openapi: 3.2.0 info: title: OpenAI Vaults API description: The OpenAI REST API. Please see https://platform.openai.com/docs/api-reference for more details. version: 2.3.0 termsOfService: https://openai.com/policies/terms-of-use contact: name: OpenAI Support url: https://help.openai.com/ license: name: MIT identifier: MIT servers: - url: https://api.openai.com/v1 security: - ApiKeyAuth: [] tags: - name: Vaults paths: /vaults: get: operationId: listVaults summary: List vaults description: Lists vaults using ID-based pagination. See vaults. tags: - Vaults parameters: - name: order in: query required: false schema: $ref: '#/components/schemas/ListOrderParam' default: desc description: Sort order by the `created_at` timestamp. Use `asc` for ascending order or `desc` for descending order. Defaults to `desc`. - name: limit in: query required: false schema: type: - integer - 'null' format: int64 minimum: 0 description: The maximum number of resources to return. Defaults to 20. Values are clamped between 1 and 100. - name: status in: query required: false schema: $ref: '#/components/schemas/VaultStatusFilterParam' description: Filter by one status or a list, such as `status=active` or `status[]=active&status[]=archived`. Both statuses are included by default. - name: after in: query required: false schema: type: string minLength: 0 maxLength: 1048576 description: Return resources after this resource ID in the selected order. responses: '200': description: A page of vaults. content: application/json: schema: $ref: '#/components/schemas/VaultListResource' description: A page of vaults. '400': description: The request was invalid. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '401': description: Authentication or project context was missing. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '403': description: The API key lacks the required management permission. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '404': description: The requested vault or credential was not found. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '409': description: The request conflicted with the current vault state. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '500': description: An internal error occurred. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '503': description: The service is temporarily unavailable. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' post: operationId: createVault summary: Create a vault description: Creates a vault for the current project. See vaults. tags: - Vaults requestBody: content: application/json: schema: $ref: '#/components/schemas/CreateVaultParams' responses: '201': description: The created vault. content: application/json: schema: $ref: '#/components/schemas/VaultResource' '400': description: The request was invalid. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '401': description: Authentication or project context was missing. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '403': description: The API key lacks the required management permission. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '404': description: The requested vault or credential was not found. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '409': description: The request conflicted with the current vault state. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '500': description: An internal error occurred. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '503': description: The service is temporarily unavailable. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' /vaults/{vault_id}: get: operationId: retrieveVault summary: Retrieve a vault description: Retrieves a vault by its ID. See vaults. tags: - Vaults parameters: - name: vault_id in: path required: true schema: type: string minLength: 0 maxLength: 1048576 description: The ID of the vault. responses: '200': description: The requested vault. content: application/json: schema: $ref: '#/components/schemas/VaultResource' '400': description: The request was invalid. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '401': description: Authentication or project context was missing. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '403': description: The API key lacks the required management permission. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '404': description: The requested vault or credential was not found. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '409': description: The request conflicted with the current vault state. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '500': description: An internal error occurred. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '503': description: The service is temporarily unavailable. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' delete: operationId: deleteVault summary: Delete a vault description: Deletes a vault and all its credentials. See vaults. tags: - Vaults parameters: - name: vault_id in: path required: true schema: type: string minLength: 0 maxLength: 1048576 description: The ID of the vault. responses: '200': description: The deleted vault. content: application/json: schema: $ref: '#/components/schemas/DeletedVaultResource' '400': description: The request was invalid. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '401': description: Authentication or project context was missing. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '403': description: The API key lacks the required management permission. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '404': description: The requested vault or credential was not found. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '409': description: The request conflicted with the current vault state. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '500': description: An internal error occurred. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '503': description: The service is temporarily unavailable. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' /vaults/{vault_id}/credentials: get: operationId: listVaultCredentials summary: List vault credentials description: Lists a vault's credentials using ID-based pagination without returning secret values. See vaults. tags: - Vaults parameters: - name: vault_id in: path required: true schema: type: string minLength: 0 maxLength: 1048576 description: The ID of the vault. - name: order in: query required: false schema: $ref: '#/components/schemas/ListOrderParam' default: desc description: Sort order by the `created_at` timestamp. Use `asc` for ascending order or `desc` for descending order. Defaults to `desc`. - name: limit in: query required: false schema: type: - integer - 'null' format: int64 minimum: 0 description: The maximum number of resources to return. Defaults to 20. Values are clamped between 1 and 100. - name: status in: query required: false schema: $ref: '#/components/schemas/VaultStatusFilterParam' description: Filter by one status or a list, such as `status=active` or `status[]=active&status[]=archived`. Both statuses are included by default. - name: after in: query required: false schema: type: string minLength: 0 maxLength: 1048576 description: Return resources after this resource ID in the selected order. responses: '200': description: A page of vault credentials. content: application/json: schema: $ref: '#/components/schemas/VaultCredentialListResource' description: A page of credentials in a vault. '400': description: The request was invalid. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '401': description: Authentication or project context was missing. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '403': description: The API key lacks the required management permission. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '404': description: The requested vault or credential was not found. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '409': description: The request conflicted with the current vault state. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '500': description: An internal error occurred. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '503': description: The service is temporarily unavailable. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' post: operationId: createVaultCredential summary: Create a vault credential description: Creates a vault credential. Secret values are write-only and are never returned. See vaults. tags: - Vaults parameters: - name: vault_id in: path required: true schema: type: string minLength: 0 maxLength: 1048576 description: The ID of the vault. requestBody: content: application/json: schema: $ref: '#/components/schemas/CreateVaultCredentialParams' responses: '201': description: The created vault credential without secret values. content: application/json: schema: $ref: '#/components/schemas/VaultCredentialResource' '400': description: The request was invalid. