The OpenRouter Terraform Provider lets you manage OpenRouter as infrastructure-as-code: API keys, guardrails, workspaces, BYOK provider credentials, and observability destinations — with full lifecycle support, drift detection, and import.
To learn more about the underlying platform, check out the OpenRouter Documentation. Reference docs for every resource and data source are on the Terraform Registry.
To install this provider, copy and paste this code into your Terraform configuration. Then, run terraform init.
terraform {
required_providers {
openrouter = {
source = "OpenRouterTeam/openrouter"
version = "0.2.128"
}
}
}
provider "openrouter" {
server_url = "..." # Optional
}Authenticate with a Management API key (sk-or-mgmt-...) — management keys administer resources but cannot spend inference credits.
provider "openrouter" {
api_key = var.openrouter_management_key
}
resource "openrouter_workspace" "production" {
name = "Production"
slug = "production"
}
resource "openrouter_api_key" "backend" {
name = "backend-service"
limit = 100 # monthly credit limit in USD
limit_reset = "monthly"
workspace_id = openrouter_workspace.production.id
}
resource "openrouter_guardrail" "cost_cap" {
name = "cost-cap"
limit_usd = 50
reset_interval = "monthly"
enforce_zdr = true
}This provider supports authentication configuration via environment variables and provider configuration.
The configuration precedence is:
- Provider configuration
- Environment variables
Available configuration:
| Provider Attribute | Description |
|---|---|
api_key |
API key as bearer token in Authorization header. Configurable via environment variable OPENROUTER_MANAGEMENT_KEY. |
- openrouter_api_key
- openrouter_byok_key
- openrouter_guardrail
- openrouter_observability_destination
- openrouter_scim_group_mapping
- openrouter_workspace
- openrouter_workspace_budget
- openrouter_api_key
- openrouter_api_keys
- openrouter_byok_key
- openrouter_byok_keys
- openrouter_credits
- openrouter_guardrail
- openrouter_guardrail_key_assignments
- openrouter_guardrail_member_assignments
- openrouter_guardrails
- openrouter_model
- openrouter_models
- openrouter_observability_destination
- openrouter_observability_destinations
- openrouter_organization_members
- openrouter_preset
- openrouter_presets
- openrouter_providers
- openrouter_scim_group_mapping
- openrouter_workspace
- openrouter_workspace_budget
- openrouter_workspace_budgets
- openrouter_workspace_members
- openrouter_workspaces
Should you want to validate a change locally, the --debug flag allows you to execute the provider against a terraform instance locally.
This also allows for debuggers (e.g. delve) to be attached to the provider.
go run main.go --debug
# Copy the TF_REATTACH_PROVIDERS env var
# In a new terminal
cd examples/your-example
TF_REATTACH_PROVIDERS=... terraform init
TF_REATTACH_PROVIDERS=... terraform applyTerraform allows you to use local provider builds by setting a dev_overrides block in a configuration file called .terraformrc. This block overrides all other configured installation methods.
- Execute
go buildto construct a binary calledterraform-provider-openrouter - Ensure that the
.terraformrcfile is configured with adev_overridessection such that your local copy of terraform can see the provider binary
Terraform searches for the .terraformrc file in your home directory and applies any configuration settings you set.
provider_installation {
dev_overrides {
"registry.terraform.io/OpenRouterTeam/openrouter" = "<PATH>"
}
# For all other providers, install them directly from their origin provider
# registries as normal. If you omit this, Terraform will _only_ use
# the dev_overrides block, and so no other providers will be available.
direct {}
}
While we value open-source contributions to this terraform provider, this library is generated programmatically. Any manual changes added to internal files will be overwritten on the next generation. We look forward to hearing your feedback. Feel free to open a PR or an issue with a proof of concept and we'll do our best to include it in a future release.
