> ## Documentation Index
> Fetch the complete documentation index at: https://ara-90a60a07.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Check a saved provider account

> Requires org:write and workspace owner/admin membership. Accepts ordinary API keys as well as user OAuth grants. Checks the exact saved account using provider metadata only, without paid inference calls. Reports saved connection presence, authentication evidence, and capacity separately. Accepted metadata authentication or available capacity does not establish model access or inference success. Missing accounts return connected=false; unavailable storage returns connected=null. Does not persist a health verdict.

<sub>Scope: `org:write`</sub>



## OpenAPI

````yaml /openapi.json post /v3/organizations/{orgId}/provider-credentials/{providerId}/accounts/{accountKey}/check
openapi: 3.1.0
info:
  title: Reason Machines API
  version: 3.0.0
  description: >-
    The Reason HTTP API. Drive cloud software-engineering agents: open sessions
    against your repositories, stream their work, and manage the secrets,
    knowledge, skills, and automations they run with.


    Authenticate with a Reason API key sent as a bearer token. New keys use
    `reason_`; legacy `ara_` keys remain accepted. Every resource is scoped to
    an organization; resolve your `org_id` once with `GET /v3/self`.
servers:
  - url: https://api.reasonmachines.ai
security:
  - araApiKey: []
tags:
  - name: Devices
    description: >-
      Owned Mac and headless Device identity, bounded enrollment and root
      grants.
  - name: Account
    description: Verify a key and resolve the organization it belongs to.
  - name: Projects
    description: >-
      Discover existing workspace projects to target when creating and listing
      sessions.
  - name: Sessions
    description: >-
      A session is one run of an agent against a repository: it reproduces the
      task, writes the code, verifies it, and opens a pull request or merge
      request.
  - name: Secrets
    description: >-
      Encrypted credentials injected into the agent's sandbox. Write-only:
      values can be set but never read back.
  - name: Knowledge
    description: Durable notes the agent consults while it works.
  - name: Memory
    description: >-
      Editable repository notes that are projected into native memory; generated
      memory remains read-only.
  - name: Skills
    description: >-
      Reusable instruction bundles Reason selects semantically from their
      descriptions for matching agent tasks.
  - name: Automations
    description: Recurring or one-time triggers that open sessions on a timetable.
  - name: Change Request Reviews
    description: >-
      Automated senior-engineer reviews posted on pull requests and merge
      requests.
  - name: Repositories
    description: Connected repositories, their indexing state, and generated wikis.
  - name: Git Connections
    description: Linked source-control accounts and the repositories they expose.
  - name: Consumption
    description: 'Billing-aligned usage: daily consumption and billing cycles.'
  - name: Metrics
    description: Aggregate analytics over sessions, change requests, and usage.
  - name: Audit Logs
    description: An append-only record of changes made within the organization.
  - name: Organizations
    description: The top-level tenant. Create, read, update, and delete organizations.
  - name: Members
    description: People in an organization and their pending invites.
  - name: Service Users
    description: Machine principals that own API keys for headless access.
  - name: Roles
    description: Role assignments that govern what each member can do.
  - name: Attachments
    description: >-
      Files uploaded to the organization and shared with sessions, downloaded
      via short-lived signed URLs.
  - name: Guardrails
    description: >-
      Per-repository automation limits and the violations recorded when a limit
      is hit.
  - name: MCP Servers
    description: >-
      Org-level Model Context Protocol servers exposed to the agent. Secret
      values are write-only.
  - name: Settings
    description: 'Organization configuration: namespaced settings and the run tag policy.'
  - name: Blueprints
    description: >-
      Read-only declarative manifests of an organization's agents (identity, run
      config, triggers, suite), with credentials redacted.
  - name: IP Access List
    description: >-
      Source-network allow-list that, when enabled, restricts the organization's
      API surface to a set of CIDR ranges.
  - name: Groups
    description: Manually-curated member groups carrying optional per-day resource limits.
  - name: Provider Credentials
    description: >-
      Configure Bring-Your-Own-Key (BYOK) API keys and subscription credentials
      for model providers. Secret values are write-only.
paths:
  /v3/organizations/{orgId}/provider-credentials/{providerId}/accounts/{accountKey}/check:
    parameters:
      - $ref: '#/components/parameters/orgId'
      - name: providerId
        description: The provider identifier (e.g. openai, anthropic, google, deepseek).
        in: path
        required: true
        schema:
          type: string
      - name: accountKey
        description: >-
          The exact saved provider account slot identifier. URL-encode this path
          segment.
        in: path
        required: true
        schema:
          type: string
          minLength: 1
          maxLength: 512
    post:
      tags:
        - Provider credentials
      summary: Check a saved provider account
      description: >-
        Requires org:write and workspace owner/admin membership. Accepts
        ordinary API keys as well as user OAuth grants. Checks the exact saved
        account using provider metadata only, without paid inference calls.
        Reports saved connection presence, authentication evidence, and capacity