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '401': description: Authentication or project context was missing. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '403': description: The API key lacks the required management permission. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '404': description: The requested vault or credential was not found. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '409': description: The request conflicted with the current vault state. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '500': description: An internal error occurred. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '503': description: The service is temporarily unavailable. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' /vaults/{vault_id}/credentials/{credential_id}: get: operationId: retrieveVaultCredential summary: Retrieve a vault credential description: Retrieves vault credential metadata without returning secret values. See vaults. tags: - Vaults parameters: - name: vault_id in: path required: true schema: type: string minLength: 0 maxLength: 1048576 description: The ID of the vault. - name: credential_id in: path required: true schema: type: string minLength: 0 maxLength: 1048576 description: The ID of the vault credential. responses: '200': description: The requested vault credential without secret values. content: application/json: schema: $ref: '#/components/schemas/VaultCredentialResource' '400': description: The request was invalid. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '401': description: Authentication or project context was missing. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '403': description: The API key lacks the required management permission. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '404': description: The requested vault or credential was not found. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '409': description: The request conflicted with the current vault state. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '500': description: An internal error occurred. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '503': description: The service is temporarily unavailable. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' post: operationId: rotateVaultCredential summary: Update a vault credential description: Updates credential metadata or rotates its write-only secret. See vaults. tags: - Vaults parameters: - name: vault_id in: path required: true schema: type: string minLength: 0 maxLength: 1048576 description: The ID of the vault. - name: credential_id in: path required: true schema: type: string minLength: 0 maxLength: 1048576 description: The ID of the vault credential. requestBody: content: application/json: schema: $ref: '#/components/schemas/RotateVaultCredentialParams' responses: '200': description: The updated vault credential without secret values. content: application/json: schema: $ref: '#/components/schemas/VaultCredentialResource' '400': description: The request was invalid. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '401': description: Authentication or project context was missing. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '403': description: The API key lacks the required management permission. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '404': description: The requested vault or credential was not found. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '409': description: The request conflicted with the current vault state. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '500': description: An internal error occurred. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '503': description: The service is temporarily unavailable. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' delete: operationId: deleteVaultCredential summary: Delete a vault credential description: Deletes a vault credential. See vaults. tags: - Vaults parameters: - name: vault_id in: path required: true schema: type: string minLength: 0 maxLength: 1048576 description: The ID of the vault. - name: credential_id in: path required: true schema: type: string minLength: 0 maxLength: 1048576 description: The ID of the vault credential. responses: '200': description: The deleted vault credential. content: application/json: schema: $ref: '#/components/schemas/DeletedVaultCredentialResource' '400': description: The request was invalid. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '401': description: Authentication or project context was missing. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '403': description: The API key lacks the required management permission. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '404': description: The requested vault or credential was not found. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '409': description: The request conflicted with the current vault state. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '500': description: An internal error occurred. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' '503': description: The service is temporarily unavailable. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse-2' components: schemas: RotateVaultCredentialAuthParamMcpOauth: type: object properties: type: type: string enum: - mcp_oauth default: mcp_oauth x-stainless-const: true description: The type of the object. Always `mcp_oauth`. access_token: type: - string - 'null' minLength: 0 maxLength: 1048576 description: A write-only replacement OAuth access token. expires_at: type: - string - 'null' minLength: 0 maxLength: 1048576 description: The replacement expiry as an RFC 3339 timestamp, or `null` to clear it. Omitting this field preserves the expiry unless a new access token is supplied, in which case the expiry is cleared. refresh: anyOf: - $ref: '#/components/schemas/RotateMcpOauthRefreshParam' - type: 'null' description: Optional write-only refresh-token and client-secret updates. required: - type additionalProperties: false description: Rotate an OAuth credential for an HTTPS MCP destination. RotateMcpOauthTokenEndpointAuthParamClientSecretPost: type: object properties: type: type: string enum: - client_secret_post default: client_secret_post x-stainless-const: true description: The type of the object. Always `client_secret_post`. client_secret: type: - string - 'null' minLength: 0 maxLength: 1048576 description: The replacement OAuth client secret. Omit or pass `null` to keep the stored secret. This secret is never returned in resources. required: - type additionalProperties: false description: Updates credentials sent in the token request body. RotateVaultCredentialAuthParam: oneOf: - $ref: '#/components/schemas/RotateVaultCredentialAuthParamMcpOauth' - $ref: '#/components/schemas/RotateVaultCredentialAuthParamStaticBearer' - $ref: '#/components/schemas/RotateVaultCredentialAuthParamEnvironmentVariable' discriminator: propertyName: type mapping: mcp_oauth: '#/components/schemas/RotateVaultCredentialAuthParamMcpOauth' static_bearer: '#/components/schemas/RotateVaultCredentialAuthParamStaticBearer' environment_variable: '#/components/schemas/RotateVaultCredentialAuthParamEnvironmentVariable' x-oai-discriminator-values: - mcp_oauth - static_bearer - environment_variable description: Updates to a vault credential without changing its authentication method or destination configuration. McpOauthTokenEndpointAuthResourceNone: type: object properties: type: type: string enum: - none default: none x-stainless-const: true description: The type of the object. Always `none`. required: - type additionalProperties: false description: Sends the client ID without a client secret. VaultCredentialNetworkingResourceLimited: type: object properties: type: type: string enum: - limited default: limited x-stainless-const: true description: The type of the object. Always `limited`. allowed_hosts: type: array items: type: string minLength: 0 minItems: 1 maxItems: 16 description: The 1 to 16 distinct allowed hostnames or IPv4 addresses, normalized to lowercase. Entries contain no scheme, path, port, or wildcard. IPv6 addresses are not supported. required: - type - allowed_hosts additionalProperties: false description: