SpyBara
Go Premium

Reference 2026-08-07 21:59 UTC to 2026-08-08 00:59 UTC

5 files changed +252 −10. View all changes and history on the product overview
2026
Sat 8 00:59 Fri 7 21:59 Thu 6 18:59 Wed 5 02:01 Tue 4 22:59 Mon 3 21:58 Sat 1 01:00
Details

893 893 

894### Returns894### Returns

895 895 

896- `data: array of object { id, effective_at, type, 57 more }`896- `data: array of object { id, effective_at, type, 58 more }`

897 897 

898 - `id: string`898 - `id: string`

899 899 


2033 2033 

2034 The role of the service account. Is either `owner` or `member`.2034 The role of the service account. Is either `owner` or `member`.

2035 2035 

2036 - `source: optional "cloud_console" or "adminapi" or "retool" or 5 more`

2037 

2038 The server-derived administrative authorization context recorded for the action, when available. API-key paths identify the authenticated API surface; biscuit-authorized paths identify the permission namespace used for authorization. This does not necessarily identify the literal client software.

2039 

2040 - `"cloud_console"`

2041 

2042 - `"adminapi"`

2043 

2044 - `"retool"`

2045 

2046 - `"glass"`

2047 

2048 - `"managementapi"`

2049 

2050 - `"tenantapi"`

2051 

2052 - `"scim"`

2053 

2054 - `"backfill"`

2055 

2036 - `"user.added": optional object { id, data }`2056 - `"user.added": optional object { id, data }`

2037 2057 

2038 The details for events with this `type`.2058 The details for events with this `type`.


2487 "role": "role"2507 "role": "role"

2488 }2508 }

2489 },2509 },

2510 "source": "cloud_console",

2490 "user.added": {2511 "user.added": {

2491 "id": "id",2512 "id": "id",

2492 "data": {2513 "data": {


2615 2636 

2616### Audit Log List Response2637### Audit Log List Response

2617 2638 

2618- `AuditLogListResponse object { id, effective_at, type, 57 more }`2639- `AuditLogListResponse object { id, effective_at, type, 58 more }`

2619 2640 

2620 A log of a user action or configuration change within this organization.2641 A log of a user action or configuration change within this organization.

2621 2642 


3757 3778 

3758 The role of the service account. Is either `owner` or `member`.3779 The role of the service account. Is either `owner` or `member`.

3759 3780 

3781 - `source: optional "cloud_console" or "adminapi" or "retool" or 5 more`

3782 

3783 The server-derived administrative authorization context recorded for the action, when available. API-key paths identify the authenticated API surface; biscuit-authorized paths identify the permission namespace used for authorization. This does not necessarily identify the literal client software.

3784 

3785 - `"cloud_console"`

3786 

3787 - `"adminapi"`

3788 

3789 - `"retool"`

3790 

3791 - `"glass"`

3792 

3793 - `"managementapi"`

3794 

3795 - `"tenantapi"`

3796 

3797 - `"scim"`

3798 

3799 - `"backfill"`

3800 

3760 - `"user.added": optional object { id, data }`3801 - `"user.added": optional object { id, data }`

3761 3802 

3762 The details for events with this `type`.3803 The details for events with this `type`.

Details

891 891 

892### Returns892### Returns

893 893 

894- `data: array of object { id, effective_at, type, 57 more }`894- `data: array of object { id, effective_at, type, 58 more }`

895 895 

896 - `id: string`896 - `id: string`

897 897 


2031 2031 

2032 The role of the service account. Is either `owner` or `member`.2032 The role of the service account. Is either `owner` or `member`.

2033 2033 

2034 - `source: optional "cloud_console" or "adminapi" or "retool" or 5 more`

2035 

2036 The server-derived administrative authorization context recorded for the action, when available. API-key paths identify the authenticated API surface; biscuit-authorized paths identify the permission namespace used for authorization. This does not necessarily identify the literal client software.

