# OpenRouter routes and preferences

Source: https://immiscible.fly.dev/docs/api/get-api-w-wid-openrouter

`GET /api/w/:wid/openrouter`

Any member. Whether the workspace holds an OpenRouter key, its provider routing preferences, and every OpenRouter route in the catalogue with the vendor and model behind it (`underlying`), which is what allowlists are checked against. `onRequest` routes are used only when a client asks for them by name.

## Authentication

Session cookie. A signed-in person: the console's session cookie. Every state-changing request also carries the header `x-immiscible-csrf: 1`, and the member's role decides what it may do. Bearer tokens are ignored on these routes, so no machine credential can reach them.

## Path parameters

- `wid` (string, required): Workspace id

## Request

curl:

```bash
curl "https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/openrouter" \
  -H "cookie: __Host-sid=$IMMISCIBLE_SESSION"
```

Node:

```ts
const res = await fetch('https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/openrouter', {
  headers: {
    cookie: `__Host-sid=${process.env.IMMISCIBLE_SESSION}`,
  },
});
const data = await res.json();
console.log(res.status, data);
```

Python:

```python
import os
import requests

res = requests.get(
    "https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/openrouter",
    headers={
        "cookie": f"__Host-sid={os.environ['IMMISCIBLE_SESSION']}",
    },
)
print(res.status_code, res.json())
```

## Response

```json
{
  "configured": true,
  "prefs": { "dataCollection": "deny", "allowFallbacks": false, "title": "Acme agents" },
  "routes": [{ "id": "openrouter/claude-sonnet-4.5", "displayName": "Claude Sonnet 4.5 (via OpenRouter)", "openrouterModel": "anthropic/claude-sonnet-4.5", "underlying": "anthropic/claude-sonnet-4.5", "onRequest": true, "price": { "inputPerMTok": 3, "outputPerMTok": 15, "cachedInputPerMTok": 0.3 }, "availability": "available" }],
  "headers": { "HTTP-Referer": "https://immiscible.fly.dev", "X-Title": "Acme agents" }
}
```
