Skip to main content
GET
Error

Authorizations

Authorization
string
header
required

Management API authentication for /api/* endpoints. Use the Authorization header with Bearer <token>, where <token> is one of:

  • a Bifrost management API key,
  • a dashboard session token issued by POST /api/session/login,
  • base64 of <admin-username>:<admin-password> (legacy equivalent of BasicAuth).

Virtual keys (sk-bf-*) and the x-api-key header are not accepted on management APIs - the sole exception is GET /api/governance/virtual-keys/quota, which is virtual-key-only.

Authentication alone is not sufficient in Bifrost Enterprise: each operation page shows a Required Permissions table (Resource:Operation, for example Dashboard:View) above its Authorizations section, and the caller's RBAC role or management API key scopes must include what it lists, otherwise the request is rejected with 403 Forbidden.

A local admin — authenticated with the admin password, or any caller on a deployment with dashboard auth disabled — bypasses these checks and can call every management endpoint.

OSS setup lock. On Bifrost OSS, while dashboard auth is not active (no admin account, or auth disabled), every management endpoint except the public ones (/health, /api/version, /api/session/is-auth-enabled, /api/session/login, ...) requires the operator's setup token in the X-Bifrost-Setup-Token header, in place of Authorization. The token is set with setup_token in config.json or the BIFROST_SETUP_TOKEN environment variable. A missing header returns 401, a wrong token 403. The header stops working once dashboard auth is enabled. The dashboard instead trades the token once for an HttpOnly bifrost_setup_session cookie via POST /api/session/setup. See Required permissions for how permissions are derived and which endpoints are exempt.

Response

Warp configuration

Warp's deployment-wide settings, as returned by the read API.

The stored provider credential is never included. api_key_id names which of the provider's configured keys Warp uses - a reference, not a secret, so the settings form can render "configured" without the key itself ever leaving the server: a dashboard session is a weaker credential than the provider key it would otherwise reveal.

configured
boolean
required

Whether Warp has everything it needs to answer a question: enabled, with a provider and a model, and an embedding space - embedding provider, embedding model, a positive embedding dimension and a namespace - since semantic search over the logs is part of answering. A key is deliberately not part of this test, since a provider using ambient credentials legitimately needs none.

enabled
boolean
required

Whether the operator has switched Warp on.

provider
string
required

The provider of Warp's default model, e.g. openai. The default answers every chat request that names no model.

Example:

"openai"

model
string
required

Warp's default model.

Example:

"gpt-4o"

max_iterations
integer
default:8
required

How many times Warp may call tools and feed the results back before it must answer with what it has. Resolved value, so a row that never set one reports the default rather than zero.

Required range: 1 <= x <= 20
request_timeout_seconds
integer
default:120
required

Bound on a single upstream call. Resolved value.

history_retention_days
integer
default:30
required

How long a saved chat is kept after its last turn. Resolved value, so a row that never set one reports the default rather than zero.

Deliberately separate from logs_store.retention_days: how long request telemetry is worth storing and how long someone's conversations stay theirs to reopen are different questions, and one number cannot answer both without either discarding transcripts early or keeping logs late.

Required range: x >= 1
embedding_provider
string
required

Provider used to embed gateway conversations for semantic search.

Example:

"openai"

embedding_model
string
required

Embedding model used for both indexing and queries.

Example:

"text-embedding-3-small"

embedding_dimension
integer
required
Required range: x >= 0
Example:

1536

log_vector_store_namespace
string
default:BifrostWarpLogs
required
semantic_search_threshold
number
default:0.8
required
Required range: x <= 1
semantic_search_limit
integer
default:10
required
Required range: 1 <= x <= 25
vector_store_connected
boolean
required
read-only

Whether the shared runtime vector store is connected.

api_key_id
string

Which of the provider's configured keys the default model uses. A reference, not a credential, so it round-trips in the clear - there is nothing here worth redacting. Empty when the provider needs no key.

additional_models
object[]

The other models an operator has exposed. A chat request may name any of them, or the default, by provider and model; nothing else is accepted. Omitted when only the default is configured.

Maximum array length: 20
system_prompt_suffix
string

Appended to Warp's built-in system prompt. Additive only: an operator can teach Warp local naming conventions, but cannot remove the tool-use and scoping instructions the built-in prompt establishes.

embedding_api_key_id
string

Optional reference to one of the embedding provider's configured keys.