2037 

2038 - `"cloud_console"`

2039 

2040 - `"adminapi"`

2041 

2042 - `"retool"`

2043 

2044 - `"glass"`

2045 

2046 - `"managementapi"`

2047 

2048 - `"tenantapi"`

2049 

2050 - `"scim"`

2051 

2052 - `"backfill"`

2053 

2034 - `"user.added": optional object { id, data }`2054 - `"user.added": optional object { id, data }`

2035 2055 

2036 The details for events with this `type`.2056 The details for events with this `type`.


2485 "role": "role"2505 "role": "role"

2486 }2506 }

2487 },2507 },

2508 "source": "cloud_console",

2488 "user.added": {2509 "user.added": {

2489 "id": "id",2510 "id": "id",

2490 "data": {2511 "data": {


2613 2634 

2614### Audit Log List Response2635### Audit Log List Response

2615 2636 

2616- `AuditLogListResponse object { id, effective_at, type, 57 more }`2637- `AuditLogListResponse object { id, effective_at, type, 58 more }`

2617 2638 

2618 A log of a user action or configuration change within this organization.2639 A log of a user action or configuration change within this organization.

2619 2640 


3755 3776 

3756 The role of the service account. Is either `owner` or `member`.3777 The role of the service account. Is either `owner` or `member`.

3757 3778 

3779 - `source: optional "cloud_console" or "adminapi" or "retool" or 5 more`

3780 

3781 The server-derived administrative authorization context recorded for the action, when available. API-key paths identify the authenticated API surface; biscuit-authorized paths identify the permission namespace used for authorization. This does not necessarily identify the literal client software.

3782 

3783 - `"cloud_console"`

3784 

3785 - `"adminapi"`

3786 

3787 - `"retool"`

3788 

3789 - `"glass"`

3790 

3791 - `"managementapi"`

3792 

3793 - `"tenantapi"`

3794 

3795 - `"scim"`

3796 

3797 - `"backfill"`

3798 

3758 - `"user.added": optional object { id, data }`3799 - `"user.added": optional object { id, data }`

3759 3800 

3760 The details for events with this `type`.3801 The details for events with this `type`.

Details

352 352 

353### Returns353### Returns

354 354 

355- `data: array of object { id, effective_at, type, 57 more }`355- `data: array of object { id, effective_at, type, 58 more }`

356 356 

357 - `id: string`357 - `id: string`

358 358 


1492 1492 

1493 The role of the service account. Is either `owner` or `member`.1493 The role of the service account. Is either `owner` or `member`.

1494 1494 

1495 - `source: optional "cloud_console" or "adminapi" or "retool" or 5 more`

1496 

1497 The server-derived administrative authorization context recorded for the action, when available. API-key paths identify the authenticated API surface; biscuit-authorized paths identify the permission namespace used for authorization. This does not necessarily identify the literal client software.

1498 

1499 - `"cloud_console"`

1500 

1501 - `"adminapi"`

1502 

1503 - `"retool"`

1504 

1505 - `"glass"`

1506 

1507 - `"managementapi"`

1508 

1509 - `"tenantapi"`

1510 

1511 - `"scim"`

1512 

1513 - `"backfill"`

1514 

1495 - `"user.added": optional object { id, data }`1515 - `"user.added": optional object { id, data }`

1496 1516 

1497 The details for events with this `type`.1517 The details for events with this `type`.


1946 "role": "role"1966 "role": "role"

1947 }1967 }

1948 },1968 },

1969 "source": "cloud_console",

1949 "user.added": {1970 "user.added": {

1950 "id": "id",1971 "id": "id",

1951 "data": {1972 "data": {


2074 2095 

2075### Audit Log List Response2096### Audit Log List Response

2076 2097 

2077- `AuditLogListResponse object { id, effective_at, type, 57 more }`2098- `AuditLogListResponse object { id, effective_at, type, 58 more }`

2078 2099 

2079 A log of a user action or configuration change within this organization.2100 A log of a user action or configuration change within this organization.

2080 2101 


3216 3237 

3217 The role of the service account. Is either `owner` or `member`.3238 The role of the service account. Is either `owner` or `member`.

3218 3239 

3240 - `source: optional "cloud_console" or "adminapi" or "retool" or 5 more`

3241 

3242 The server-derived administrative authorization context recorded for the action, when available. API-key paths identify the authenticated API surface; biscuit-authorized paths identify the permission namespace used for authorization. This does not necessarily identify the literal client software.

