Base URL
http://localhost:8180.
Authentication
ManyLayers supports three authentication methods:- API Key (Bearer)
- Personal Access Token
gateway.yaml or via POST /admin/keys. Each key is scoped to a team and inherits its model allow-list and rate limits.Request conventions
- All request bodies are JSON (
Content-Type: application/json) unless otherwise noted (e.g.multipart/form-datafor file uploads). - All
/v1/*endpoints accept the same request format as the OpenAI API — no changes needed for existing OpenAI SDK code. See OpenAI Compatibility for the parameter-by-parameter and provider-by-provider matrix. - Requests are validated against the OpenAI schema before any provider is contacted, so a malformed request comes back naming the field rather than as a translated provider error.
- The
X-ManyLayers-Configheader selects a named routing config for the request. - The
X-Session-Idheader enables sticky sessions to a specific upstream. - The
X-Request-Idheader is returned on every response (auto-generated if not provided by you).
Error format
All errors follow the OpenAI error format:param is present whenever a specific request field is at fault; the OpenAI SDKs
surface it as error.param.
Provider errors are translated rather than relayed: an upstream’s status and body
are logged server-side and answered in the gateway’s own vocabulary, so behaviour
does not depend on which provider happened to serve a model. See the error
map.
HTTP status codes
| Status | Meaning |
|---|---|
| 400 | Bad request (validation error or firewall block) |
| 401 | Invalid or missing API key |
| 402 | Budget or quota exhausted |
| 403 | Insufficient permissions |
| 404 | Resource not found |
| 429 | Rate limit exceeded |
| 500 | Internal server error |
| 502 | Upstream provider error |
| 504 | Upstream timeout or cold-start timeout |
Endpoint groups
| Group | Prefix | Auth | Description |
|---|---|---|---|
| Gateway | /v1/* | API key or OIDC | OpenAI-compatible inference endpoints |
| Workspace | /w/* | Session cookie or PAT | Chat, knowledge bases, agents, workflows, evals |
| Admin | /admin/* | API key (admin role) | Team, key, config, and deployment management |
| Auth | /auth/* | Varies | Login, signup, SSO, invite flows |
| SCIM | /scim/v2/* | SCIM Bearer token | Automated user provisioning |
| Org | /org/* | Session (org_admin) | Org-level billing and SCIM management |
| Hooks | /hooks/* | HMAC signature | Inbound workflow webhook triggers |