Organization
Every Organization method in the Confident AI Python and TypeScript SDKs.
Overview
The Confident AI SDK exposes every Organization method on the platform. This page documents how to call these methods in all supported languages. See the introduction to install the SDK and set your API key.
Methods
Get Organization
Retrieves the organization your API key is scoped to. Every other admin endpoint operates inside this organization, so its id is the one to pass wherever an organization id is asked for, and its plan is what decides which of those endpoints you are entitled to call.
from confident_ai import ConfidentAI
client = ConfidentAI()
result = client.organization.get()For async mode, call a_get and await it as shown below:
result = await client.organization.a_get(...)import { ConfidentAI } from "confident-ai";
const client = new ConfidentAI();
const result = await client.organization.get();Returns
This method returns an object of type Organization.
Update Organization
Renames the organization and returns it as stored. The name is the only field this endpoint changes — the plan follows your subscription and cannot be set through the API.
from confident_ai import ConfidentAI
client = ConfidentAI()
result = client.organization.update(name="Acme")For async mode, call a_update and await it as shown below:
result = await client.organization.a_update(...)Parameters
| Parameter | Type | Description |
|---|---|---|
name | str | Required. The name of the organization, as it appears throughout the Confident AI platform. |
import { ConfidentAI } from "confident-ai";
const client = new ConfidentAI();
const result = await client.organization.update("Acme");Parameters
| Parameter | Type | Description |
|---|---|---|
name | string | Required. The name of the organization, as it appears throughout the Confident AI platform. |
Returns
This method returns an object of type Organization.
Update Model Credentials
Sets, replaces, or clears your organization's stored credential for a single model provider, which every project without credentials of its own then uses. TypeSafe credentials are project scoped and are rejected here. This is a write-only surface: there is no read endpoint, and the response returns every credential masked. A provider your organization's model provider policy does not allow cannot have a credential set (403), though clearing one is always permitted.
from confident_ai import ConfidentAI
from confident_ai.common import ModelProvider
client = ConfidentAI()
result = client.organization.update_model_credentials(
provider=ModelProvider.OPEN_AI,
api_key="sk-proj-a1B2c3D4e5F6g7H8i9J0kLmN",
model_config={
"azureApiBase": "https://acme.openai.azure.com",
"azureDeploymentName": "gpt-4o",
"azureApiVersion": "2024-06-01",
"azureApiKey": "b7f3c9d1e5a24f8090c6d4b2a1e8f37c"
},
)For async mode, call a_update_model_credentials and await it as shown below:
result = await client.organization.a_update_model_credentials(...)Parameters
| Parameter | Type | Description |
|---|---|---|
provider | ModelProvider | Required. See ModelProvider. |
api_key | Optional[str] | The provider's API key, for the API-key providers only. Send the raw secret to set it, or null to clear it; a masked value read back from a response is rejected. Sending it for a configuration provider is rejected. |
model_config | Optional[Dict[str, Any]] | The provider's configuration, for the configuration providers only — for example azureApiBase, azureDeploymentName, azureApiVersion and azureApiKey for AZURE. It replaces the stored configuration wholesale rather than merging into it, so send every key the provider needs; send null to clear it. It must not be empty and must not carry masked values read back from a response. Sending it for an API-key provider is rejected. For BEDROCK, always send regionName and modelId, then authenticate with either ACCESS_KEYS (awsAccessKeyId and awsSecretAccessKey) or, when calling the OpenAI-compatible Mantle API by setting api to MANTLE, an authType of API_KEY together with apiKey, an optional apiBase, and an optional projectId (sent as the OpenAI- Project header so AWS attributes usage and cost to that Mantle project; letters, numbers, hyphens and underscores only). An API key only works with the Mantle API, and assume-role Bedrock configurations can only be managed on the Confident AI platform. |
import { ConfidentAI } from "confident-ai";
import { ModelProvider } from "confident-ai/common";
const client = new ConfidentAI();