3243 

3244 - `"cloud_console"`

3245 

3246 - `"adminapi"`

3247 

3248 - `"retool"`

3249 

3250 - `"glass"`

3251 

3252 - `"managementapi"`

3253 

3254 - `"tenantapi"`

3255 

3256 - `"scim"`

3257 

3258 - `"backfill"`

3259 

3219 - `"user.added": optional object { id, data }`3260 - `"user.added": optional object { id, data }`

3220 3261 

3221 The details for events with this `type`.3262 The details for events with this `type`.

Details

350 350 

351### Returns351### Returns

352 352 

353- `data: array of object { id, effective_at, type, 57 more }`353- `data: array of object { id, effective_at, type, 58 more }`

354 354 

355 - `id: string`355 - `id: string`

356 356 


1490 1490 

1491 The role of the service account. Is either `owner` or `member`.1491 The role of the service account. Is either `owner` or `member`.

1492 1492 

1493 - `source: optional "cloud_console" or "adminapi" or "retool" or 5 more`

1494 

1495 The server-derived administrative authorization context recorded for the action, when available. API-key paths identify the authenticated API surface; biscuit-authorized paths identify the permission namespace used for authorization. This does not necessarily identify the literal client software.

1496 

1497 - `"cloud_console"`

1498 

1499 - `"adminapi"`

1500 

1501 - `"retool"`

1502 

1503 - `"glass"`

1504 

1505 - `"managementapi"`

1506 

1507 - `"tenantapi"`

1508 

1509 - `"scim"`

1510 

1511 - `"backfill"`

1512 

1493 - `"user.added": optional object { id, data }`1513 - `"user.added": optional object { id, data }`

1494 1514 

1495 The details for events with this `type`.1515 The details for events with this `type`.


1944 "role": "role"1964 "role": "role"

1945 }1965 }

1946 },1966 },

1967 "source": "cloud_console",

1947 "user.added": {1968 "user.added": {

1948 "id": "id",1969 "id": "id",

1949 "data": {1970 "data": {

ruby/index.md +101 −3

Details

15<!-- x-release-please-start-version -->15<!-- x-release-please-start-version -->

16 16 

17```ruby17```ruby

18gem "openai", "~> 0.77.1"18gem "openai", "~> 0.78.0"

19```19```

20 20 

21<!-- x-release-please-end -->21<!-- x-release-please-end -->


107 107 

108Note that you can also pass a raw `IO` descriptor, but this disables retries, as the library can't be sure if the descriptor is a file or pipe (which cannot be rewound).108Note that you can also pass a raw `IO` descriptor, but this disables retries, as the library can't be sure if the descriptor is a file or pipe (which cannot be rewound).

109 109 

110### Custom HTTP clients

111 

112`OpenAI::Client` accepts an `http_client` for advanced transport requirements.

113Provide an object that implements `execute(request)` and returns an

114`OpenAI::HTTPClient::Response`; subclassing `OpenAI::HTTPClient` is the easiest

115way to make that contract explicit. The request exposes the SDK-prepared HTTP

116method, URL, headers, encoded body, and timeout. Response bodies are enumerable

117byte-string chunks (or a single buffered string), so large and streaming

118responses do not need to be buffered.

119 

120The OpenAI client owns API authentication, redirects, and API-level retries.

121The custom HTTP client owns connection pooling and lifecycle, must enforce

122`request.timeout`, and should raise `OpenAI::Errors::APIConnectionError` or

123`OpenAI::Errors::APITimeoutError` for retryable transport failures. Other

124exceptions propagate without an SDK retry. The SDK does not close an injected

125HTTP client.

126 

127The default `OpenAI::NetHTTPClient` implements this contract with pooled

128`Net::HTTP` connections. It accepts an optional block for native connection

129configuration, as shown below. Call `close` to retire its current pools; the

130HTTP client remains reusable and creates fresh connections on its next request.

131 

132### Mutual TLS with a custom HTTP client

133 

134To opt in and activate mTLS for an organization or project, follow the

135[OpenAI Mutual TLS Beta Program

136guide](https://help.openai.com/en/articles/10876024-openai-mutual-tls-beta-program).

137If you use an intermediate chain, confirm that certificate-chain support is

138enabled for your organization.

139 

140For API-key requests that also require mutual TLS (mTLS), set the mTLS endpoint

141explicitly and pass a configured `OpenAI::NetHTTPClient` as `http_client`.

142`OpenAI::Client` accepts an HTTP client object so advanced transport behavior

143does not require a separate SDK option for every use case. The default

144`OpenAI::NetHTTPClient` accepts a block that configures each native

145`Net::HTTP` connection before it is pooled and started.

