> ## Documentation Index
> Fetch the complete documentation index at: https://docs.barndoor.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Get a launch profile



## OpenAPI

````yaml api-reference/llm-gateway-openapi.yml get /admin/agent-runtime-profiles/{slug}
openapi: 3.1.0
info:
  title: Barndoor LLM Gateway Admin API
  version: 1.0.0
  description: >
    Configure the Barndoor LLM Gateway programmatically: credentials and
    providers,

    model routes and route groups, pricing, routing policies and rules, launch
    profiles,

    budgets, rate limits, model access, API keys, and organization-wide
    governance settings.


    These are the same APIs the Barndoor app uses under **LLM Management**, and
    the

    Barndoor Terraform provider manages its LLM Gateway resources through them.
    Every

    endpoint is scoped to the organization of the calling token.


    ## Base URL


    ```

    https://app.barndoor.ai/api/llm-gateway

    ```


    For a dedicated deployment, replace `app.barndoor.ai` with the host you sign
    in to.


    ## Authentication


    Send an access token from Barndoor's identity provider in the
    `Authorization` header:


    ```

    Authorization: Bearer <access-token>

    ```


    For scripts and CI, use a service-account token from the OAuth 2.0
    client-credentials

    grant, as the Terraform provider does. The caller needs the admin role in
    the

    organization.


    The `bd-...` API keys you create with these endpoints are for LLM traffic

    (`/v1/chat/completions`, `/v1/messages`, and so on), not for these
    administrative calls.


    ## Partial updates


    Most `PUT` endpoints change only the fields you send. Where a field can be
    cleared,

    send it as `null`; omitting it leaves it unchanged. The exceptions are
    called out on

    the endpoint: `PUT /admin/governance-config` replaces the whole
    configuration,

    `PUT /admin/routing-rules/{id}` replaces the whole rule, and

    `PUT /admin/agent-runtime-profiles/{slug}` replaces the profile's models.


    ## Errors


    Errors are returned as JSON:


    ```json

    { "error": { "message": "retry_on_429_count must be between 0 and 10",
    "type": "invalid_request_error" } }

    ```
  contact:
    name: Barndoor Support
    url: https://barndoor.ai
servers:
  - url: https://{host}/api/llm-gateway
    description: Your Barndoor platform host.
    variables:
      host:
        default: app.barndoor.ai
        description: >-
          The host serving your Barndoor deployment. Use the default for
          Barndoor SaaS; for a dedicated deployment, use the host you sign in
          to.
security:
  - BearerAuth: []
tags:
  - name: Credentials
    description: >-
      Stored upstream secrets (API keys, AWS roles, Google credentials) that
      providers reference
  - name: Providers
    description: Named upstream providers backed by a credential and a model family
  - name: Model Routes
    description: >-
      Map caller-facing aliases to upstream models on one or more providers,
      with failover order, retries, timeouts, and cooldowns
  - name: Route Groups
    description: >-
      Named sets of model aliases that model access policies can target as one
      unit
  - name: Model Pricing
    description: >-
      Versioned per-million-token costs used for cost reporting and cost-based
      budgets
  - name: Routing Policies
    description: Model aliases that pick one of several model slots for each request
  - name: Routing Rules
    description: >-
      Plain-English rules that set a minimum slot or forbid slots on a routing
      policy
  - name: Launch Profiles
    description: >-
      Models and capabilities applied when members start an agent with barndoor
      run
  - name: Rate Limits
    description: Requests-per-minute and tokens-per-minute ceilings
  - name: Budgets
    description: Daily, weekly, or monthly token and cost ceilings
  - name: Model Access
    description: >-
      Allowlist and denylist policies for models, providers, aliases, and route
      groups
  - name: Governance
    description: Organization-wide LLM Gateway settings
  - name: API Keys
    description: Organization-managed `bd-...` gateway API keys for LLM traffic
paths:
  /admin/agent-runtime-profiles/{slug}:
    get:
      tags:
        - Launch Profiles
      summary: Get a launch profile
      operationId: getLaunchProfile
      parameters:
        - name: slug
          in: path
          description: Launch profile slug, unique within the organization
          required: true
          schema:
            type: string
      responses:
        '200':
          description: The profile
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AgentRuntimeProfile'
        '401':
          description: Missing or invalid access token
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Your role does not allow this action
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: No such record in your organization
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - BearerAuth: []
components:
  schemas:
    AgentRuntimeProfile:
      type: object
      description: >-
        A launch profile: the models and capabilities applied when organization
        members start an agent with `barndoor run`.
      required:
        - id
        - org_id
        - slug
        - display_name
        - client
        - active
        - is_org_default
        - version
        - config
        - capabilities
        - created_at
        - updated_at
      properties:
        active:
          type: boolean
          description: Whether members can launch with this profile.
        capabilities:
          $ref: '#/components/schemas/AgentRuntimeCapabilities'
        client:
          type: string
          description: 'The agent client: `claude` (Claude Code) or `codex` (Codex CLI).'
        config:
          type: object
          additionalProperties:
            type: string
          propertyNames:
            type: string
          description: >-
            Model route aliases keyed by client setting. `model` is required.