const result = await client.organization.updateModelCredentials(
ModelProvider.OPEN_AI,
{
apiKey: "sk-proj-a1B2c3D4e5F6g7H8i9J0kLmN",
modelConfig: {
azureApiBase: "https://acme.openai.azure.com",
azureDeploymentName: "gpt-4o",
azureApiVersion: "2024-06-01",
azureApiKey: "b7f3c9d1e5a24f8090c6d4b2a1e8f37c"
}
},
);Parameters
| Parameter | Type | Description |
|---|---|---|
provider | ModelProvider | Required. See ModelProvider. |
apiKey | string | null | The provider's API key, for the API-key providers only. Send the raw secret to set it, or null to clear it; a masked value read back from a response is rejected. Sending it for a configuration provider is rejected. |
modelConfig | Record<string, unknown> | null | The provider's configuration, for the configuration providers only — for example azureApiBase, azureDeploymentName, azureApiVersion and azureApiKey for AZURE. It replaces the stored configuration wholesale rather than merging into it, so send every key the provider needs; send null to clear it. It must not be empty and must not carry masked values read back from a response. Sending it for an API-key provider is rejected. For BEDROCK, always send regionName and modelId, then authenticate with either ACCESS_KEYS (awsAccessKeyId and awsSecretAccessKey) or, when calling the OpenAI-compatible Mantle API by setting api to MANTLE, an authType of API_KEY together with apiKey, an optional apiBase, and an optional projectId (sent as the OpenAI- Project header so AWS attributes usage and cost to that Mantle project; letters, numbers, hyphens and underscores only). An API key only works with the Mantle API, and assume-role Bedrock configurations can only be managed on the Confident AI platform. |
Returns
This method returns an object of type ModelCredentials.
List Permissions
Lists every organization permission an organization policy can grant. Each is named resource:action — billing:read, user:manage — and its id is what you send in a policy's permissionIds. This is Confident AI's whole organization catalog, not only the permissions you already use. Project permissions are a separate catalog with its own endpoint; an organization policy referencing a project permission id is stored but never matches.
from confident_ai import ConfidentAI
client = ConfidentAI()
result = client.organization.list_permissions()For async mode, call a_list_permissions and await it as shown below:
result = await client.organization.a_list_permissions(...)import { ConfidentAI } from "confident-ai";
const client = new ConfidentAI();
const result = await client.organization.listPermissions();Returns
This method returns an object of type PermissionList.
Types
ModelCredentials
One provider credential per field, for the whole organization or for a single project. Every secret comes back masked — fifteen asterisks followed by its last six characters, and the same treatment for the secret leaves inside a configuration object — so a stored credential can never be read back in full once it is set. A field is null when no credential is stored for that provider.
class ModelCredentials:
id: str
open_ai_api_key: Optional[str] = Field(alias="openAiApiKey")
anthropic_api_key: Optional[str] = Field(alias="anthropicApiKey")
gemini_api_key: Optional[str] = Field(alias="geminiApiKey")
x_ai_api_key: Optional[str] = Field(alias="xAiApiKey")
deep_seek_api_key: Optional[str] = Field(alias="deepSeekApiKey")
mistral_api_key: Optional[str] = Field(alias="mistralApiKey")
perplexity_api_key: Optional[str] = Field(alias="perplexityApiKey")
type_safe_api_key: Optional[str] = Field(alias="typeSafeApiKey")
fal_api_key: Optional[str] = Field(alias="falApiKey")
bedrock_model_config: Optional[Dict[str, Any]] = Field(alias="bedrockModelConfig")
vertex_ai_model_config: Optional[Dict[str, Any]] = Field(alias="vertexAiModelConfig")
azure_model_config: Optional[Dict[str, Any]] = Field(alias="azureModelConfig")
port_key_config: Optional[Dict[str, Any]] = Field(alias="portKeyConfig")
open_router_config: Optional[Dict[str, Any]] = Field(alias="openRouterConfig")
true_foundry_config: Optional[Dict[str, Any]] = Field(alias="trueFoundryConfig")
lite_llm_config: Optional[Dict[str, Any]] = Field(alias="liteLlmConfig")
hugging_face_config: Optional[Dict[str, Any]] = Field(alias="huggingFaceConfig")
organization_id: Optional[str] = Field(alias="organizationId")idstrRequired
The id of the credentials record, generated by Confident AI. A project that inherits the organization's credentials shares this id with it.
