Validate Llm Connection
Validate an LLM provider API key and model availability.
Two callable shapes:
- Inline - raw
apiKey+ optionalbaseUrlsupplied directly. Used when the user is pasting a fresh key in the form. - Saved connection -
savedConnectionIdreferences a storedllmConnection; BE loads the decryptedapiKey+baseUrl+providerserver-side so the browser never holds the plaintext.
Calls the provider’s free list-models endpoint to check key validity
and model existence. The “apiKey required unless ollama or saved” rule
is enforced by the request model’s @model_validator.
Per-tenant rate limit: 30 req/min/bucket -> 429 with Retry-After.
/agents/validate-llmAuthorizationBearer token · headerrequiredapplication/jsonproviderAgentLlmProviderEnumrequiredUnified LLM provider enum.
A single AgentLlmConnection row carries one provider and a set of
capabilities (chat / embedding). PROVIDER_CAPABILITIES below pins
which capabilities each provider can serve — picked by the FE Connections
drawer and re-validated server-side on every write.
anthropicopenaiopenai-responsesollamaazureazure-openaibedrockqwenopenai-compatiblemodelstringapiKeystringRaw key - never stored
baseUrlstring | nullShow propertiesHide properties
stringnullsavedConnectionIdstring | nullIf set, BE resolves provider/apiKey/baseUrl from the tenant's saved llmConnection by id and ignores the inline apiKey / baseUrl.
Show propertiesHide properties
stringnullSuccessful Response
objectValidation Error
detailValidationError[]Show propertiesHide properties
ValidationErrorlocstring | integer[]requiredShow propertiesHide properties
string | integerstringintegermsgstringrequiredtypestringrequiredinputanyctxobject