Skip to main content
Provider credentials belong to your organization, not to an individual router. Save each API key, AWS credential, or Azure resource key once on the Credentials page, then select it anywhere that provider is used. Each built-in router provider uses one of two sources:
  • Managed uses Dari’s provider account when the provider supports it.
  • Saved Credential uses an organization credential you created for that provider.
OpenRouter, Amazon Bedrock, and Microsoft Azure are BYOK-only. Custom models also select a saved credential for their provider.

Save An API Key

In the dashboard, open Credentials, find the provider section, and choose Add. The value is write-only after save. You can also use the CLI without putting the secret in shell history:
The response includes a stable credential ID such as cred_.... Select it in a router manifest:
Or pass it directly:

Amazon Bedrock

Amazon Bedrock supports three saved authentication types:
  • AWS Role (recommended) is an IAM role in your account that Dari assumes with its own AWS identity before signing each request. No long-lived key leaves your account.
  • API Key uses a Bedrock API key, equivalent to AWS_BEARER_TOKEN_BEDROCK. Its IAM identity needs bedrock:CallWithBearerToken permission.
  • AWS IAM signs each Bedrock request with AWS Signature Version 4 using a saved access key ID, secret access key, optional session token, and AWS Region.

AWS Role

Open Credentials, choose Add Credential, select Amazon Bedrock, and choose AWS Role. The dialog shows the trust policy your role needs: it trusts Dari’s AWS principal and requires the External ID shown there, which is your Dari organization ID. Create the role with that trust policy, allow it to invoke every selected model or inference profile, then save the role ARN and AWS Region. The same values are available from the API. GET /v1/organizations/current/credentials returns aws_assume_role with principal_arn and external_id, or null when the deployment cannot assume roles.
Dari calls sts:AssumeRole with the External ID before each request, caches the temporary credentials, and re-assumes the role a few minutes before they expire. Updating the credential with a new role ARN or Region takes effect on the next request.

AWS IAM

Create an AWS IAM credential from environment variables:
Omit --aws-session-token-env for long-lived credentials. The IAM identity must be allowed to invoke every selected model or inference profile. Instance profiles and ambient credential discovery are not supported; use an AWS Role credential when you do not want to hand over static keys. Public API responses expose only non-secret metadata: the authentication type, AWS Region, and for AWS Role credentials the role ARN and External ID. Dari does not install saved values in process-wide environment variables or use ambient AWS profiles.

Microsoft Azure

A Microsoft Azure credential is the API key of one Microsoft Foundry or Azure OpenAI resource plus that resource’s endpoint. Dari calls OpenAI deployments through the Azure OpenAI v1 Responses API under /openai/v1 and Claude deployments through the Foundry Messages API under /anthropic, so one Foundry resource (https://<resource>.services.ai.azure.com) serves both model families. A classic Azure OpenAI resource (https://<resource>.openai.azure.com) serves OpenAI models only. Open Credentials, choose Add Credential, select Microsoft Azure, then enter the resource API key and the endpoint without a path. Or use the CLI:
Dari sends the model name as the deployment name, so keep Foundry’s default deployment names; deployments named differently are not reachable through the built-in Azure models. Key-based authentication must be enabled on the resource; Microsoft Entra ID authentication is not supported. Public API responses expose only the endpoint. Change the endpoint without re-entering the key:

Update Or Delete

Updating preserves the credential ID, so every router and custom model using it receives the new value without being reconfigured:
Delete an unused credential with dari credentials provider remove cred_.... Dari rejects deletion while a router or custom model still references it. When a model is bound to OpenRouter via model_providers, Dari forwards strict zero-data-retention routing controls. Your application still sends only its Dari Routing API key; Dari resolves the saved provider credential after selecting a model.