Vendors and discovery
OpenRouter routes and preferences
GET
/api/w/:wid/openrouterAny member. Whether the workspace holds an OpenRouter key, its provider routing preferences, and every OpenRouter route in the catalogue with the vendor and model behind it (underlying), which is what allowlists are checked against. onRequest routes are used only when a client asks for them by name.
#Authentication
Session cookie
A signed-in person: the console's session cookie. Every state-changing request also carries the header x-immiscible-csrf: 1, and the member's role decides what it may do. Bearer tokens are ignored on these routes, so no machine credential can reach them.
#Path parameters
widstringrequired
Workspace id