> ## Documentation Index
> Fetch the complete documentation index at: https://docs.barndoor.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Terraform Provider

> Manage your Barndoor organization as code with the official Terraform provider

The official Barndoor Terraform provider lets you manage your organization's configuration — MCP servers, access policies, LLM Gateway routing and controls, and data protection — as versioned, reviewable infrastructure-as-code.

The provider is published on the Terraform Registry as [`barndoor-ai/barndoor`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest) and developed on [GitHub](https://github.com/barndoor-ai/terraform-provider-barndoor).

<CardGroup cols={2}>
  <Card title="Getting Started" icon="rocket" href="/terraform/getting-started">
    Generate a provider credential, configure the provider, and apply your first resource.
  </Card>

  <Card title="Manage MCP Access" icon="shield-halved" href="/terraform/manage-mcp-access">
    Onboard an MCP server, connect it, register an AI Agent, and govern access with a policy.
  </Card>

  <Card title="Manage the LLM Gateway" icon="route" href="/terraform/llm-gateway">
    Configure providers, model routing with failover, access policies, rate limits, and budgets.
  </Card>

  <Card title="Manage Data Protection" icon="user-shield" href="/terraform/data-protection">
    Define custom detection types, allow lists, and enforcement policies with a safe rollout path.
  </Card>

  <Card title="Best Practices" icon="list-check" href="/terraform/best-practices">
    Importing existing configuration, avoiding drift, CI/CD, and troubleshooting.
  </Card>

  <Card title="Provider Reference" icon="book" href="https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs">
    The complete argument-level reference for every resource and data source, on the Terraform Registry.
  </Card>
</CardGroup>

## What you can manage

This page groups the provider's resources by product area. For argument-level detail, each resource links to its [Terraform Registry](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs) reference page — the registry is always the authoritative schema documentation for the provider version you have installed.

### MCP Gateway

| Resource | Manages |
| - | - |
| [`barndoor_mcp_server`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/resources/mcp_server) | An MCP server instance created from a directory entry, including OAuth or pre-populated credentials |
| [`barndoor_connection`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/resources/connection) | A tenant-wide credential connection to an MCP server (non-OAuth providers) |
| [`barndoor_policy`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/resources/policy) | An MCP access policy: which AI Agents may call which tools, under what conditions |
| [`barndoor_agent`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/resources/agent) | An AI Agent registration with your organization |

Data sources: [`barndoor_mcp_server`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/data-sources/mcp_server), [`barndoor_agent`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/data-sources/agent), and [`barndoor_policy`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/data-sources/policy) look up existing objects by ID or name so you can reference them without managing them. [`barndoor_mcp_server_directory`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/data-sources/mcp_server_directory) and [`barndoor_agent_directory`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/data-sources/agent_directory) look up catalog entries by slug or name, so onboarding a server or registering an agent needs no hand-copied IDs.

### LLM Gateway

| Resource | Manages |
| - | - |
| [`barndoor_llm_connection`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/resources/llm_connection) | A shareable credential for a model vendor: an API key, structured credentials, or an assumed IAM role |
| [`barndoor_llm_provider`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/resources/llm_provider) | An upstream LLM provider (OpenAI, Anthropic, …), the connection it reads its credential from, and how its usage is billed |
| [`barndoor_llm_model_mapping`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/resources/llm_model_mapping) | A route from a caller-facing model alias to an upstream model, with failover priority and cooldowns |
| [`barndoor_llm_model_route_group`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/resources/llm_model_route_group) | A named set of route aliases that access policies can grant or deny as one |
| [`barndoor_llm_routing_policy`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/resources/llm_routing_policy) | A caller-facing alias that picks one of several model slots per request |
| [`barndoor_llm_routing_rule`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/resources/llm_routing_rule) | A plain-English rule that sets a routing policy's minimum or banned slots for a kind of work |
| [`barndoor_llm_model_access`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/resources/llm_model_access) | An allowlist or denylist of models for an organization, group, or user scope |
| [`barndoor_llm_rate_limit`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/resources/llm_rate_limit) | Requests-per-minute and tokens-per-minute ceilings on a scope or on each member of an IdP group, optionally for one provider, model, alias or MCP server |
| [`barndoor_llm_token_budget`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/resources/llm_token_budget) | Daily, weekly, or monthly token or spend budgets with alert thresholds, on a scope or on each member of an IdP group, optionally for one provider, model, alias or MCP server |
| [`barndoor_llm_model_pricing`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/resources/llm_model_pricing) | Pricing rules used for cost attribution |
| [`barndoor_llm_governance_config`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/resources/llm_governance_config) | Organization-wide LLM Gateway governance settings: pricing enforcement, default model access, and routing-policy enforcement |

Data source: [`barndoor_llm_provider`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/data-sources/llm_provider) looks up a provider created in the Barndoor app by ID or name, so mappings, access policies, and pricing rules can reference it without managing it.

### Data Control Center

| Resource | Manages |
| - | - |
| [`barndoor_dlp_org_config`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/resources/dlp_org_config) | The organization's data protection master switch and global dry-run mode |
| [`barndoor_dlp_detection_engine`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/resources/dlp_detection_engine) | A detection engine (a Protection Profile in the app): which detection provider scans for which data types |
| [`barndoor_dlp_custom_detection_type`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/resources/dlp_custom_detection_type) | Organization-defined detection types built from literal and regex patterns |
| [`barndoor_dlp_allow_list_entry`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/resources/dlp_allow_list_entry) | Allow-list entries that suppress false-positive findings |
| [`barndoor_dlp_enforcement_policy`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/resources/dlp_enforcement_policy) | Enforcement policies that block, redact, or tokenize findings in MCP or LLM traffic |
| [`barndoor_dlp_field_control_policy`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/resources/dlp_field_control_policy) | Per-tool field rules applied to an MCP server's tool output |

Data source: [`barndoor_dlp_detection_engine`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/data-sources/dlp_detection_engine) looks up an existing Protection Profile by ID or name.

### Security & Access

| Resource | Manages |
| - | - |
| [`barndoor_idp`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/resources/idp) | Your organization's enterprise SSO / OIDC federation |
| [`barndoor_log_export`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/resources/log_export) | Streaming audit-log export to your own S3-compatible or Azure Blob Storage container |
| [`barndoor_notification_channel`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/resources/notification_channel) | