Find the IDs you need
LLM integrations hang off an account, an organization, or a space. Start fromviewer for the space ID and account for the account and organization IDs. See using global node IDs for how these opaque IDs work.
Understand the three resource types
LlmIntegration: backs the AI Providers UI, prompt playground, evals and agent runtimes. It carries its ownapiKey,baseUrlandmodelNames, is scoped viascopings, and is listed onAccount.llmIntegrationsandSpace.llmIntegrations.ExternalLlmApiKeyandCustomLlmEndpoint: narrower records scoped byaccountOrganizationIddirectly (no further scoping, unlikeLlmIntegration’sscopings), listed onAccountOrganization.externalLlmApiKeysand.customLlmEndpoints. Nothing links either back to anLlmIntegration; creating one does not create a usable playground integration.GoogleCloudIntegration: an organization-scoped record that verifies access to a Google Cloud project. It has no query field, so the only way to see one again is the ID the mutation returned.
LlmIntegration directly with createLlmIntegration. Reach for ExternalLlmApiKey or CustomLlmEndpoint only if you specifically need that narrower record.
List configured LLM integrations
List the integrations available to the account and to a space. Space-level results include integrations scoped to that space, its organization, or the whole account.apiKey in a listing query; use hasApiKey to check whether a key is set without round-tripping the secret.
Add a provider API key and connect it as an LLM integration
AnExternalLlmApiKey only stores a raw credential at the organization level. To actually use the provider in the playground, evals or agents, create an LlmIntegration as a separate step, passing the key straight to it.
input reuses the same key: { "accountId": "QWNjb3VudDo5", "provider": "anthropic", "name": "Team Anthropic key", "apiKey": "sk-ant-REPLACE_ME", "enableDefaultModels": true, "scopings": [{ "spaceId": "U3BhY2U6MTIz" }] }. Omit scopings for an account-wide integration. For AWS or GCP, add providerMetadata (AWS: roleArn, externalId; GCP: projectId, location, projectAccessLabel).
Reference: createExternalLlmApiKey, createLlmIntegration.
Register a custom OpenAI-compatible endpoint
Point Arize at a self-hosted or third-party OpenAI-compatible model server withcreateCustomLlmEndpoint, or use createLlmIntegration with provider: "custom" and a baseUrl if you want it usable directly in the playground.
/v1) but without an endpoint path like /chat/completions; Arize appends that automatically. Add headers (a list of { key, value } pairs) for anything else your proxy requires.
Reference: createCustomLlmEndpoint.
Set up a Google Cloud (Vertex) integration
Verify access to a Google Cloud project before using Vertex AI models. Set anarize-integration-key label on the GCP project first, then register that same value as projectAccessLabel.
createGoogleCloudIntegration.
Rotate or remove a key
Update the stored key on anLlmIntegration without recreating it, or delete the integration outright once it is no longer in use.
null or an empty string for apiKey on updateLlmIntegration removes the stored key instead of rotating it. updateExternalLlmApiKey, deleteExternalLlmApiKey, deleteCustomLlmEndpoint and deleteGoogleCloudIntegration follow the same shape for the narrower resource types.
Reference: updateLlmIntegration, deleteLlmIntegration.
Gotchas and behavior notes
The input provider enum and the output provider enum do not match
The input provider enum and the output provider enum do not match
createLlmIntegration and updateLlmIntegration take provider: LlmProvider (lowercase values like openai, azureopenai, aws, googleCloud). Reading an integration back returns provider: LLMIntegrationProvider, a differently-cased and differently-spelled enum (openAI, azureOpenAI, awsBedrock, vertexAI). Do not echo a value you read straight back into a mutation.oauthConfig is required when enabling OAuth, and omitting it keeps the existing config
oauthConfig is required when enabling OAuth, and omitting it keeps the existing config
On
updateLlmIntegration, switching authType to oauth2_client_credentials requires oauthConfig with tokenUrl, clientId and clientSecret; switching away from it deletes the stored config. Omitting oauthConfig while authType is unchanged keeps whatever is already stored.compatibleFormat uses a narrower provider enum
compatibleFormat uses a narrower provider enum
createCustomLlmEndpoint and createLlmIntegration both type compatibleFormat as ExternalLlmApiKeyProvider, which has only 8 values and does not include custom, googleCloud, aws, cursor or typeSafeAi. It defaults to openai.LLM integration mutations
Full argument and return-type reference for all twelve mutations.
All mutations
Index of every GraphQL mutation grouped by domain.
API explorer
Run queries and mutations interactively against your own account.