Skip to main content
POST
A browser cannot set an Authorization header on a WebSocket, and an API key shipped to a browser is an API key anyone can read. A client secret solves both: your server, which holds the API key, mints a secret that lasts minutes and is tied to one deployment, and the browser connects to realtime sessions with it. The request and response have the shape of OpenAI’s client_secrets API, so code written to mint an OpenAI ephemeral key needs only the gateway URL and your Bud credential.

Headers

Body

Response

The secret is opaque and encrypted. Do not parse it: it carries no project, user or deployment ID anyone holding it could read, and changing any character makes it invalid.

How long a secret lasts

A secret never outlives the credential that minted it: expires_at is the earlier of the time you asked for and the parent credential’s expiry. When it is shortened, the response says so through expires_at rather than failing.
  • Minted with a Keycloak access token. The token’s own expiry caps the secret. Keycloak access tokens usually last about 5 minutes, so a secret minted from one lasts at most that long. A token with fewer than 10 seconds left is refused with 401 credential_expiring.
  • Minted with an API key. The secret’s own expiry applies, and the secret stops working as soon as its API key is deleted or expires, whichever comes first.

Using a secret

Open the socket with the secret in the WebSocket subprotocol, and model naming the deployment the secret was minted for:
When the socket opens, the gateway checks that:
  1. the secret is intact and has not expired (otherwise 401);
  2. model names the deployment it was minted for (otherwise 403);
  3. the credential that minted it is still valid and can still use that deployment.
A secret can open any number of sessions until expires_at. A session that is already open keeps running after the secret expires, but not after its parent credential is revoked: it is closed with session_revoked within 30 seconds for an API key, or within 30 seconds plus the gateway’s authorization cache lifetime (5 minutes by default) for a Keycloak token. Usage from a session opened with a secret is attributed and billed to the project, user and API key that minted it.

Errors