Allows substitution only for the listed hosts. The environment network policy must also allow these hosts. CreateVaultParams: type: object properties: name: type: string minLength: 1 maxLength: 1048576 description: The name is trimmed before storage. It must contain 1 to 256 UTF-8 bytes after trimming. metadata: type: - object - 'null' additionalProperties: type: string minLength: 0 maxLength: 1048576 propertyNames: type: string minLength: 1 maxLength: 256 minProperties: 0 maxProperties: 1024 description: Key-value pairs to associate with the vault, such as an application or team identifier. additionalProperties: false description: Parameters for creating a vault to store credentials used by agent tools. VaultCredentialNetworkingParamLimited: type: object properties: type: type: string enum: - limited default: limited x-stainless-const: true description: The type of the object. Always `limited`. allowed_hosts: type: array items: type: string minLength: 0 maxLength: 1048576 minItems: 1 maxItems: 16 description: The 1 to 16 distinct allowed hostnames or IPv4 addresses, normalized to lowercase. Entries contain no scheme, path, port, or wildcard. IPv6 addresses are not supported. required: - type - allowed_hosts additionalProperties: false description: Allows substitution only for the listed hosts. The environment network policy must also allow these hosts. CreateMcpOauthTokenEndpointAuthParam: oneOf: - $ref: '#/components/schemas/CreateMcpOauthTokenEndpointAuthParamNone' - $ref: '#/components/schemas/CreateMcpOauthTokenEndpointAuthParamClientSecretBasic' - $ref: '#/components/schemas/CreateMcpOauthTokenEndpointAuthParamClientSecretPost' discriminator: propertyName: type mapping: none: '#/components/schemas/CreateMcpOauthTokenEndpointAuthParamNone' client_secret_basic: '#/components/schemas/CreateMcpOauthTokenEndpointAuthParamClientSecretBasic' client_secret_post: '#/components/schemas/CreateMcpOauthTokenEndpointAuthParamClientSecretPost' x-oai-discriminator-values: - none - client_secret_basic - client_secret_post description: Client authentication credentials for OAuth token refresh. RotateVaultCredentialAuthParamEnvironmentVariable: type: object properties: type: type: string enum: - environment_variable default: environment_variable x-stainless-const: true description: The type of the object. Always `environment_variable`. secret_value: type: string minLength: 1 maxLength: 1048576 description: The write-only replacement secret. Never returned in credential resources or supplied directly to sandbox code. Must be nonempty and must not contain carriage returns, newlines, or NUL bytes. required: - type - secret_value additionalProperties: false description: Replace the secret for an OpenAI-hosted environment credential. The environment variable name and networking configuration remain unchanged. VaultCredentialResource: type: object properties: id: type: string minLength: 0 description: The ID of the credential. object: type: string enum: - vault.credential default: vault.credential x-stainless-const: true description: The object type. Always `vault.credential`. vault_id: type: string minLength: 0 description: The ID of the vault containing this credential. name: type: string minLength: 0 description: The human-readable name of the credential. auth: $ref: '#/components/schemas/VaultCredentialAuthResource' description: The authentication method and non-secret configuration of the credential. metadata: type: object additionalProperties: type: string minLength: 0 propertyNames: type: string minLength: 0 minProperties: 0 description: Application-defined key-value pairs associated with this credential. created_at: type: integer format: int64 description: The Unix timestamp, in seconds, when the credential was created. updated_at: type: integer format: int64 description: The Unix timestamp, in seconds, when the credential was last updated. required: - id - object - vault_id - name - auth - metadata - created_at - updated_at additionalProperties: false description: Metadata for a stored credential. Secret values are never returned. VaultCredentialListResource: type: object properties: object: type: string enum: - list default: list x-stainless-const: true description: The object type, which is always `list`. data: type: array items: $ref: '#/components/schemas/VaultCredentialResource' minItems: 0 maxItems: 2000 description: The resources returned in this page, in the requested sort order. first_id: type: - string - 'null' minLength: 0 description: The ID of the first resource in `data`, or `null` if the page is empty. last_id: type: - string - 'null' minLength: 0 description: The ID of the last resource in `data`, or `null` if the page is empty. Pass this as `after` with the same order and filters. has_more: type: boolean description: Whether there are more resources to retrieve after this page. required: - object - data - first_id - last_id - has_more additionalProperties: false description: A page of Agents API resources, with IDs for retrieving additional pages. RotateVaultCredentialAuthParamStaticBearer: type: object properties: type: type: string enum: - static_bearer default: static_bearer x-stainless-const: true description: The type of the object. Always `static_bearer`. token: type: string minLength: 0 maxLength: 1048576 description: The replacement bearer token. This secret is never returned in credential resources. required: - type - token additionalProperties: false description: Replace the bearer token for the credential's MCP server. ErrorResponse-2: type: object properties: error: $ref: '#/components/schemas/ErrorBodyResource' description: The error returned by the API. required: - error additionalProperties: false description: An API error response. ListOrderParam: type: string enum: - asc - desc x-enumDescriptions: - Returns resources in ascending order. - Returns resources in descending order. description: The order in which paginated resources are returned. VaultCredentialNetworkingParam: oneOf: - $ref: '#/components/schemas/VaultCredentialNetworkingParamUnrestricted' - $ref: '#/components/schemas/VaultCredentialNetworkingParamLimited' discriminator: propertyName: type mapping: unrestricted: '#/components/schemas/VaultCredentialNetworkingParamUnrestricted' limited: '#/components/schemas/VaultCredentialNetworkingParamLimited' x-oai-discriminator-values: - unrestricted - limited description: Destination permissions for an environment-variable credential. These do not grant network access to the environment. VaultCredentialNetworkingResourceUnrestricted: type: object properties: type: type: string enum: - unrestricted default: unrestricted x-stainless-const: true description: The type of the object. Always `unrestricted`. required: - type additionalProperties: false description: Allows substitution for destinations permitted by the environment network policy. Requires `environment.network.access` to be `restricted`, with explicit `allowed_domains`. RotateMcpOauthRefreshParam: type: object properties: refresh_token: type: - string - 'null' minLength: 0 maxLength: 1048576 description: The replacement refresh token. Omit or pass `null` to keep the stored token. This secret is never returned in resources. scope: type: - string - 'null' minLength: 0 maxLength: 1048576 description: Replacement space-separated OAuth scopes for refresh requests. Omit to keep the scopes, or pass `null` to stop sending a scope parameter. token_endpoint_auth: anyOf: - $ref: '#/components/schemas/RotateMcpOauthTokenEndpointAuthParam' - type: 'null' description: Client-secret updates for the existing token endpoint authentication method. additionalProperties: false description: Updates to an MCP credential's existing OAuth refresh configuration. McpOauthRefreshResource: type: object properties: token_endpoint: type: string minLength: 0 description: The HTTPS OAuth token endpoint used for refresh. client_id: type: string minLength: 0 description: The OAuth client ID used when requesting a new access token. resource: type: - string - 'null' minLength: 0 description: The resource URI sent to the OAuth token endpoint during refresh, if configured. scope: type: - string - 'null' minLength: 0 description: Space-separated OAuth scopes requested during refresh, if configured. token_endpoint_auth: $ref: '#/components/schemas/McpOauthTokenEndpointAuthResource' description: How the OAuth client authenticates to the token endpoint, excluding its client secret. required: - token_endpoint - client_id - resource - scope - token_endpoint_auth