Example: "<MODEL-CREDENTIALS-ID>"
open_ai_api_keyOptional[str]Required
The stored OpenAI API key, masked, or null when none is stored.
Example: "***************Yz7Kq2"
anthropic_api_keyOptional[str]Required
The stored Anthropic API key, masked, or null when none is stored.
gemini_api_keyOptional[str]Required
The stored Gemini API key, masked, or null when none is stored.
x_ai_api_keyOptional[str]Required
The stored xAI API key, masked, or null when none is stored.
deep_seek_api_keyOptional[str]Required
The stored DeepSeek API key, masked, or null when none is stored.
mistral_api_keyOptional[str]Required
The stored Mistral API key, masked, or null when none is stored.
perplexity_api_keyOptional[str]Required
The stored Perplexity API key, masked, or null when none is stored.
type_safe_api_keyOptional[str]Required
The stored TypeSafe API key, masked, or null when none is stored.
fal_api_keyOptional[str]Required
The stored fal API key, masked, or null when none is stored. It powers the speech-to-speech simulated caller.
bedrock_model_configOptional[Dict[str, Any]]Required
The stored Amazon Bedrock configuration — access keys, an assumed IAM role, or a Mantle API key — with its secret fields masked, or null when none is stored.
vertex_ai_model_configOptional[Dict[str, Any]]Required
The stored Vertex AI configuration, with its secret fields masked, or null when none is stored.
azure_model_configOptional[Dict[str, Any]]Required
The stored Azure OpenAI configuration, with its secret fields masked, or null when none is stored.
Example: {"azureApiBase":"https://acme.openai.azure.com","azureDeploymentName":"gpt-4o","azureApiVersion":"2024-06-01","azureApiKey":"***************Yz7Kq2"}
port_key_configOptional[Dict[str, Any]]Required
The stored Portkey configuration, with its secret fields masked, or null when none is stored.
open_router_configOptional[Dict[str, Any]]Required
The stored OpenRouter configuration, with its secret fields masked, or null when none is stored.
true_foundry_configOptional[Dict[str, Any]]Required
The stored TrueFoundry configuration, with its secret fields masked, or null when none is stored.
lite_llm_configOptional[Dict[str, Any]]Required
The stored LiteLLM configuration, with its secret fields masked, or null when none is stored.
hugging_face_configOptional[Dict[str, Any]]Required
The stored Hugging Face configuration, with its secret fields masked, or null when none is stored.
organization_idOptional[str]Required
The id of the organization these credentials belong to, or null when they belong to a single project.
Example: "<ORGANIZATION-ID>"
interface ModelCredentials {
id: string;
openAiApiKey: string | null;
anthropicApiKey: string | null;
geminiApiKey: string | null;
xAiApiKey: string | null;
deepSeekApiKey: string | null;
mistralApiKey: string | null;
perplexityApiKey: string | null;
typeSafeApiKey: string | null;
falApiKey: string | null;
bedrockModelConfig: Record<string, unknown> | null;
vertexAiModelConfig: Record<string, unknown> | null;
azureModelConfig: Record<string, unknown> | null;
portKeyConfig: Record<string, unknown> | null;
openRouterConfig: Record<string, unknown> | null;
trueFoundryConfig: Record<string, unknown> | null;
liteLlmConfig: Record<string, unknown> | null;
huggingFaceConfig: Record<string, unknown> | null;
organizationId: string | null;
}idstringRequired
The id of the credentials record, generated by Confident AI. A project that inherits the organization's credentials shares this id with it.
Example: "<MODEL-CREDENTIALS-ID>"
openAiApiKeystring | nullRequired
The stored OpenAI API key, masked, or null when none is stored.
