Create a vault
With scope: "installation" the installation's own vault, owned by installation, which any session may attach; or a vault of one person (ownerUserId), which only that person's sessions attach.
managementKeyAuthorizationBearer <token>A management key of the Tenant (role management): it reaches the Management API (/v1/tenant/*) and /v1/me, as itself, never for a subject. Issued only on the Tenant's machine (nylorun-operate keys put <id> --role management) or from NYLORUN_MANAGEMENT_KEY_FILE. Never accepted from a browser (Origin).
Nylorun-Protocol*stringThe protocol version, 8
application/json- body
requestId*string1 <= lengthidempotencyKey*string1 <= length <= 256name*string1 <= lengthscope?string"user""installation"ownerUserId?string1 <= lengthmetadata?The vault
application/json- response
id*stringname*stringownerUserId*stringmetadata?createdAt*stringimport { createAdmin } from "@nylorun/admin";const admin = createAdmin();const vault = await admin.vaults.create({ scope: "installation", name: "tools", idempotencyKey: "tools",});{ "id": "string", "name": "string", "ownerUserId": "string", "metadata": { "property1": "string", "property2": "string" }, "createdAt": "string"}Set the Tenant's model budgets PUT
Replaces every budget. Before each model call the gate checks the scope's spend against its cap; once a cap is reached the call fails with `budget_exhausted` and the turn with `model.budget_exhausted`. An empty list removes every cap.
List vaults GET
The installation vaults, after the vaults of `ownerUserId` when it names a person.