only. ' type: object additionalProperties: true nullable: true x-speakeasy-type-override: any model: type: object properties: model_alias: description: The model name parameter from the request that this model should map to. type: string name: description: Model name to execute. type: string options: description: Key/value settings for the model type: object properties: anthropic_version: description: Defines the schema/API version, if using Anthropic provider. type: string azure_api_version: description: '''api-version'' for Azure OpenAI instances.' type: string default: '2023-05-15' azure_deployment_id: description: Deployment ID for Azure OpenAI instances. type: string azure_instance: description: Instance name for Azure OpenAI hosted models. type: string bedrock: type: object properties: aws_assume_role_arn: description: If using AWS providers (Bedrock) you can assume a different role after authentication with the current IAM context is successful. type: string aws_region: description: If using AWS providers (Bedrock) you can override the `AWS_REGION` environment variable by setting this option. type: string aws_role_session_name: description: If using AWS providers (Bedrock), set the identifier of the assumed role session. type: string aws_sts_endpoint_url: description: If using AWS providers (Bedrock), override the STS endpoint URL when assuming a different role. type: string batch_bucket_prefix: description: S3 URI prefix (s3://bucket/prefix/) where Bedrock will get input files from and store results to for native batch API. type: string batch_role_arn: description: AWS role arn used for calling batch API. Try to get the value from request if ommited. type: string embeddings_normalize: description: If using AWS providers (Bedrock), set to true to normalize the embeddings. type: boolean default: false performance_config_latency: description: Force the client's performance configuration 'latency' for all requests. Leave empty to let the consumer select the performance configuration. type: string video_output_s3_uri: description: S3 URI (s3://bucket/prefix) where Bedrock will store generated video files. Required for video generation. type: string cohere: type: object properties: embedding_input_type: description: The purpose of the input text to calculate embedding vectors. type: string default: classification enum: - classification - clustering - image - search_document - search_query x-speakeasy-unknown-values: allow wait_for_model: description: Wait for the model if it is not ready type: boolean dashscope: type: object properties: international: description: 'Two Dashscope endpoints are available, and the international endpoint will be used when this is set to `true`. It is recommended to set this to `true` when using international version of dashscope. ' type: boolean default: true databricks: type: object properties: workspace_instance_id: description: Workspace Instance ID ('dbc-xxx-yyy') for Databricks model serving. type: string embeddings_dimensions: description: If using embeddings models, set the number of dimensions to generate. type: integer gemini: type: object properties: api_endpoint: description: If running Gemini on Vertex, specify the regional API endpoint (hostname only). type: string endpoint_id: description: If running Gemini on Vertex Model Garden, specify the endpoint ID. type: string location_id: description: If running Gemini on Vertex, specify the location ID. type: string project_id: description: If running Gemini on Vertex, specify the project ID. type: string huggingface: type: object properties: use_cache: description: Use the cache layer on the inference API type: boolean wait_for_model: description: Wait for the model if it is not ready type: boolean input_cost: description: Defines the cost per 1M tokens in your prompt. type: number llama2_format: description: If using llama2 provider, select the upstream message format. type: string enum: - ollama - openai - raw x-speakeasy-unknown-values: allow max_tokens: description: Defines the max_tokens, if using chat or completion models. type: integer mistral_format: description: If using mistral provider, select the upstream message format. type: string enum: - ollama - openai x-speakeasy-unknown-values: allow output_cost: description: Defines the cost per 1M tokens in the output of the AI. type: number temperature: description: Defines the matching temperature, if using chat or completion models. type: number maximum: 5 minimum: 0 top_k: description: Defines the top-k most likely tokens, if supported. type: integer maximum: 500 minimum: 0 top_p: description: Defines the top-p probability mass, if supported. type: number maximum: 1 minimum: 0 upstream_path: description: Manually specify or override the AI operation path, used when e.g. using the 'preserve' route_type. type: string upstream_url: description: Manually specify or override the full URL to the AI operation endpoints, when calling (self-)hosted models, or for running via a private endpoint. type: string provider: description: AI provider request format - Kong translates requests to and from the specified backend compatible formats. type: string enum: - anthropic - azure - bedrock - cerebras - cohere - dashscope - databricks - deepseek - gemini - huggingface - llama2 - mistral - ollama - openai - vllm - xai x-speakeasy-unknown-values: allow required: - provider route_type: description: 'The model''s operation implementation, for this provider. ' type: string enum: - audio/v1/audio/speech - audio/v1/audio/transcriptions - audio/v1/audio/translations - image/v1/images/edits - image/v1/images/generations - llm/v1/assistants - llm/v1/batches - llm/v1/chat - llm/v1/completions - llm/v1/embeddings - llm/v1/files - llm/v1/responses - preserve - realtime/v1/realtime - video/v1/videos/generations x-speakeasy-unknown-values: allow weight: description: The weight this target gets within the upstream loadbalancer (1-65535). Only used by ai-proxy-advanced. type: integer default: 100 maximum: 65535 minimum: 1 required: - model - route_type created_at: description: Unix epoch when the resource was created. type: integer nullable: true id: description: A string representing a UUID (universally unique identifier). type: string nullable: true name: description: A unique string representing a UTF-8 encoded name. type: string nullable: true tags: description: A set of strings representing tags. type: array items: description: A string representing a tag. type: string nullable: true type: type: string const: model updated_at: description: Unix epoch when the resource was last updated. type: integer nullable: true example: config: auth: header_name: Authorization header_value: Bearer openai-api-key model: name: gpt-4 provider: openai route_type: llm/v1/chat type: model additionalProperties: false required: - type - config GatewayUnauthorizedError: type: object properties: message: type: string status: type: integer required: - message - status parameters: PaginationSize: description: Number of resources to be returned. in: query name: size schema: type: integer default: 100 maximum: 1000 minimum: 1 PaginationOffset: allowEmptyValue: true description: Offset from which to return the next set of resources. Use the value of the 'offset' field from the response of a list operation as input here to paginate through all the resources in: query name: offset schema: type: string PartialId: description: ID of the Partial to lookup example: '' in: path name: PartialId required: true schema: type: string x-speakeasy-match: id PartialId_2: description: ID of the Partial to lookup example: '' in: path name: PartialId required: true schema: type: string Workspace: description: The name of the workspace in: path name: workspace required: true schema: type: string example: team-payments default: default PaginationTagsFilter: allowEmptyValue: true description: A list of tags to filter the list of resources on. Multiple tags can be concatenated using ',' to mean AND or using '/' to mean OR. example: tag1,tag2 in: query name: tags schema: type: string controlPlaneId: name: controlPlaneId in: path required: true schema: type: string format: uuid example: 9524ec7d-36d9-465d-a8c5-83a3c9390458 description: The UUID of your control plane. This variable is available in the Konnect manager. x-speakeasy-param-force-new: true responses: HTTP401Error_2: description: Unauthorized content: application/json: schema: $ref: '#/components/schemas/GatewayUnauthorizedError' HTTP401Error: description: Unauthorized content: application/json: examples: DuplicateApiKey: summary: Duplicate API key found value: message: Duplicate API key found status: 401 InvalidAuthCred: summary: Invalid authentication credentials value: message: Unauthorized status: 401 NoAPIKey: summary: No API key found value: message: No API key found in request status: 401 schema: $ref: '#/components/schemas/GatewayUnauthorizedError' securitySchemes: adminToken: in: header name: Kong-Admin-Token type: apiKey externalDocs: description: Documentation for Kong Gateway and its APIs url: https://developer.konghq.com