Example: "***************Yz7Kq2"
anthropicApiKeystring | nullRequired
The stored Anthropic API key, masked, or null when none is stored.
geminiApiKeystring | nullRequired
The stored Gemini API key, masked, or null when none is stored.
xAiApiKeystring | nullRequired
The stored xAI API key, masked, or null when none is stored.
deepSeekApiKeystring | nullRequired
The stored DeepSeek API key, masked, or null when none is stored.
mistralApiKeystring | nullRequired
The stored Mistral API key, masked, or null when none is stored.
perplexityApiKeystring | nullRequired
The stored Perplexity API key, masked, or null when none is stored.
typeSafeApiKeystring | nullRequired
The stored TypeSafe API key, masked, or null when none is stored.
falApiKeystring | nullRequired
The stored fal API key, masked, or null when none is stored. It powers the speech-to-speech simulated caller.
bedrockModelConfigRecord<string, unknown> | nullRequired
The stored Amazon Bedrock configuration — access keys, an assumed IAM role, or a Mantle API key — with its secret fields masked, or null when none is stored.
vertexAiModelConfigRecord<string, unknown> | nullRequired
The stored Vertex AI configuration, with its secret fields masked, or null when none is stored.
azureModelConfigRecord<string, unknown> | nullRequired
The stored Azure OpenAI configuration, with its secret fields masked, or null when none is stored.
Example: {"azureApiBase":"https://acme.openai.azure.com","azureDeploymentName":"gpt-4o","azureApiVersion":"2024-06-01","azureApiKey":"***************Yz7Kq2"}
portKeyConfigRecord<string, unknown> | nullRequired
The stored Portkey configuration, with its secret fields masked, or null when none is stored.
openRouterConfigRecord<string, unknown> | nullRequired
The stored OpenRouter configuration, with its secret fields masked, or null when none is stored.
trueFoundryConfigRecord<string, unknown> | nullRequired
The stored TrueFoundry configuration, with its secret fields masked, or null when none is stored.
liteLlmConfigRecord<string, unknown> | nullRequired
The stored LiteLLM configuration, with its secret fields masked, or null when none is stored.
huggingFaceConfigRecord<string, unknown> | nullRequired
The stored Hugging Face configuration, with its secret fields masked, or null when none is stored.
organizationIdstring | nullRequired
The id of the organization these credentials belong to, or null when they belong to a single project.
Example: "<ORGANIZATION-ID>"
ModelProvider
This is the provider of the model.
class ModelProvider(Enum):
OPEN_AI = "OPEN_AI"
CUSTOM = "CUSTOM"
CONFIDENT_AI = "CONFIDENT_AI"
BEDROCK = "BEDROCK"
ANTHROPIC = "ANTHROPIC"
GEMINI = "GEMINI"
X_AI = "X_AI"
DEEPSEEK = "DEEPSEEK"
MOONSHOT_AI = "MOONSHOT_AI"
VERTEX_AI = "VERTEX_AI"
AZURE = "AZURE"
MISTRAL = "MISTRAL"
PERPLEXITY = "PERPLEXITY"
OPEN_ROUTER = "OPEN_ROUTER"
PORTKEY = "PORTKEY"
LITE_LLM = "LITE_LLM"
TRUE_FOUNDRY = "TRUE_FOUNDRY"
HUGGING_FACE = "HUGGING_FACE"
TYPE_SAFE = "TYPE_SAFE"
FAL = "FAL"enum ModelProvider {
OPEN_AI = "OPEN_AI",
CUSTOM = "CUSTOM",
CONFIDENT_AI = "CONFIDENT_AI",
BEDROCK = "BEDROCK",
ANTHROPIC = "ANTHROPIC",
GEMINI = "GEMINI",
X_AI = "X_AI",
DEEPSEEK = "DEEPSEEK",
MOONSHOT_AI = "MOONSHOT_AI",
VERTEX_AI = "VERTEX_AI",
AZURE = "AZURE",
MISTRAL = "MISTRAL",
PERPLEXITY = "PERPLEXITY",
OPEN_ROUTER = "OPEN_ROUTER",
PORTKEY = "PORTKEY",
LITE_LLM = "LITE_LLM",
TRUE_FOUNDRY = "TRUE_FOUNDRY",
HUGGING_FACE = "HUGGING_FACE",
TYPE_SAFE = "TYPE_SAFE",
FAL = "FAL",
}OPEN_AI · CUSTOM · CONFIDENT_AI · BEDROCK · ANTHROPIC · GEMINI · X_AI · DEEPSEEK · MOONSHOT_AI · VERTEX_AI · AZURE · MISTRAL · PERPLEXITY · OPEN_ROUTER · PORTKEY · LITE_LLM · TRUE_FOUNDRY · HUGGING_FACE · TYPE_SAFE · FAL
Organization
The tenant every project, API key and member belongs to. An organization API key is scoped to exactly one of these, so this is the top of the hierarchy the admin endpoints operate on.
class Organization:
id: str
name: str
plan: OrganizationPlan
created_at: stridstrRequired
The id of the organization, generated by Confident AI.
