- Managed uses Dari’s provider account when the provider supports it.
- Saved Credential uses an organization credential you created for that provider.
Save An API Key
In the dashboard, open Credentials, find the provider section, and choose Add. The value is write-only after save. You can also use the CLI without putting the secret in shell history:cred_.... Select it in a router manifest:
Amazon Bedrock
Amazon Bedrock supports three saved authentication types:- AWS Role (recommended) is an IAM role in your account that Dari assumes with its own AWS identity before signing each request. No long-lived key leaves your account.
- API Key uses a Bedrock API key, equivalent to
AWS_BEARER_TOKEN_BEDROCK. Its IAM identity needsbedrock:CallWithBearerTokenpermission. - AWS IAM signs each Bedrock request with AWS Signature Version 4 using a saved access key ID, secret access key, optional session token, and AWS Region.
AWS Role
Open Credentials, choose Add Credential, select Amazon Bedrock, and choose AWS Role. The dialog shows the trust policy your role needs: it trusts Dari’s AWS principal and requires the External ID shown there, which is your Dari organization ID. Create the role with that trust policy, allow it to invoke every selected model or inference profile, then save the role ARN and AWS Region. The same values are available from the API.GET /v1/organizations/current/credentials returns aws_assume_role with principal_arn and external_id, or null when the deployment cannot assume roles.
sts:AssumeRole with the External ID before each request, caches the temporary credentials, and re-assumes the role a few minutes before they expire. Updating the credential with a new role ARN or Region takes effect on the next request.
AWS IAM
Create an AWS IAM credential from environment variables:--aws-session-token-env for long-lived credentials. The IAM identity must be allowed to invoke every selected model or inference profile. Instance profiles and ambient credential discovery are not supported; use an AWS Role credential when you do not want to hand over static keys.
Public API responses expose only non-secret metadata: the authentication type, AWS Region, and for AWS Role credentials the role ARN and External ID. Dari does not install saved values in process-wide environment variables or use ambient AWS profiles.
Microsoft Azure
A Microsoft Azure credential is the API key of one Microsoft Foundry or Azure OpenAI resource plus that resource’s endpoint. Dari calls OpenAI deployments through the Azure OpenAI v1 Responses API under/openai/v1 and Claude deployments through the Foundry Messages API under /anthropic, so one Foundry resource (https://<resource>.services.ai.azure.com) serves both model families. A classic Azure OpenAI resource (https://<resource>.openai.azure.com) serves OpenAI models only.
Open Credentials, choose Add Credential, select Microsoft Azure, then enter the resource API key and the endpoint without a path. Or use the CLI:
Update Or Delete
Updating preserves the credential ID, so every router and custom model using it receives the new value without being reconfigured:dari credentials provider remove cred_.... Dari rejects deletion while a router or custom model still references it.
When a model is bound to OpenRouter via model_providers, Dari forwards strict zero-data-retention routing controls. Your application still sends only its Dari Routing API key; Dari resolves the saved provider credential after selecting a model.