            Claude Code profiles also accept `ANTHROPIC_DEFAULT_OPUS_MODEL`,
            `ANTHROPIC_DEFAULT_SONNET_MODEL`, `ANTHROPIC_DEFAULT_HAIKU_MODEL`,
            `ANTHROPIC_DEFAULT_FABLE_MODEL`, `advisorModel`, and
            `additionalModel1` through `additionalModel16`. Codex profiles
            accept only `model`. Each value is a single model route alias.
        created_at:
          type: string
          format: date-time
        display_name:
          type: string
        id:
          type: string
          format: uuid
        is_org_default:
          type: boolean
          description: >-
            Whether this is the organization's default profile for its client.
            Each client has at most one default.
        org_id:
          type: string
          format: uuid
        slug:
          type: string
          description: Identifier used in the URL, unique within the organization.
        updated_at:
          type: string
          format: date-time
        version:
          type: integer
          format: int32
          description: >-
            Version of the current models-and-capabilities contract. Each
            replacement creates a new version.
    Error:
      type: object
      required:
        - error
      properties:
        error:
          type: object
          required:
            - message
            - type
          properties:
            message:
              type: string
              description: Human-readable explanation of what went wrong.
            type:
              type: string
              description: >-
                Error category, such as `invalid_request_error`,
                `authentication_error`, `permission_error`, `not_found_error`,
                or `conflict_error`.
            code:
              type:
                - string
                - 'null'
              description: Machine-readable code, when one applies.
      example:
        error:
          message: retry_on_429_count must be between 0 and 10
          type: invalid_request_error
    AgentRuntimeCapabilities:
      type: object
      description: >-
        The capabilities a launch profile gives agent sessions. Omitted fields
        take the `client_default` values shown as defaults. Some combinations
        are not available for every client; the error message names the
        conflict.
      properties:
        additional_instructions:
          type: string
          default: ''
          description: Extra instructions given to the agent, up to 4,000 characters.
        allowed_commands:
          type: array
          items:
            type: string
          default: []
          description: Shell commands the agent may run. Same limits as `allowed_tools`.
        allowed_tools:
          type: array
          items:
            type: string
          default: []
          description: >-
            Tools the agent may use. Up to 64 entries of at most 200 characters,
            no duplicates, and none that also appear in `blocked_tools`.
        blocked_commands:
          type: array
          items:
            type: string
          default: []
          description: >-
            Shell commands the agent may not run. Same limits as
            `allowed_tools`.
        blocked_tools:
          type: array
          items:
            type: string
          default: []
          description: Tools the agent may not use. Same limits as `allowed_tools`.
        browser:
          type: string
          default: native
          description: 'Browser access: `disabled` or `native`.'
        environment:
          type: string
          default: inherit
          description: >-
            Whether the session inherits the user's environment variables
            (`inherit`) or starts with a cleaned environment (`scrubbed`).
        filesystem:
          type: string
          default: read_write
          description: 'File access: `disabled`, `read_only`, or `read_write`.'
        network:
          type: string
          default: native
          description: 'Network access: `disabled`, `barndoor`, or `native`.'
        preset:
          type: string
          default: client_default
          description: >-
            Named starting point: `locked_down`, `guarded_development`,
            `client_default`, or `custom`.
        schema_version:
          type: integer
          format: int32
          default: 1
          minimum: 0
          description: Capability contract version. Must be `1`.
        shell:
          type: string
          default: native
          description: >-
            Shell access: `disabled`, `barndoor`, or `native`. `native` requires
            `filesystem: read_write`.
        skills:
          type: boolean
          default: true
          description: Whether the agent can use skills.
        subagents:
          type: boolean
          default: true
          description: Whether the agent can start subagents.
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        An access token from Barndoor's identity provider, sent as
        `Authorization: Bearer <token>`. Use a service-account token from the
        OAuth 2.0 client-credentials grant for scripts and CI, or a signed-in
        user's token. The caller needs the admin role in the organization.
        Gateway API keys (`bd-...`) are not accepted here.

````