openapi: 3.2.0 info: title: LiteLLM Plugins API description: "Enterprise Edition \n\nProxy Server to call 100+ LLMs in the OpenAI format. [**Customize Swagger Docs**](https://docs.litellm.ai/docs/proxy/enterprise#swagger-docs---custom-routes--branding)\n\n\U0001F449 [```LiteLLM Admin Panel on /ui```](/ui). Create, Edit Keys with SSO. Having issues? Try [```Fallback Login```](/fallback/login)\n\n\U0001F4B8 [```LiteLLM Model Cost Map```](https://models.litellm.ai/).\n\n\U0001F50E [```LiteLLM Model Hub```](/ui/model_hub_table). See available models on the proxy. [**Docs**](https://docs.litellm.ai/docs/proxy/ai_hub)" version: 1.95.0 x-operator: institution x-provenance: method: probed source: https://llmproxy.uva.nl/openapi.json retrieved: '2026-08-19' note: Document is generated by the LiteLLM proxy software the University of Amsterdam self-hosts; the deployment, the key issuance and the host (llmproxy.uva.nl, UvA Azure) are the institution's. servers[] added by API Evangelist because the served document omits it; nothing else altered. servers: - url: https://llmproxy.uva.nl description: University of Amsterdam / Amsterdam University of Applied Sciences shared AI gateway tags: - name: plugins paths: /api/plugins: get: tags: - plugins summary: List Plugins description: 'Return registered plugins for authenticated UI callers. plugin_key is never returned — the browser never needs it (the proxy injects it server-side from the registry), and exposing it here would leak the credential into React state and DevTools. Admin key management goes through the redacted /config/field/info path instead.' operationId: list_plugins_api_plugins_get responses: '200': description: Successful Response content: application/json: schema: items: additionalProperties: type: string type: object type: array title: Response List Plugins Api Plugins Get security: - APIKeyHeader: [] /api/plugins/auth-token: get: tags: - plugins summary: Plugin Auth Token description: 'Issue a short-lived, audience-scoped plugin session claim. The claim contains {user_id, user_role, plugin, exp}. It does NOT contain the caller''s litellm bearer token — a compromised plugin can only learn the caller''s identity, not impersonate them against the proxy. Encrypted with a key derived from HMAC(LITELLM_SALT_KEY, plugin_name), so each plugin holds only its own key and cannot forge claims for others. Requires LITELLM_SALT_KEY to be set; returns 503 otherwise.' operationId: plugin_auth_token_api_plugins_auth_token_get security: - APIKeyHeader: [] parameters: - name: plugin_name in: query required: false schema: type: string default: litellm-platform-plugin title: Plugin Name responses: '200': description: Successful Response content: application/json: schema: type: object additionalProperties: true title: Response Plugin Auth Token Api Plugins Auth Token Get '422': description: Validation Error content: application/json: schema: $ref: '#/components/schemas/HTTPValidationError' components: schemas: HTTPValidationError: properties: detail: items: $ref: '#/components/schemas/ValidationError' type: array title: Detail type: object title: HTTPValidationError ValidationError: properties: loc: items: anyOf: - type: string - type: integer type: array title: Location msg: type: string title: Message type: type: string title: Error Type input: title: Input ctx: type: object title: Context type: object required: - loc - msg - type title: ValidationError securitySchemes: APIKeyHeader: type: apiKey description: Bearer token in: header name: x-litellm-api-key