> ## Documentation Index
> Fetch the complete documentation index at: https://openrouter.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# UpdateBYOKKeyRequest

## Example Usage

```typescript theme={null}
import { UpdateBYOKKeyRequest } from "@openrouter/sdk/models";

let value: UpdateBYOKKeyRequest = {};
```

## Fields

| Field                 | Type        | Required             | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | Example                                                                           |
| --------------------- | ----------- | -------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | --------------------------------------------------------------------------------- |
| `allowedApiKeyHashes` | *string*\[] | :heavy\_minus\_sign: | Optional allowlist of OpenRouter API key hashes (`api_keys.hash`) that may use this credential. `null` clears the restriction. Must contain at least one hash if provided. Hashes that do not belong to your account return a 400.                                                                                                                                                                                                                                                                                 | \[<br />"f01d52606dc8f0a8303a7b5cc3fa07109c2e346cec7c0a16b40de462992ce943"<br />] |
| `allowedModels`       | *string*\[] | :heavy\_minus\_sign: | Optional allowlist of model slugs this credential may be used for. `null` means no restriction.                                                                                                                                                                                                                                                                                                                                                                                                                    | null                                                                              |
| `allowedUserIds`      | *string*\[] | :heavy\_minus\_sign: | Optional allowlist of user IDs that may use this credential. `null` means no restriction.                                                                                                                                                                                                                                                                                                                                                                                                                          | null                                                                              |
| `declaredZdr`         | *boolean*   | :heavy\_minus\_sign: | Your declaration of whether the upstream provider account behind this credential has zero data retention (ZDR). `null` inherits OpenRouter's data policy for the provider's endpoint; `true` declares the account ZDR so requests that require ZDR may route to this credential even when the shared endpoint retains data; `false` declares it non-ZDR so such requests never route to it. Self-declared and not verified by OpenRouter. Omit to leave the stored value unchanged; `null` clears the declaration. | null                                                                              |
| `disabled`            | *boolean*   | :heavy\_minus\_sign: | Whether this credential is disabled.                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | false                                                                             |
| `isByokOnly`          | *boolean*   | :heavy\_minus\_sign: | Whether OpenRouter's shared endpoints on this provider are removed for every model, including models outside `allowed_models` and after all of your keys for the provider fail. The provider is skipped instead of spending OpenRouter credits. Only valid on non-fallback credentials. Omit to leave the stored value unchanged.                                                                                                                                                                                  | false                                                                             |
| `isFallback`          | *boolean*   | :heavy\_minus\_sign: | Whether this credential is treated as a fallback — used only after non-fallback keys for the same provider have been tried. Cannot be combined with `is_byok_only`. Omit to leave the stored value unchanged.                                                                                                                                                                                                                                                                                                      | false                                                                             |
| `isRequired`          | *boolean*   | :heavy\_minus\_sign: | Whether OpenRouter's shared endpoints on this provider are removed for the models this credential applies to (its `allowed_models`, or every model when `null`). Requests for those models run only on your keys; models outside the allowlist may still fall back to shared capacity on this provider. Omit to leave the stored value unchanged.                                                                                                                                                                  | false                                                                             |
| `key`                 | *string*    | :heavy\_minus\_sign: | A new raw provider API key to rotate the credential in-place. The previous key material is overwritten and the masked label is regenerated. Encrypted at rest and never returned in API responses.                                                                                                                                                                                                                                                                                                                 | sk-proj-newkey456...                                                              |
| `name`                | *string*    | :heavy\_minus\_sign: | Optional human-readable name for the credential.                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | Updated OpenAI Key                                                                |