        separately. Accepted metadata authentication or available capacity does
        not establish model access or inference success. Missing accounts return
        connected=false; unavailable storage returns connected=null. Does not
        persist a health verdict.


        <sub>Scope: `org:write`</sub>
      operationId: checkProviderAccount
      responses:
        '200':
          description: Point-in-time metadata evidence; inference is not tested.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ProviderAccountCheck'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '503':
          description: Account check unavailable.
      security:
        - araApiKey:
            - org:write
components:
  parameters:
    orgId:
      name: orgId
      in: path
      required: true
      description: Organization id or slug. Resolve it with `GET /v3/self`.
      schema:
        type: string
  schemas:
    ProviderAccountCheck:
      type: object
      properties:
        connected:
          description: >-
            Saved credential presence, not validity. Null means storage could
            not be inspected.
          type:
            - boolean
            - 'null'
        authentication:
          type: object
          properties:
            status:
              type: string
              enum:
                - accepted
                - rejected
                - unverified
            scope:
              type: string
              enum:
                - saved_credential
                - provider_metadata
            reason:
              anyOf:
                - type: string
                  enum:
                    - not_connected
                    - credential_unreadable
                    - storage_unavailable
                    - unsupported_provider
                    - unsupported_credential_type
                    - auth_resolution_failed
                    - auth_unavailable
                    - http_401
                    - http_403
                    - rate_limited
                    - provider_unavailable
                    - unexpected_http_status
                    - network_error
                    - invalid_metadata
                - type: string
                  const: metadata_accepted
          required:
            - status
            - scope
            - reason
        capacity:
          type: object
          properties:
            status:
              type: string
              enum:
                - available
                - blocked
                - unknown
            scope:
              type: string
              enum:
                - paid_key_budget
                - subscription_quota
                - unknown
            reason:
              anyOf:
                - type: string
                  enum:
                    - not_connected
                    - credential_unreadable
                    - storage_unavailable
                    - unsupported_provider
                    - unsupported_credential_type
                    - auth_resolution_failed
                    - auth_unavailable
                    - http_401
                    - http_403
                    - rate_limited
                    - provider_unavailable
                    - unexpected_http_status
                    - network_error
                    - invalid_metadata
                - type: string
                  enum:
                    - capacity_not_reported
                    - zero_key_budget
                    - unlimited_key_budget
                    - key_budget_remaining
                    - key_budget_exhausted
                    - quota_blocked
                    - quota_available
          required:
            - status
            - scope
            - reason
        inference:
          type: string
          const: not_tested
          description: >-
            No model execution occurred. Metadata checks do not establish
            inference access.
        observed_at:
          type: string
          format: date-time
      required:
        - connected
        - authentication
        - capacity
        - inference
        - observed_at
    Error:
      type: object
      properties:
        error:
          type: string
        message:
          type: string
        required_scope:
          type: string
          description: >-
            The capability required when the request was denied for a missing
            scope.
  responses:
    BadRequest:
      description: Invalid request.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error: prompt_required
    Unauthorized:
      description: Missing, invalid, or expired key.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error: unauthorized
    Forbidden:
      description: The key lacks the required scope or role.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error: missing_scope
            required_scope: sessions:read
  securitySchemes:
    araApiKey:
      type: http
      scheme: bearer
      bearerFormat: 'reason_<hex> (legacy: ara_<hex>)'
      description: >-
        Your Reason API key from Settings > API. New keys use `reason_`; legacy
        `ara_` keys remain accepted. Keys are capability-scoped: run, mcp:read,
        mcp:write, secrets:read, secrets:write, sessions:read, sessions:debug,
        knowledge:read, memory:read, memory:write, skills:read, skills:write,
        repos:read, repos:write, reviews:read, reviews:write, deployment:read,
        analytics:read, org:read, org:write, attachments:read,
        attachments:write, guardrails:read, guardrails:write, automations:read,
        automations:write, agent_auth:read. mcp:write manages MCP server
        configuration only; it does not authorize remote MCP-tool execution.
        sessions:debug is privileged: it expands diagnostic session events only
        for organization owners/admins.

````