additionalProperties: false description: Configuration used to refresh an MCP OAuth access token, excluding secret values. VaultCredentialAuthResource: oneOf: - $ref: '#/components/schemas/VaultCredentialAuthResourceMcpOauth' - $ref: '#/components/schemas/VaultCredentialAuthResourceStaticBearer' - $ref: '#/components/schemas/VaultCredentialAuthResourceEnvironmentVariable' discriminator: propertyName: type mapping: mcp_oauth: '#/components/schemas/VaultCredentialAuthResourceMcpOauth' static_bearer: '#/components/schemas/VaultCredentialAuthResourceStaticBearer' environment_variable: '#/components/schemas/VaultCredentialAuthResourceEnvironmentVariable' x-oai-discriminator-values: - mcp_oauth - static_bearer - environment_variable description: The authentication configuration of a vault credential, excluding secrets. CreateMcpOauthTokenEndpointAuthParamNone: type: object properties: type: type: string enum: - none default: none x-stainless-const: true description: The type of the object. Always `none`. required: - type additionalProperties: false description: Sends the client ID without a client secret. VaultCredentialAuthResourceStaticBearer: type: object properties: type: type: string enum: - static_bearer default: static_bearer x-stainless-const: true description: The type of the object. Always `static_bearer`. mcp_server_url: type: string minLength: 0 description: The HTTPS MCP server URL authorized by this credential. required: - type - mcp_server_url additionalProperties: false description: Metadata for a bearer-token credential, without automatic OAuth refresh. VaultCredentialAuthResourceMcpOauth: type: object properties: type: type: string enum: - mcp_oauth default: mcp_oauth x-stainless-const: true description: The type of the object. Always `mcp_oauth`. mcp_server_url: type: string minLength: 0 description: The HTTPS MCP server URL authorized by this credential. expires_at: type: - string - 'null' minLength: 0 description: When the OAuth access token expires, as an RFC 3339 timestamp, if known. refresh: anyOf: - $ref: '#/components/schemas/McpOauthRefreshResource' - type: 'null' description: Public refresh metadata without refresh tokens or OAuth client secrets. required: - type - mcp_server_url - expires_at - refresh additionalProperties: false description: Public metadata for an OAuth credential; tokens and client secrets are never returned. CreateMcpOauthTokenEndpointAuthParamClientSecretPost: type: object properties: type: type: string enum: - client_secret_post default: client_secret_post x-stainless-const: true description: The type of the object. Always `client_secret_post`. client_secret: type: string minLength: 0 maxLength: 1048576 description: The OAuth client secret to store. Never returned in credential resources. required: - type - client_secret additionalProperties: false description: Sends the client ID and secret in the token request body. CreateVaultCredentialAuthParamStaticBearer: type: object properties: type: type: string enum: - static_bearer default: static_bearer x-stainless-const: true description: The type of the object. Always `static_bearer`. mcp_server_url: type: string minLength: 0 maxLength: 1048576 description: The HTTPS MCP server URL authorized by this credential. token: type: string minLength: 0 maxLength: 1048576 description: The bearer token to store. This secret is never returned in credential resources. required: - type - mcp_server_url - token additionalProperties: false description: A bearer token for an MCP server, without automatic OAuth refresh. RotateMcpOauthTokenEndpointAuthParam: oneOf: - $ref: '#/components/schemas/RotateMcpOauthTokenEndpointAuthParamClientSecretBasic' - $ref: '#/components/schemas/RotateMcpOauthTokenEndpointAuthParamClientSecretPost' discriminator: propertyName: type mapping: client_secret_basic: '#/components/schemas/RotateMcpOauthTokenEndpointAuthParamClientSecretBasic' client_secret_post: '#/components/schemas/RotateMcpOauthTokenEndpointAuthParamClientSecretPost' x-oai-discriminator-values: - client_secret_basic - client_secret_post description: Client-secret updates that preserve the credential's OAuth authentication method. RotateVaultCredentialParams: type: object properties: auth: $ref: '#/components/schemas/RotateVaultCredentialAuthParam' description: Replacement values for the credential's existing authentication method. metadata: type: object additionalProperties: type: string minLength: 0 maxLength: 512 propertyNames: type: string minLength: 1 maxLength: 64 minProperties: 0 maxProperties: 16 description: Replaces all metadata. Omit to preserve it, or pass {} to clear it. Up to 16 string key-value pairs, with keys up to 64 and values up to 512 characters. additionalProperties: false description: Metadata, secret, expiry, and OAuth refresh scope updates for an existing vault credential. Supply at least one of `auth` or `metadata`. VaultCredentialAuthResourceEnvironmentVariable: type: object properties: type: type: string enum: - environment_variable default: environment_variable x-stainless-const: true description: The type of the object. Always `environment_variable`. secret_name: type: string minLength: 0 description: The environment variable name that receives the placeholder in the sandbox. networking: $ref: '#/components/schemas/VaultCredentialNetworkingResource' description: The destinations where the proxy can substitute the secret, subject to the environment network policy. required: - type - secret_name - networking additionalProperties: false description: Metadata for an HTTP credential used only in OpenAI-hosted environments. Sandbox code receives a placeholder. The proxy substitutes the secret for allowed HTTPS destinations on ports 443 and 8443. The real secret is not available to sandbox code for local computation and is never returned in this resource. CreateVaultCredentialParams: type: object properties: name: type: string minLength: 1 maxLength: 1048576 description: The name is trimmed before storage. It must contain 1 to 256 UTF-8 bytes after trimming. auth: $ref: '#/components/schemas/CreateVaultCredentialAuthParam' description: The authentication method and write-only secret values to store. metadata: type: object additionalProperties: type: string minLength: 0 maxLength: 512 propertyNames: type: string minLength: 1 maxLength: 64 minProperties: 0 maxProperties: 16 description: Up to 16 string key-value pairs, with keys up to 64 and values up to 512 characters. Defaults to an empty map. required: - auth - name additionalProperties: false description: Parameters for storing a credential for an MCP server or an OpenAI-hosted environment. McpOauthTokenEndpointAuthResourceClientSecretPost: type: object properties: type: type: string enum: - client_secret_post default: client_secret_post x-stainless-const: true description: The type of the object. Always `client_secret_post`. required: - type additionalProperties: false description: Sends the client ID and secret in the token request body. ErrorBodyResource: type: object properties: type: type: string minLength: 0 description: The error type. code: type: string minLength: 0 description: A machine-readable error code. message: type: string minLength: 0 description: A human-readable error message. param: type: - string - 'null' minLength: 0 description: The request parameter that caused the error, or null for a request-wide error. required: - type - code - message - param additionalProperties: false description: Details about an API error. VaultStatusFilterParam: oneOf: - $ref: '#/components/schemas/VaultStatusParam' - type: array items: $ref: '#/components/schemas/VaultStatusParam' minItems: 0 maxItems: 16384 description: One or more lifecycle statuses to include when listing vaults or credentials. VaultStatusParam: type: string enum: - active - archived description: Whether a vault or credential is active or archived. VaultResource: type: object properties: id: type: string minLength: 0 description: The ID of the vault. object: type: string enum: - vault default: vault x-stainless-const: true description: The object type. Always `vault`. name: type: - string - 'null' minLength: 0 description: The human-readable name of the vault, if set. metadata: type: object additionalProperties: type: string minLength: 0 propertyNames: type: string minLength: 0 minProperties: 0 description: Key-value pairs associated with the vault, such as an application or team identifier. created_at: type: integer format: int64 description: The Unix timestamp, in seconds, when the