> ## Documentation Index
> Fetch the complete documentation index at: https://docs.barndoor.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# List routing policies

> Returns every routing policy in the organization. A routing policy is a model alias that, when called, picks one of several model slots per request.



## OpenAPI

````yaml api-reference/llm-gateway-openapi.yml get /admin/routing-policies
openapi: 3.1.0
info:
  title: Barndoor LLM Gateway Admin API
  version: 1.0.0
  description: >
    Configure the Barndoor LLM Gateway programmatically: credentials and
    providers,

    model routes and route groups, pricing, routing policies and rules, launch
    profiles,

    budgets, rate limits, model access, API keys, and organization-wide
    governance settings.


    These are the same APIs the Barndoor app uses under **LLM Management**, and
    the

    Barndoor Terraform provider manages its LLM Gateway resources through them.
    Every

    endpoint is scoped to the organization of the calling token.


    ## Base URL


    ```

    https://app.barndoor.ai/api/llm-gateway

    ```


    For a dedicated deployment, replace `app.barndoor.ai` with the host you sign
    in to.


    ## Authentication


    Send an access token from Barndoor's identity provider in the
    `Authorization` header:


    ```

    Authorization: Bearer <access-token>

    ```


    For scripts and CI, use a service-account token from the OAuth 2.0
    client-credentials

    grant, as the Terraform provider does. The caller needs the admin role in
    the

    organization.


    The `bd-...` API keys you create with these endpoints are for LLM traffic

    (`/v1/chat/completions`, `/v1/messages`, and so on), not for these
    administrative calls.


    ## Partial updates


    Most `PUT` endpoints change only the fields you send. Where a field can be
    cleared,

    send it as `null`; omitting it leaves it unchanged. The exceptions are
    called out on

    the endpoint: `PUT /admin/governance-config` replaces the whole
    configuration,

    `PUT /admin/routing-rules/{id}` replaces the whole rule, and

    `PUT /admin/agent-runtime-profiles/{slug}` replaces the profile's models.


    ## Errors


    Errors are returned as JSON:


    ```json

    { "error": { "message": "retry_on_429_count must be between 0 and 10",
    "type": "invalid_request_error" } }

    ```
  contact:
    name: Barndoor Support
    url: https://barndoor.ai
servers:
  - url: https://{host}/api/llm-gateway
    description: Your Barndoor platform host.
    variables:
      host:
        default: app.barndoor.ai
        description: >-
          The host serving your Barndoor deployment. Use the default for
          Barndoor SaaS; for a dedicated deployment, use the host you sign in
          to.
security:
  - BearerAuth: []
tags:
  - name: Credentials
    description: >-
      Stored upstream secrets (API keys, AWS roles, Google credentials) that
      providers reference
  - name: Providers
    description: Named upstream providers backed by a credential and a model family
  - name: Model Routes
    description: >-
      Map caller-facing aliases to upstream models on one or more providers,
      with failover order, retries, timeouts, and cooldowns
  - name: Route Groups
    description: >-
      Named sets of model aliases that model access policies can target as one
      unit
  - name: Model Pricing
    description: >-
      Versioned per-million-token costs used for cost reporting and cost-based
      budgets
  - name: Routing Policies
    description: Model aliases that pick one of several model slots for each request
  - name: Routing Rules
    description: >-
      Plain-English rules that set a minimum slot or forbid slots on a routing
      policy
  - name: Launch Profiles
    description: >-
      Models and capabilities applied when members start an agent with barndoor
      run
  - name: Rate Limits
    description: Requests-per-minute and tokens-per-minute ceilings
  - name: Budgets
    description: Daily, weekly, or monthly token and cost ceilings
  - name: Model Access
    description: >-
      Allowlist and denylist policies for models, providers, aliases, and route
      groups
  - name: Governance
    description: Organization-wide LLM Gateway settings
  - name: API Keys
    description: Organization-managed `bd-...` gateway API keys for LLM traffic
paths:
  /admin/routing-policies:
    get:
      tags:
        - Routing Policies
      summary: List routing policies
      description: >-
        Returns every routing policy in the organization. A routing policy is a
        model alias that, when called, picks one of several model slots per
        request.
      operationId: listRoutingPolicies
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/RoutingPolicy'
        '401':
          description: Missing or invalid access token
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Your role does not allow this action
