> ## Documentation Index
> Fetch the complete documentation index at: https://onecli.sh/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Set or update a spend budget

> Caps how much an organization can spend on one of your LLM keys. When the organization's spend reaches the limit, the gateway stops using that key for the organization until the budget is raised or reset. Creates the budget, or replaces the existing one.

Only partner owners and admins can set budgets, and budgets are supported on metered LLM keys (Anthropic today).




## OpenAPI

````yaml /openapi.yaml post /partner/orgs/{orgId}/secrets/{secretId}/budget
openapi: 3.1.0
info:
  title: OneCLI API
  version: '1.0'
  description: >
    The OneCLI API lets you manage agents, secrets, policy rules, app
    connections, and user settings programmatically.


    **Base URL:** `https://api.onecli.sh/v1` (Cloud) or
    `http://localhost:10254/v1` (self-hosted)


    ## Authentication


    All endpoints require authentication via one of:


    - **API Key** — `Authorization: Bearer <key>` header. Generate keys in the
    dashboard or via `GET /v1/user/api-key`.

    - **Session** — Cookie-based session from the web dashboard.


    For organization-scoped API keys, include the `X-Project-Id` header to
    specify which project to operate on.
servers:
  - url: https://api.onecli.sh/v1
    description: OneCLI Cloud
  - url: http://localhost:10254/v1
    description: Self-hosted (Docker)
security:
  - bearerAuth: []
tags:
  - name: Agents
    description: Manage agents and their access tokens, secrets, and configuration.
  - name: Secrets
    description: Manage credentials that the gateway injects into outbound requests.
  - name: Policy
    description: >-
      Author project policy-engine rules that control how agents interact with
      external services (staged draft → publish).
  - name: Approvals
    description: >-
      Long-poll for pending manual-approval requests and submit approve/deny
      decisions.
  - name: User
    description: Manage your user profile and API keys.
  - name: Projects
    description: >-
      Manage projects within your organization. Requires admin role for
      create/update and owner role for delete. Cloud only.
  - name: Team
    description: Provision team members programmatically. Requires admin role. Cloud only.
  - name: Apps
    description: >-
      Manage app connections (OAuth and direct credentials), BYOC configuration,
      permission catalogs, and blocklists.
  - name: Connections
    description: App connections as a top-level resource.
  - name: Utility
    description: Health check and project resource summaries.
  - name: Agent Setup
    description: >-
      Endpoints agents and orchestrators use to bootstrap gateway access
      (container config, credential stubs, gateway skill).
  - name: Migration
    description: Migrate data from a self-hosted instance to OneCLI Cloud.
  - name: Organization Settings
    description: >-
      Organization-wide policy settings. Available on OneCLI Cloud and
      self-hosted Enterprise.
  - name: Organization Secrets
    description: >-
      Manage secrets at the organization level. Organization secrets apply
      across all projects. Available on OneCLI Cloud and self-hosted Enterprise.
  - name: Organization Policy
    description: >-
      Author policy-engine rules at the organization level. Organization rules
      apply across all projects. Available on OneCLI Cloud and self-hosted
      Enterprise.
  - name: Organization Connections
    description: >-
      Manage app connections at the organization level. Available on OneCLI
      Cloud and self-hosted Enterprise.
  - name: Organization App Config
    description: >-
      Connect apps (OAuth and direct credentials) and manage BYOC app
      configuration at the organization level. Available on OneCLI Cloud and
      self-hosted Enterprise.
  - name: Organization Approvals
    description: >-
      Long-poll for manual-approval requests across every project in the
      organization. Available on OneCLI Cloud and self-hosted Enterprise.
  - name: Partner Organizations
    description: >-
      Create and manage customer organizations as a partner. Requires a Partner
      API key. Cloud only.
  - name: Partner Projects
    description: Manage projects within an unclaimed partner organization. Cloud only.
  - name: Partner Secrets
    description: >-
      Manage partner-level secrets inherited by every organization you manage.
      Cloud only.
  - name: Partner Budgets
    description: >-
      Cap how much an organization can spend on a partner LLM key. Owner or
      admin only. Cloud only.
  - name: Partner Members
    description: >-
      Manage who can sign in to your partner portal. Owner or admin only. Cloud
      only.
  - name: Organization Partner
    description: Inspect and detach an organization's partner relationship. Cloud only.
paths:
  /partner/orgs/{orgId}/secrets/{secretId}/budget:
    post:
      tags:
        - Partner Budgets
      summary: Set or update a spend budget
      description: >
        Caps how much an organization can spend on one of your LLM keys. When
        the organization's spend reaches the limit, the gateway stops using that
        key for the organization until the budget is raised or reset. Creates
        the budget, or replaces the existing one.


        Only partner owners and admins can set budgets, and budgets are
        supported on metered LLM keys (Anthropic today).
      operationId: setPartnerOrgBudget
      parameters:
        - $ref: '#/components/parameters/orgId'
        - $ref: '#/components/parameters/secretId'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - limitCents
                - period
              properties:
                limitCents:
                  type: integer
                  minimum: 1
                  maximum: 100000000
                  description: Spend ceiling in US cents (e.g. `500` = $5.00).
                  example: 500
                period:
                  type: string
                  enum:
                    - monthly
                    - total
                  description: >-
                    `monthly` resets on the 1st of each month (UTC); `total` is
                    a one-time lifetime cap.
      responses:
        '200':
          description: Budget saved
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Budget'
        '400':
          description: Validation error, or the secret type isn't supported for budgets
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Caller is not a partner owner or admin
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: Organization or secret not found for this partner
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  parameters:
    orgId:
      name: orgId
      in: path
      required: true
      schema:
        type: string
    secretId:
      name: secretId
      in: path
      required: true
      schema:
        type: string
  schemas:
    Budget:
      type: object
      properties:
        secretId:
          type: string
          description: The partner LLM key this budget caps.
        organizationId:
          type: string
        limitCents:
          type: integer
          description: Spend ceiling in US cents (e.g. `500` = $5.00).
          example: 500
        period:
          type: string
          enum:
            - monthly
            - total
        spentCents:
          type: integer
          description: >-
            Spend so far this period, in US cents. Updates within a few seconds
            of usage.
          example: 320
    Error:
      description: |
        Error responses take one of two shapes depending on the failing layer:
        route-level validation returns the flat shape (`{ "error": "..." }`),
        while authentication failures (401/403) and service errors (not-found,
        conflict, and service-level validation) return the envelope
        (`{ "error": { "message": "...", "type": "..." } }`).
      oneOf:
        - $ref: '#/components/schemas/ErrorFlat'
        - $ref: '#/components/schemas/ErrorEnvelope'
    ErrorFlat:
      type: object
      description: Flat error shape used by route-level validation.
      properties:
        error:
          type: string
      required:
        - error
    ErrorEnvelope:
      type: object
      description: >-
        Envelope error shape used for authentication failures and service
        errors.
      properties:
        error:
          type: object
          properties:
            message:
              type: string
            type:
              type: string
              description: Error category (e.g. `authentication_error`).
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: API key obtained from the dashboard or `GET /user/api-key`

````