vault was created. required: - id - object - name - metadata - created_at additionalProperties: false description: A collection of credentials for MCP servers and OpenAI-hosted environments. DeletedVaultCredentialResource: type: object properties: id: type: string minLength: 0 description: The ID of the deleted credential. object: type: string enum: - vault.credential.deleted default: vault.credential.deleted x-stainless-const: true description: The object type. Always `vault.credential.deleted`. deleted: type: boolean description: Whether the resource was deleted. Always `true`. required: - id - object - deleted additionalProperties: false description: Confirmation that a vault credential was deleted. CreateVaultCredentialAuthParamMcpOauth: type: object properties: type: type: string enum: - mcp_oauth default: mcp_oauth x-stainless-const: true description: The type of the object. Always `mcp_oauth`. mcp_server_url: type: string minLength: 0 maxLength: 1048576 description: The HTTPS MCP server URL authorized by this credential. access_token: type: string minLength: 0 maxLength: 1048576 description: A write-only OAuth access token; never returned by credential resources. expires_at: type: - string - 'null' minLength: 0 maxLength: 1048576 description: When the OAuth access token expires, as an RFC 3339 timestamp, if known. refresh: anyOf: - $ref: '#/components/schemas/CreateMcpOauthRefreshParam' - type: 'null' description: Optional refresh configuration for an HTTPS OAuth token endpoint. required: - type - mcp_server_url - access_token additionalProperties: false description: An OAuth credential for an HTTPS MCP destination. RotateMcpOauthTokenEndpointAuthParamClientSecretBasic: type: object properties: type: type: string enum: - client_secret_basic default: client_secret_basic x-stainless-const: true description: The type of the object. Always `client_secret_basic`. client_secret: type: - string - 'null' minLength: 0 maxLength: 1048576 description: The replacement OAuth client secret. Omit or pass `null` to keep the stored secret. This secret is never returned in resources. required: - type additionalProperties: false description: Updates credentials sent using HTTP Basic authentication. CreateVaultCredentialAuthParamEnvironmentVariable: type: object properties: type: type: string enum: - environment_variable default: environment_variable x-stainless-const: true description: The type of the object. Always `environment_variable`. secret_name: type: string minLength: 1 maxLength: 1048576 description: The environment variable name that receives the placeholder, such as `SERVICE_API_KEY`. Use ASCII letters, digits, and underscores, starting with a letter or underscore. Names starting with `CODEX_` and managed proxy or certificate variable names are reserved. secret_value: type: string minLength: 1 maxLength: 1048576 description: The write-only secret to store. Never returned in credential resources or supplied directly to sandbox code. Must be nonempty and must not contain carriage returns, newlines, or NUL bytes. networking: $ref: '#/components/schemas/VaultCredentialNetworkingParam' description: The destinations where the proxy can substitute this secret. The environment network policy must also allow them. required: - type - secret_name - secret_value - networking additionalProperties: false description: An HTTP credential for OpenAI-hosted environments only. The sandbox receives an environment variable containing a placeholder, not the secret. Use the placeholder unchanged in outgoing requests. The egress proxy replaces the placeholder with the secret for allowed HTTPS destinations on ports 443 and 8443. Sandbox code cannot read the real secret or use it for local computation, such as signing a request. VaultCredentialNetworkingResource: oneOf: - $ref: '#/components/schemas/VaultCredentialNetworkingResourceUnrestricted' - $ref: '#/components/schemas/VaultCredentialNetworkingResourceLimited' discriminator: propertyName: type mapping: unrestricted: '#/components/schemas/VaultCredentialNetworkingResourceUnrestricted' limited: '#/components/schemas/VaultCredentialNetworkingResourceLimited' x-oai-discriminator-values: - unrestricted - limited description: Destination permissions for an environment-variable credential. These do not grant network access to the environment. VaultCredentialNetworkingParamUnrestricted: type: object properties: type: type: string enum: - unrestricted default: unrestricted x-stainless-const: true description: The type of the object. Always `unrestricted`. required: - type additionalProperties: false description: Allows substitution for destinations permitted by the environment network policy. Requires `environment.network.access` to be `restricted`, with explicit `allowed_domains`. McpOauthTokenEndpointAuthResource: oneOf: - $ref: '#/components/schemas/McpOauthTokenEndpointAuthResourceNone' - $ref: '#/components/schemas/McpOauthTokenEndpointAuthResourceClientSecretBasic' - $ref: '#/components/schemas/McpOauthTokenEndpointAuthResourceClientSecretPost' discriminator: propertyName: type mapping: none: '#/components/schemas/McpOauthTokenEndpointAuthResourceNone' client_secret_basic: '#/components/schemas/McpOauthTokenEndpointAuthResourceClientSecretBasic' client_secret_post: '#/components/schemas/McpOauthTokenEndpointAuthResourceClientSecretPost' x-oai-discriminator-values: - none - client_secret_basic - client_secret_post description: The client authentication method used for OAuth token refresh. CreateMcpOauthTokenEndpointAuthParamClientSecretBasic: type: object properties: type: type: string enum: - client_secret_basic default: client_secret_basic x-stainless-const: true description: The type of the object. Always `client_secret_basic`. client_secret: type: string minLength: 0 maxLength: 1048576 description: The OAuth client secret to store. Never returned in credential resources. required: - type - client_secret additionalProperties: false description: Sends the client ID and secret using HTTP Basic authentication. McpOauthTokenEndpointAuthResourceClientSecretBasic: type: object properties: type: type: string enum: - client_secret_basic default: client_secret_basic x-stainless-const: true description: The type of the object. Always `client_secret_basic`. required: - type additionalProperties: false description: Sends the client ID and secret using HTTP Basic authentication. DeletedVaultResource: type: object properties: id: type: string minLength: 0 description: The ID of the deleted vault. object: type: string enum: - vault.deleted default: vault.deleted x-stainless-const: true description: The object type. Always `vault.deleted`. deleted: type: boolean description: Whether the resource was deleted. Always `true`. required: - id - object - deleted additionalProperties: false description: Confirmation that a vault was deleted. VaultListResource: type: object properties: object: type: string enum: - list default: list x-stainless-const: true description: The object type, which is always `list`. data: type: array items: $ref: '#/components/schemas/VaultResource' minItems: 0 maxItems: 2000 description: The resources returned in this page, in the requested sort order. first_id: type: - string - 'null' minLength: 0 description: The ID of the first resource in `data`, or `null` if the page is empty. last_id: type: - string - 'null' minLength: 0 description: The ID of the last resource in `data`, or `null` if the page is empty. Pass this as `after` with the same order and filters. has_more: type: boolean description: Whether there are more resources to retrieve after this page. required: - object - data - first_id - last_id - has_more additionalProperties: false description: A page of Agents API resources, with IDs for retrieving additional pages. CreateVaultCredentialAuthParam: oneOf: - $ref: '#/components/schemas/CreateVaultCredentialAuthParamMcpOauth' - $ref: '#/components/schemas/CreateVaultCredentialAuthParamStaticBearer' - $ref: '#/components/schemas/CreateVaultCredentialAuthParamEnvironmentVariable' discriminator: propertyName: type mapping: mcp_oauth: '#/components/schemas/CreateVaultCredentialAuthParamMcpOauth' static_bearer: '#/components/schemas/CreateVaultCredentialAuthParamStaticBearer' environment_variable: '#/components/schemas/CreateVaultCredentialAuthParamEnvironmentVariable' x-oai-discriminator-values: - mcp_oauth - static_bearer - environment_variable description: Authentication credentials for an MCP server or an OpenAI-hosted environment. CreateMcpOauthRefreshParam: