# ai.keys.save

Save or replace this organization's key for one AI provider, at the current revision (0 for the first key). Oatmilk checks the key with the provider first and saves it encrypted. Administrators only, from the dashboard.

`POST /api/v1/accounting/ai.keys.save`

Permissions: `accounting:read`, `accounting:write`, `accounting:admin` · Roles: admin · Idempotency key required · Send `expectedRevision`

Not available over MCP: An AI provider key would pass through the agent.

## Fields

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `provider` | enum | Yes | One of: `typesafe-ai`, `gateway`, `openai`, `google`, `zai`. |
| `apiKey` | string | Yes | 8–500 characters; Matches ^\S+$. |
| `expectedRevision` | integer | Yes | The record's current revision, from the last time you read it. If someone changed the record since, the request is refused with a conflict so you can reload and check before trying again. 0 to 9007199254740991. |
| `idempotencyKey` | string | Yes | Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match. 8–200 characters. |

## Example request

```bash
curl https://app.getoatmilk.com/api/v1/accounting/ai.keys.save \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "provider": "typesafe-ai",
  "apiKey": "api_key",
  "expectedRevision": 3
}'
```

Reference page: https://app.getoatmilk.com/docs/api/ai.keys.save
