> ## Documentation Index
> Fetch the complete documentation index at: https://docs.prisme.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Bulk-replace the entire model catalogue

> **Destructive.** Deletes the entire models collection and inserts the
provided list. Used by the platform Models page "Import" flow.

- Body must be `{ "models": [...] }` (max 500 items). Each item must
  carry at least `model_id` and `type`.
- Per-key cache (`global.models_cache`) is fully invalidated.
- Emits a `model.bulk_replaced` audit event.
- Rate-limited: 5 calls per 3600 seconds per consumer
  (`ModelsBulkReplace`).




## OpenAPI

````yaml /api-reference/llm-gateway/swagger.yml put /v1/models
openapi: 3.0.3
info:
  version: 1.0.0
  title: LLM Gateway API
  description: |
    Public REST API for the Prisme.ai LLM Gateway - OpenAI-compatible
    chat completions and embeddings, plus a managed model catalogue
    with governance overrides per organization.

    The gateway abstracts multi-provider LLM access (OpenAI, Azure OpenAI,
    Anthropic, Google Vertex, AWS Bedrock, OpenAI-compatible providers) behind
    an OpenAI-compatible request/response shape. It enforces per-tenant
    governance (allowed models, default models, quotas) and emits analytics
    events (`analytics.llm.completion`) usable for cost and carbon reporting.

    This spec documents only the public REST surface (endpoints exposed via
    Prisme.ai workspace webhooks). Internal helpers (private automations
    prefixed with `_`) and load-test mocks are not part of the public contract.
  contact:
    name: Prisme.ai
    url: https://prisme.ai
servers:
  - url: https://{host}/v2/workspaces/slug:llm-gateway/webhooks
    description: Prisme.ai workspace webhooks
    variables:
      host:
        default: api.studio.prisme.ai
        description: API host (override for self-hosted or sandbox)
security:
  - BearerAuth: []
  - OrgApiKeyAuth: []
tags:
  - name: Completions
    description: OpenAI-compatible chat completions (with optional SSE streaming).
  - name: Embeddings
    description: OpenAI-compatible text embeddings.
  - name: Models
    description: Model catalogue (CRUD + bulk replace + governance-aware listing).
  - name: Defaults
    description: >-
      Resolved default models for completions / embeddings / image generation /
      file parsing.
  - name: Test
    description: Smoke-test reachability of a model through the gateway.
paths:
  /v1/models:
    put:
      tags:
        - Models
      summary: Bulk-replace the entire model catalogue
      description: |
        **Destructive.** Deletes the entire models collection and inserts the
        provided list. Used by the platform Models page "Import" flow.

        - Body must be `{ "models": [...] }` (max 500 items). Each item must
          carry at least `model_id` and `type`.
        - Per-key cache (`global.models_cache`) is fully invalidated.
        - Emits a `model.bulk_replaced` audit event.
        - Rate-limited: 5 calls per 3600 seconds per consumer
          (`ModelsBulkReplace`).
      operationId: replaceModels
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - models
              properties:
                models:
                  type: array
                  description: Replacement catalogue (max 500 items).
                  maxItems: 500
                  items:
                    $ref: '#/components/schemas/ModelCreateInput'
      responses:
        '200':
          description: Bulk replace summary.
          content:
            application/json:
              schema:
                type: object
                required:
                  - deleted
                  - inserted
                properties:
                  deleted:
                    type: integer
                    description: Number of documents removed before the insert.
                  inserted:
                    type: integer
                    description: Number of documents inserted.
        '400':
          description: |
            Validation error. Codes: `INVALID_BODY` (missing or non-array
            `models`), `INVALID_ITEMS` (one or more items missing `model_id` or
            `type` - `details` lists the offending entries),
            `PAYLOAD_TOO_LARGE` (more than 500 items).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: Missing or invalid authentication.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '405':
          description: Method not allowed.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          description: >-
            Rate limit exceeded (`code: RATE_LIMITED`, 5 req / 3600 s per
            consumer).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    ModelCreateInput:
      type: object
      description: |
        Write-shape for `POST /v1/models` and each item of `PUT /v1/models`.
        `model_id` and `type` are required.
      required:
        - model_id
        - type
      properties:
        model_id:
          type: string
          maxLength: 128
        type:
          type: string
          maxLength: 64
          enum:
            - completion
            - embeddings
            - image_generation
        display:
          type: object
        capabilities:
          type: object
        limits:
          type: object
        failover:
          type: string
          maxLength: 128
        region:
          type: string
          maxLength: 64
        dimensions: {}
        supported_dimensions: {}
        metrics: {}
        provider_config: {}
        pricing: {}
        tags: {}
        org_slugs: {}
        enabled: {}
    Error:
      type: object
      required:
        - error
      description: |
        Standard error envelope. `error` carries either a stable PascalCase
        identifier or a free-text label (legacy endpoints) - `code` is the
        canonical machine-readable identifier going forward.
      properties:
        error:
          type: string
          description: Stable PascalCase identifier or short error label.
        message:
          type: string
          description: Human-readable error message.
        code:
          type: string
          description: |
            Machine-readable error code. Observed values include
            `RATE_LIMITED`, `MODEL_NOT_ALLOWED`, `MODEL_NOT_FOUND`,
            `MODEL_EXISTS`, `MISSING_MODEL_ID`, `MISSING_TYPE`, `INVALID_BODY`,
            `INVALID_ITEMS`, `INVALID_DIMENSIONS`, `PAYLOAD_TOO_LARGE`,
            `METHOD_NOT_ALLOWED`, `PROVIDER_ERROR`, `PROVIDER_NO_RESPONSE`.
        details:
          description: Optional structured context (e.g. list of invalid items).
          additionalProperties: true
        status:
          type: integer
          description: HTTP status mirror, when present.
        retryAfter:
          type: integer
          description: Seconds to wait before retrying (rate-limit responses).
        provider:
          type: string
          description: Upstream provider name (provider-error responses).
        model:
          type: string
          description: Model id involved in the error (provider-error responses).
        provider_error_type:
          type: string
          description: Upstream provider's own error class name.
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: |
        User-bound credential carrying an identity: either a session JWT
        or a user access token (`at:*`) generated from the user settings UI.
        Send as `Authorization: Bearer <token>`.
        Org API keys (`iak_*`) are **not** accepted here - they carry
        no user identity. Use the `x-prismeai-api-key` header instead
        (see `OrgApiKeyAuth`).
    OrgApiKeyAuth:
      type: apiKey
      in: header
      name: x-prismeai-api-key
      description: |
        Organization API key (`iak_{orgSlug}_{uuid}`). Unlike
        `Authorization: Bearer`, this credential is **not** tied to a user
        identity - it is bound to the org and its effective access is
        defined by the scopes / permission rules attached to it (it can
        be restricted to a single project, or kept broader).
        Send as `x-prismeai-api-key: iak_...`.

````