Example: "<ORGANIZATION-ID>"
namestrRequired
The name of the organization.
Example: "Acme"
planOrganizationPlanRequired
See OrganizationPlan.
created_atstrRequired
When the organization was created.
Example: "2025-01-14T09:30:00+00:00"
interface Organization {
id: string;
name: string;
plan: OrganizationPlan;
created_at: string;
}idstringRequired
The id of the organization, generated by Confident AI.
Example: "<ORGANIZATION-ID>"
namestringRequired
The name of the organization.
Example: "Acme"
planOrganizationPlanRequired
See OrganizationPlan.
created_atstringRequired
When the organization was created.
Example: "2025-01-14T09:30:00+00:00"
OrganizationPlan
The billing plan the organization is on, which decides its entitlements and usage limits. Plans rank FREE and TRIAL, then STARTER, PREMIUM, TEAM and ENTERPRISE, each carrying every lower plan's entitlements plus more projects and seats: FREE allows a single project, STARTER up to five, and the paid plans above it bill extra project spaces as usage. Some features are reserved outright — red teaming through the API is ENTERPRISE only. TRIAL is a time-limited run at paid entitlements; once the trial period has elapsed the organization is entitled as FREE, but this field keeps reporting the stored plan, so it is not a substitute for a 403 when deciding whether a call will be allowed.
class OrganizationPlan(Enum):
TRIAL = "TRIAL"
FREE = "FREE"
STARTER = "STARTER"
ENTERPRISE = "ENTERPRISE"
TEAM = "TEAM"
PREMIUM = "PREMIUM"enum OrganizationPlan {
TRIAL = "TRIAL",
FREE = "FREE",
STARTER = "STARTER",
ENTERPRISE = "ENTERPRISE",
TEAM = "TEAM",
PREMIUM = "PREMIUM",
}TRIAL · FREE · STARTER · ENTERPRISE · TEAM · PREMIUM
Permission
One thing a policy can allow. Permissions are never granted to a member directly: a policy names a set of them, a role holds policies, and a member holds roles.
class Permission:
id: str
name: str
description: Optional[str]idstrRequired
The id of the permission, generated by Confident AI. This is what a policy references in its permissionIds.
Example: "<PERMISSION-ID>"
namestrRequired
The permission, written as resource:action — the resource it applies to, then what it allows on it. read grants viewing, manage grants creating and updating, and create, update and delete appear where a resource distinguishes them.
Example: "user:read"
descriptionOptional[str]Required
What the permission allows, in prose, or null when it has none. Confident AI creates these permissions from its own catalog and does not describe them, so this is null unless someone has filled it in.
interface Permission {
id: string;
name: string;
description: string | null;
}idstringRequired
The id of the permission, generated by Confident AI. This is what a policy references in its permissionIds.
Example: "<PERMISSION-ID>"
namestringRequired
The permission, written as resource:action — the resource it applies to, then what it allows on it. read grants viewing, manage grants creating and updating, and create, update and delete appear where a resource distinguishes them.
Example: "user:read"
descriptionstring | nullRequired
What the permission allows, in prose, or null when it has none. Confident AI creates these permissions from its own catalog and does not describe them, so this is null unless someone has filled it in.
PermissionList
The complete set of permissions a policy in this scope can grant, taken from Confident AI's own catalog rather than from what your organization happens to use already.
class PermissionList:
permissions: List[Permission]permissionsList[Permission]Required
Every permission in the catalog for this scope, in no particular order.
See Permission.
interface PermissionList {
permissions: Permission[];
}permissionsPermission[]Required
Every permission in the catalog for this scope, in no particular order.
See Permission.
Last updated on