Management API

Administer your org programmatically: API keys, projects, routing policies, and usage

The Management API administers your organization’s API keys, projects, routing policies, and usage from code, such as Pulumi, Terraform, or one-off scripts. The endpoint reference in this section has the full schemas.

Base URL and authentication

https://api-gateway.merge.dev

Authenticate with a management key from API keys → Management keys in the dashboard, shown once. It acts only on its own organization and can’t call model endpoints.

Authorization: Bearer mgmt_...

Reference

EndpointsScopeWhat it covers
/v1/keysmanage_keys (reads also accept read_usage)Create, list, update, and delete API keys, with an optional USD limit and a limit_reset of daily, weekly, or monthly. Walkthrough: Management API keys.
/v1/projectsmanage_projectsCreate and delete projects, and set their routing policy, budgets, controls, and prompt injection and DLP overrides. GET /v1/projects/{project_id}/models lists what the project can route to. Walkthrough: Projects API.
/v1/routing-policiesmanage_routing, or any active mg_ API keyCreate, update, and delete organization routing policies, and set the default
/v1/projects/{project_id}/usage, /v1/organization/usageread_usageProject and organization spend, grouped by project, API key, or vendor, with per-model monthly breakdowns

New management keys carry all four scopes. A call without the scope returns 403, and a key minted before the scope existed must be re-minted to gain it. Creating an API key needs a payment method on file, except on the Free plan. There’s no rotate endpoint: create the new key, then delete or disable the old one.

Errors use a detail object; see the codes worth branching on.

Next steps