type: object properties: token_endpoint: type: string minLength: 0 maxLength: 1048576 description: The HTTPS OAuth token endpoint used to exchange the refresh token for a new access token. client_id: type: string minLength: 0 maxLength: 1048576 description: The OAuth client ID used when requesting a new access token. resource: type: - string - 'null' minLength: 0 maxLength: 1048576 description: The resource URI to send to the OAuth token endpoint during refresh, if required. scope: type: - string - 'null' minLength: 0 maxLength: 1048576 description: Space-separated OAuth scopes to request during refresh, if required. refresh_token: type: string minLength: 0 maxLength: 1048576 description: The refresh token to store. This secret is never returned in credential resources. token_endpoint_auth: $ref: '#/components/schemas/CreateMcpOauthTokenEndpointAuthParam' description: How the OAuth client authenticates to the token endpoint. required: - token_endpoint - client_id - refresh_token - token_endpoint_auth additionalProperties: false description: Configuration for refreshing the access token of an MCP OAuth credential. securitySchemes: ApiKeyAuth: type: http scheme: bearer AdminApiKeyAuth: type: http scheme: bearer x-oaiMeta: navigationGroups: - id: responses title: Responses API - id: webhooks title: Webhooks - id: endpoints title: Platform APIs - id: vector_stores title: Vector stores - id: chatkit title: ChatKit beta: true - id: containers title: Containers - id: live title: Live (alpha) - id: realtime title: Realtime - id: chat title: Chat Completions - id: assistants title: Assistants deprecated: true - id: administration title: Administration - id: legacy title: Legacy groups: - id: responses-streaming title: Streaming events description: 'When you [create a Response](https://developers.openai.com/api/reference/resources/responses/methods/create) with `stream` set to `true`, the server will emit server-sent events to the client as the Response is generated. This section contains the events that are emitted by the server. When processing a `compaction_trigger`, `response.compaction.compacting` reports newly sampled summary output at most once every 30 seconds. It carries no summary content and does not modify the compaction output item. The existing `response.output_item.added` and `response.output_item.done` events mark that item''s lifecycle; `response.output_item.done` carries its final encrypted content. A short compaction may finish without emitting a progress event. [Learn more about streaming responses](https://developers.openai.com/api/docs/guides/streaming-responses). ' navigationGroup: responses sections: - type: object key: ResponseCreatedEvent path: - type: object key: ResponseInProgressEvent path: - type: object key: ResponseCompletedEvent path: - type: object key: ResponseFailedEvent path: - type: object key: ResponseIncompleteEvent path: - type: object key: ResponseOutputItemAddedEvent path: - type: object key: ResponseOutputItemDoneEvent path: - type: object key: ResponseCompactionCompactingEvent path: - type: object key: ResponseContentPartAddedEvent path: - type: object key: ResponseContentPartDoneEvent path: - type: object key: ResponseTextDeltaEvent path: response/output_text/delta - type: object key: ResponseTextDoneEvent path: response/output_text/done - type: object key: ResponseRefusalDeltaEvent path: - type: object key: ResponseRefusalDoneEvent path: - type: object key: ResponseFunctionCallArgumentsDeltaEvent path: - type: object key: ResponseFunctionCallArgumentsDoneEvent path: - type: object key: ResponseFileSearchCallInProgressEvent path: - type: object key: ResponseFileSearchCallSearchingEvent path: - type: object key: ResponseFileSearchCallCompletedEvent path: - type: object key: ResponseWebSearchCallInProgressEvent path: - type: object key: ResponseWebSearchCallSearchingEvent path: - type: object key: ResponseWebSearchCallCompletedEvent path: - type: object key: ResponseReasoningSummaryPartAddedEvent path: - type: object key: ResponseReasoningSummaryPartDoneEvent path: - type: object key: ResponseReasoningSummaryTextDeltaEvent path: - type: object key: ResponseReasoningSummaryTextDoneEvent path: - type: object key: ResponseReasoningTextDeltaEvent path: - type: object key: ResponseReasoningTextDoneEvent path: - type: object key: ResponseImageGenCallCompletedEvent path: - type: object key: ResponseImageGenCallGeneratingEvent path: - type: object key: ResponseImageGenCallInProgressEvent path: - type: object key: ResponseImageGenCallPartialImageEvent path: - type: object key: ResponseMCPCallArgumentsDeltaEvent path: - type: object key: ResponseMCPCallArgumentsDoneEvent path: - type: object key: ResponseMCPCallCompletedEvent path: - type: object key: ResponseMCPCallFailedEvent path: - type: object key: ResponseMCPCallInProgressEvent path: - type: object key: ResponseMCPListToolsCompletedEvent path: - type: object key: ResponseMCPListToolsFailedEvent path: - type: object key: ResponseMCPListToolsInProgressEvent path: - type: object key: ResponseCodeInterpreterCallInProgressEvent path: - type: object key: ResponseCodeInterpreterCallInterpretingEvent path: - type: object key: ResponseCodeInterpreterCallCompletedEvent path: - type: object key: ResponseCodeInterpreterCallCodeDeltaEvent path: - type: object key: ResponseCodeInterpreterCallCodeDoneEvent path: - type: object key: ResponseOutputTextAnnotationAddedEvent path: - type: object key: ResponseQueuedEvent path: - type: object key: ResponseCustomToolCallInputDeltaEvent path: - type: object key: ResponseCustomToolCallInputDoneEvent path: - type: object key: ResponseErrorEvent path: - id: responses-websocket-client-events title: Client events description: 'Events sent by the client over a Responses API WebSocket connection. ' navigationGroup: responses sections: - type: object key: ResponsesClientEventResponseCreate path: - type: object key: ResponseSteerEvent path: - id: responses-websocket-server-events title: Server events (WebSocket only) description: 'Events emitted only over a Responses API WebSocket connection. ' navigationGroup: responses sections: - type: object key: ResponseSteerAcceptedEvent path: - type: object key: ResponseSteerPendingEvent path: - type: object key: ResponseSteerFailedEvent path: - id: responses-websocket-shared-events title: Server events description: 'These events use the same payloads over WebSocket and [HTTP streaming](https://developers.openai.com/api/reference/resources/responses/streaming-events). Compaction progress follows the same cadence and output-item lifecycle described in HTTP streaming. ' navigationGroup: responses sections: - type: object key: ResponseCreatedEvent path: - type: object key: ResponseInProgressEvent path: - type: object key: ResponseCompletedEvent path: - type: object key: ResponseFailedEvent path: - type: object key: ResponseIncompleteEvent path: - type: object key: ResponseOutputItemAddedEvent path: - type: object key: ResponseOutputItemDoneEvent path: - type: object key: ResponseCompactionCompactingEvent path: - type: object key: ResponseContentPartAddedEvent path: - type: object key: ResponseContentPartDoneEvent path: - type: object key: ResponseTextDeltaEvent path: response/output_text/delta - type: object key: ResponseTextDoneEvent path: response/output_text/done - type: object key: ResponseRefusalDeltaEvent path: - type: object key: ResponseRefusalDoneEvent path: - type: object key: ResponseFunctionCallArgumentsDeltaEvent path: - type: object key: ResponseFunctionCallArgumentsDoneEvent path: - type: object key: ResponseFileSearchCallInProgressEvent path: - type: object key: ResponseFileSearchCallSearchingEvent path: - type: object key: ResponseFileSearchCallCompletedEvent path: - type: object key: ResponseWebSearchCallInProgressEvent path: - type: object key: ResponseWebSearchCallSearchingEvent path: - type: object key: ResponseWebSearchCallCompletedEvent path: - type: object key: ResponseReasoningSummaryPartAddedEvent path: - type: object key: ResponseReasoningSummaryPartDoneEvent path: - type: object key: ResponseReasoningSummaryTextDeltaEvent path: - type: object key: ResponseReasoningSummaryTextDoneEvent path: - type: object key: ResponseReasoningTextDeltaEvent path: - type: object key: ResponseReasoningTextDoneEvent path: - type: object key: ResponseImageGenCallCompletedEvent path: - type: object key: ResponseImageGenCallGeneratingEvent path: - type: object key: ResponseImageGenCallInProgressEvent path: - type: object key: ResponseImageGenCallPartialImageEvent