146 

147Ruby's native TLS properties configure the client identity. The certificate

148file must contain the leaf certificate first, followed by any intermediate

149certificates needed when certificate-chain support is enabled for your

150organization:

151 

152```ruby

153require "openai"

154 

155mtls_endpoint = URI("https://mtls.api.openai.com/v1")

156certificates = OpenSSL::X509::Certificate.load(

157 File.binread(ENV.fetch("OPENAI_CLIENT_CERTIFICATE_CHAIN"))

158)

159raise "Expected a client certificate" if certificates.empty?

160 

161leaf_certificate, *intermediates = certificates

162private_key = OpenSSL::PKey.read(

163 File.binread(ENV.fetch("OPENAI_CLIENT_KEY")),

164 ENV["OPENAI_CLIENT_KEY_PASSPHRASE"]

165)

166raise "Certificate and key do not match" unless leaf_certificate.check_private_key(private_key)

167 

168now = Time.now

169raise "Certificate is not yet valid" if now < leaf_certificate.not_before

170raise "Certificate has expired" if now > leaf_certificate.not_after

171 

172mtls_destination = [mtls_endpoint.host, mtls_endpoint.port]

173http_client = OpenAI::NetHTTPClient.new do |http|

174 unless http.use_ssl? && mtls_destination == [http.address, http.port]

175 raise "Refusing to present the client certificate to an unexpected origin"

176 end

177 

178 http.cert = leaf_certificate

179 http.extra_chain_cert = intermediates

180 http.key = private_key

181end

182 

183client = OpenAI::Client.new(

184 api_key: ENV.fetch("OPENAI_API_KEY"),

185 base_url: mtls_endpoint.to_s,

186 http_client: http_client

187)

188```

189 

190The SDK cannot infer whether custom HTTP configuration uses mTLS, so it does not

191automatically change `base_url`. An explicit `base_url`, including an EU or

192custom endpoint, is always preserved. Scope client certificates to the expected

193origin, as above, so they cannot be presented elsewhere. Use the

194`OpenAI::NetHTTPClient` block for TLS and other connection-level configuration.

195Server trust remains separate from the client identity and can be customized

196with `Net::HTTP` properties such as `cert_store` or `ca_file`.

197 

198Each `OpenAI::NetHTTPClient` owns its connection pool, so separate HTTP client

199instances do not share connections or credentials.

200 

201After a process forks, create new OpenAI and HTTP clients in the child. Keep the

202certificate configuration captured by an HTTP client immutable. For certificate

203rotation, build and atomically swap in new `OpenAI::NetHTTPClient` and

204`OpenAI::Client` instances, then call `close` on the retired HTTP client after

205in-flight work finishes. See the complete [custom HTTP client mTLS

206example](examples/mtls_custom_http_client.rb).

207 

110## Amazon Bedrock208## Amazon Bedrock

111 209 

112Use the standard client with the Bedrock provider to call OpenAI models through Amazon Bedrock's OpenAI-compatible API. Add `aws-sdk-core` to your application for AWS credential discovery and SigV4 signing:210Use the standard client with the Bedrock provider to call OpenAI models through Amazon Bedrock's OpenAI-compatible API. Add `aws-sdk-core` to your application for AWS credential discovery and SigV4 signing:


568 666 

569### Concurrency & connection pooling667### Concurrency & connection pooling

570 668 

571The `OpenAI::Client` instances are threadsafe, but are only fork-safe when there are no in-flight HTTP requests.669`OpenAI::Client` instances using the default `OpenAI::NetHTTPClient` are threadsafe, but are only fork-safe when there are no in-flight HTTP requests. Injected HTTP clients are responsible for documenting and enforcing their own concurrency guarantees.

572 670 

573Each instance of `OpenAI::Client` has its own HTTP connection pool with a default size of 99. As such, we recommend instantiating the client once per application in most settings.671By default, each `OpenAI::Client` creates its own HTTP connection pool with a size of at least 99 connections. As such, we recommend instantiating the client once per application in most settings. An injected HTTP client may instead share its pool across multiple SDK clients; the caller owns that HTTP client's lifecycle.

574 672 

575When all available connections from the pool are checked out, requests wait for a new connection to become available, with queue time counting towards the request timeout.673When all available connections from the pool are checked out, requests wait for a new connection to become available, with queue time counting towards the request timeout.

576 674