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - BearerAuth: []
components:
  schemas:
    RoutingPolicy:
      type: object
      required:
        - id
        - org_id
        - model_alias
        - enabled
        - posture
        - slots
        - context_breakpoints
        - router_input_max_chars
        - default_slot_on_failure
        - created_at
        - updated_at
      properties:
        context_breakpoints:
          type: array
          items:
            type: integer
            format: int32
          description: >-
            Prompt sizes, in tokens, that set a minimum slot for very large
            requests. There is one fewer entry than slots, in strictly
            increasing order. Defaults to `[128000, 512000]`.
        created_at:
          type: string
          format: date-time
        default_slot_on_failure:
          type: integer
          format: int32
          description: Slot used when the determiner cannot make a choice. Defaults to `1`.
        description:
          type:
            - string
            - 'null'
        determiner_model_alias:
          type:
            - string
            - 'null'
          description: The model that reads each request and picks a slot.
        determiner_prompt:
          type:
            - string
            - 'null'
          description: >-
            Optional replacement for the determiner's built-in instructions. The
            slot list and output format are always added by the gateway.
        enabled:
          type: boolean
        id:
          type: string
          format: uuid
        model_alias:
          type: string
          description: The alias callers send in `model` to use this policy.
        org_id:
          type: string
          format: uuid
        posture:
          $ref: '#/components/schemas/Posture'
          description: Which way the policy leans when the choice between slots is close.
        router_input_max_chars:
          type: integer
          format: int32
          description: >-
            How many characters of the request the determiner reads. Defaults to
            12000.
        slots:
          type: array
          items:
            $ref: '#/components/schemas/RoutingSlot'
          description: >-
            The models the policy chooses between, in order from the lightest to
            the most capable. Slot numbers elsewhere are 0-based positions in
            this list.
        updated_at:
          type: string
          format: date-time
      description: >-
        A routing policy: a model alias that sends each request to one of its
        slots.
    Error:
      type: object
      required:
        - error
      properties:
        error:
          type: object
          required:
            - message
            - type
          properties:
            message:
              type: string
              description: Human-readable explanation of what went wrong.
            type:
              type: string
              description: >-
                Error category, such as `invalid_request_error`,
                `authentication_error`, `permission_error`, `not_found_error`,
                or `conflict_error`.
            code:
              type:
                - string
                - 'null'
              description: Machine-readable code, when one applies.
      example:
        error:
          message: retry_on_429_count must be between 0 and 10
          type: invalid_request_error
    Posture:
      type: string
      description: >-
        `savings` prefers the lighter slot when the choice is close, `quality`
        prefers the more capable one, and `balanced` (the default) leans neither
        way. Posture never overrides a routing rule or the caller's model
        access.
      enum:
        - savings
        - balanced
        - quality
    RoutingSlot:
      type: object
      required:
        - model_alias
      properties:
        description:
          type:
            - string
            - 'null'
          description: >-
            Optional guidance for the determiner about what this slot is for,
            such as "code and debugging". Up to 2,000 characters.
        label:
          type:
            - string
            - 'null'
          description: Optional display label.
        model_alias:
          type: string
          description: >-
            Model alias this slot sends requests to. May include a provider
            prefix, such as `Anthropic/claude-haiku-4-5`.
      description: One model a routing policy can choose.
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        An access token from Barndoor's identity provider, sent as
        `Authorization: Bearer <token>`. Use a service-account token from the
        OAuth 2.0 client-credentials grant for scripts and CI, or a signed-in
        user's token. The caller needs the admin role in the organization.
        Gateway API keys (`bd-...`) are not accepted here.

````