path: - type: object key: ResponseMCPCallArgumentsDeltaEvent path: - type: object key: ResponseMCPCallArgumentsDoneEvent path: - type: object key: ResponseMCPCallCompletedEvent path: - type: object key: ResponseMCPCallFailedEvent path: - type: object key: ResponseMCPCallInProgressEvent path: - type: object key: ResponseMCPListToolsCompletedEvent path: - type: object key: ResponseMCPListToolsFailedEvent path: - type: object key: ResponseMCPListToolsInProgressEvent path: - type: object key: ResponseCodeInterpreterCallInProgressEvent path: - type: object key: ResponseCodeInterpreterCallInterpretingEvent path: - type: object key: ResponseCodeInterpreterCallCompletedEvent path: - type: object key: ResponseCodeInterpreterCallCodeDeltaEvent path: - type: object key: ResponseCodeInterpreterCallCodeDoneEvent path: - type: object key: ResponseOutputTextAnnotationAddedEvent path: - type: object key: ResponseQueuedEvent path: - type: object key: ResponseCustomToolCallInputDeltaEvent path: - type: object key: ResponseCustomToolCallInputDoneEvent path: - type: object key: ResponseErrorEvent path: - id: safety-cases title: Safety Cases description: 'Retrieve details about a safety warning or deactivation using the case ID from a `safety.warning_issued` or `safety.deactivation_issued` webhook event. Cases belong to an organization and require an API key with `api.safety.read`. ' navigationGroup: endpoints sections: - type: endpoint key: Getsafetycase path: retrieve - type: object key: SafetyCaseResource path: object - id: safety-alerts title: Safety Alerts description: 'Retrieve approved safety alerts with an API key. Project keys require `api.safety.alerts.read` and can read alerts from their project. ' navigationGroup: endpoints sections: - type: endpoint key: Getprojectsafetyalert path: retrieve - type: object key: SafetyAlertResource path: object - id: webhook-events title: Webhook Events description: 'Webhooks are HTTP requests sent by OpenAI to a URL you specify when certain events happen during the course of API usage. [Learn more about webhooks](https://developers.openai.com/api/docs/guides/webhooks). ' navigationGroup: webhooks sections: - type: object key: WebhookResponseCompleted path: - type: object key: WebhookResponseCancelled path: - type: object key: WebhookResponseFailed path: - type: object key: WebhookResponseIncomplete path: - type: object key: WebhookBatchCompleted path: - type: object key: WebhookBatchCancelled path: - type: object key: WebhookBatchExpired path: - type: object key: WebhookBatchFailed path: - type: object key: WebhookFineTuningJobSucceeded path: - type: object key: WebhookFineTuningJobFailed path: - type: object key: WebhookFineTuningJobCancelled path: - type: object key: WebhookEvalRunSucceeded path: - type: object key: WebhookEvalRunFailed path: - type: object key: WebhookEvalRunCanceled path: - type: object key: WebhookRealtimeCallIncoming path: - type: object key: WebhookLiveCallIncoming path: - type: object key: WebhookLiveTransportIncoming path: - type: object key: WebhookSafetyWarningIssued path: - type: object key: WebhookSafetyDeactivationIssued path: - type: object key: WebhookSafetyAlertCreated path: - type: object key: WebhookSafetyOrgAlertCreated path: - id: images-streaming title: Image Streaming description: 'Stream image generation and editing in real time with server-sent events. [Learn more about image streaming](https://developers.openai.com/api/docs/guides/image-generation). ' navigationGroup: endpoints sections: - type: object key: ImageGenPartialImageEvent path: - type: object key: ImageGenCompletedEvent path: - type: object key: ImageEditPartialImageEvent path: - type: object key: ImageEditCompletedEvent path: - id: realtime-client-events title: Client events description: 'These are events that the OpenAI Realtime WebSocket server will accept from the client. ' navigationGroup: realtime sections: - type: object key: RealtimeClientEventSessionUpdate path: - type: object key: RealtimeClientEventInputAudioBufferAppend path: - type: object key: RealtimeClientEventInputAudioBufferCommit path: - type: object key: RealtimeClientEventInputAudioBufferClear path: - type: object key: RealtimeClientEventConversationItemCreate path: - type: object key: RealtimeClientEventConversationItemRetrieve path: - type: object key: RealtimeClientEventConversationItemTruncate path: - type: object key: RealtimeClientEventConversationItemDelete path: - type: object key: RealtimeClientEventResponseCreate path: - type: object key: RealtimeClientEventResponseCancel path: - type: object key: RealtimeClientEventOutputAudioBufferClear path: - id: realtime-server-events title: Server events description: 'These are events emitted from the OpenAI Realtime WebSocket server to the client. ' navigationGroup: realtime sections: - type: object key: RealtimeServerEventError path: - type: object key: RealtimeServerEventSessionCreated path: - type: object key: RealtimeServerEventSessionUpdated path: - type: object key: RealtimeServerEventConversationItemAdded path: - type: object key: RealtimeServerEventConversationItemDone path: - type: object key: RealtimeServerEventConversationItemRetrieved path: - type: object key: RealtimeServerEventConversationItemInputAudioTranscriptionCompleted path: - type: object key: RealtimeServerEventConversationItemInputAudioTranscriptionDelta path: - type: object key: RealtimeServerEventConversationItemInputAudioTranscriptionSegment path: - type: object key: RealtimeServerEventConversationItemInputAudioTranscriptionFailed path: - type: object key: RealtimeServerEventConversationItemTruncated path: - type: object key: RealtimeServerEventConversationItemDeleted path: - type: object key: RealtimeServerEventInputAudioBufferCommitted path: - type: object key: RealtimeServerEventInputAudioBufferDtmfEventReceived path: - type: object key: RealtimeServerEventInputAudioBufferCleared path: - type: object key: RealtimeServerEventInputAudioBufferSpeechStarted path: - type: object key: RealtimeServerEventInputAudioBufferSpeechStopped path: - type: object key: RealtimeServerEventInputAudioBufferTimeoutTriggered path: - type: object key: RealtimeServerEventOutputAudioBufferStarted path: - type: object key: RealtimeServerEventOutputAudioBufferStopped path: - type: object key: RealtimeServerEventOutputAudioBufferCleared path: - type: object key: RealtimeServerEventResponseCreated path: - type: object key: RealtimeServerEventResponseDone path: - type: object key: RealtimeServerEventResponseOutputItemAdded path: - type: object key: RealtimeServerEventResponseOutputItemDone path: - type: object key: RealtimeServerEventResponseContentPartAdded path: - type: object key: RealtimeServerEventResponseContentPartDone path: - type: object key: RealtimeServerEventResponseTextDelta path: - type: object key: RealtimeServerEventResponseTextDone path: - type: object key: RealtimeServerEventResponseAudioTranscriptDelta path: - type: object key: RealtimeServerEventResponseAudioTranscriptDone path: - type: object key: RealtimeServerEventResponseAudioDelta path: - type: object key: RealtimeServerEventResponseAudioDone path: - type: object key: RealtimeServerEventResponseFunctionCallArgumentsDelta path: - type: object key: RealtimeServerEventResponseFunctionCallArgumentsDone path: - type: object key: RealtimeServerEventResponseMCPCallArgumentsDelta path: - type: object key: RealtimeServerEventResponseMCPCallArgumentsDone path: - type: object key: RealtimeServerEventResponseMCPCallInProgress path: - type: object key: RealtimeServerEventResponseMCPCallCompleted path: - type: object key: RealtimeServerEventResponseMCPCallFailed path: - type: object key: RealtimeServerEventMCPListToolsInProgress path: - type: object key: RealtimeServerEventMCPListToolsCompleted path: - type: object key: RealtimeServerEventMCPListToolsFailed path: - type: object key: RealtimeServerEventRateLimitsUpdated path: - id: realtime-translation-client-events title: Translation client events description: 'These are events that the OpenAI Realtime Translation WebSocket server will accept from the client. ' navigationGroup: realtime sections: - type: object key: RealtimeTranslationClientEventSessionUpdate path: - type: object key: RealtimeTranslationClientEventInputAudioBufferAppend path: - type: object key: RealtimeTranslationClientEventSessionClose path: - id: realtime-translation-server-events title: Translation server events description: 'These are events emitted from the OpenAI Realtime Translation WebSocket server to the client. ' navigationGroup: realtime sections: - type: object key: RealtimeServerEventError path: - type: object key: RealtimeTranslationServerEventSessionCreated path: - type: object key: RealtimeTranslationServerEventSessionUpdated path: - type: object key: RealtimeTranslationServerEventSessionClosed path: - type: object key: RealtimeTranslationServerEventSessionInputTranscriptDelta path: - type: object key: RealtimeTranslationServerEventSessionOutputTranscriptDelta path: - type: object key: RealtimeTranslationServerEventSessionOutputAudioDelta path: - id: chat-streaming title: Streaming description: 'Stream Chat Completions in real time. Receive chunks of completions returned from the model using server-sent events. [Learn more](https://developers.openai.com/api/docs/guides/streaming-responses). ' navigationGroup: chat sections: - type: object key: CreateChatCompletionStreamResponse path: streaming - id: assistants-streaming title: Streaming beta: true description: 'Stream the result of executing a Run or resuming a Run after submitting tool outputs. You can stream events from the [Create Thread and Run](https://developers.openai.com/api/docs/assistants/migration), [Create Run](https://developers.openai.com/api/docs/assistants/migration), and [Submit Tool Outputs](https://developers.openai.com/api/docs/assistants/migration) endpoints by passing `"stream": true`. The response will be a [Server-Sent events](https://html.spec.whatwg.org/multipage/server-sent-events.html#server-sent-events) stream. Our Node and Python SDKs provide helpful utilities to make streaming easy. Reference the [Assistants API quickstart](https://developers.openai.com/api/docs/assistants/migration) to learn more. ' navigationGroup: assistants sections: - type: object key: AssistantStreamEvent path: events - id: realtime-beta-client-events title: Realtime Beta client events description: 'These are events that the OpenAI Realtime WebSocket server will accept from the client. ' navigationGroup: legacy sections: - type: object key: RealtimeBetaClientEventSessionUpdate path: - type: object key: RealtimeBetaClientEventInputAudioBufferAppend path: - type: object key: RealtimeBetaClientEventInputAudioBufferCommit path: - type: object key: RealtimeBetaClientEventInputAudioBufferClear path: - type: object key: RealtimeBetaClientEventConversationItemCreate path: - type: object key: RealtimeBetaClientEventConversationItemRetrieve path: - type: object key: RealtimeBetaClientEventConversationItemTruncate path: - type: object key: RealtimeBetaClientEventConversationItemDelete path: - type: object key: RealtimeBetaClientEventResponseCreate path: - type: object key: RealtimeBetaClientEventResponseCancel path: - type: object key: RealtimeBetaClientEventTranscriptionSessionUpdate path: - type: object key: RealtimeBetaClientEventOutputAudioBufferClear path: - id: realtime-beta-server-events title: Realtime Beta server events description: 'These are events emitted from the OpenAI Realtime WebSocket server to the client. ' navigationGroup: legacy sections: - type: object key: RealtimeBetaServerEventError path: - type: object key: RealtimeBetaServerEventSessionCreated path: - type: object key: RealtimeBetaServerEventSessionUpdated path: - type: object key: RealtimeBetaServerEventTranscriptionSessionCreated path: - type: object key: RealtimeBetaServerEventTranscriptionSessionUpdated path: - type: object key: RealtimeBetaServerEventConversationItemCreated path: - type: object key: RealtimeBetaServerEventConversationItemRetrieved path: - type: object key: RealtimeBetaServerEventConversationItemInputAudioTranscriptionCompleted path: - type: object key: RealtimeBetaServerEventConversationItemInputAudioTranscriptionDelta path: - type: object key: RealtimeBetaServerEventConversationItemInputAudioTranscriptionSegment path: - type: object key: RealtimeBetaServerEventConversationItemInputAudioTranscriptionFailed path: - type: object key: RealtimeBetaServerEventConversationItemTruncated path: - type: object key: RealtimeBetaServerEventConversationItemDeleted path: - type: object key: RealtimeBetaServerEventInputAudioBufferCommitted path: - type: object key: RealtimeBetaServerEventInputAudioBufferCleared path: - type: object key: RealtimeBetaServerEventInputAudioBufferSpeechStarted path: - type: object key: RealtimeBetaServerEventInputAudioBufferSpeechStopped path: - type: object key: RealtimeServerEventInputAudioBufferTimeoutTriggered path: - type: object key: RealtimeBetaServerEventResponseCreated path: - type: object key: RealtimeBetaServerEventResponseDone path: - type: object key: RealtimeBetaServerEventResponseOutputItemAdded path: - type: object key: RealtimeBetaServerEventResponseOutputItemDone path: - type: object key: RealtimeBetaServerEventResponseContentPartAdded path: - type: object key: RealtimeBetaServerEventResponseContentPartDone path: - type: object key: RealtimeBetaServerEventResponseTextDelta path: - type: object key: RealtimeBetaServerEventResponseTextDone path: - type: object key: RealtimeBetaServerEventResponseAudioTranscriptDelta path: - type: object key: RealtimeBetaServerEventResponseAudioTranscriptDone path: - type: object key: RealtimeBetaServerEventResponseAudioDelta path: - type: object key: RealtimeBetaServerEventResponseAudioDone path: - type: object key: RealtimeBetaServerEventResponseFunctionCallArgumentsDelta path: - type: object key: RealtimeBetaServerEventResponseFunctionCallArgumentsDone path: - type: object key: RealtimeBetaServerEventResponseMCPCallArgumentsDelta path: - type: object key: RealtimeBetaServerEventResponseMCPCallArgumentsDone path: - type: object key: RealtimeBetaServerEventResponseMCPCallInProgress path: - type: object key: RealtimeBetaServerEventResponseMCPCallCompleted path: - type: object key: RealtimeBetaServerEventResponseMCPCallFailed path: - type: object key: RealtimeBetaServerEventMCPListToolsInProgress path: - type: object key: RealtimeBetaServerEventMCPListToolsCompleted path: - type: object key: RealtimeBetaServerEventMCPListToolsFailed path: - type: object key: RealtimeBetaServerEventRateLimitsUpdated path: - id: live-client-events title: Client events description: Initialize a primary WebSocket with session.start and wait for session.started before sending other events. WebRTC creation starts the session for you. Start with the [Live prompting guide](https://developers.openai.com/api/docs/guides/live-prompting) to design frontend instructions and delegation policy; see [backend prompting](https://developers.openai.com/api/docs/guides/live-delegation#start-with-your-existing-backend-prompt) for tools and business rules. navigationGroup: live sections: - type: object key: LiveSessionStartEvent path: - type: object key: LiveForkSessionStartEvent path: - type: object key: LiveSessionUpdateParam path: - type: object key: LiveInputAudioAppendEvent path: - type: object key: LiveInputAudioMuteParam path: - type: object key: LiveInputAudioUnmuteParam path: - type: object key: LiveInstructionsAppendParam path: - type: object key: LiveThinkingAppendParam path: - type: object key: LiveCommentaryAppendParam path: - type: object key: LiveResponseItemCreateParam path: - type: object key: LiveResponseCreateParam path: - type: object key: LiveSessionCloseParam path: - id: live-server-events title: Server events description: Live server events. Responses delegation lifecycle events arrive inside response.event, not as top-level response events. Start with the [Live prompting guide](https://developers.openai.com/api/docs/guides/live-prompting) to design frontend instructions and delegation policy; see [backend prompting](https://developers.openai.com/api/docs/guides/live-delegation#start-with-your-existing-backend-prompt) for tools and business rules. navigationGroup: live sections: - type: object key: LiveSessionStarted path: - type: object key: LiveSessionUpdated path: - type: object key: LiveInputAudioMuted path: - type: object key: LiveInputAudioUnmuted path: - type: object key: LiveInstructionsAppended path: - type: object key: LiveThinkingAppended path: - type: object key: LiveCommentaryAppended path: - type: object key: LiveOutputAudioDelta path: - type: object key: LiveInputTranscriptDelta path: - type: object key: LiveOutputTranscriptDelta path: - type: object key: LiveDelegationCreated path: - type: object key: LiveResponseEvent path: - type: object key: LiveSessionUsageUpdated path: - type: object key: LiveSessionClosed path: - type: object key: LiveErrorEvent path: - type: object key: LiveInfoEvent path: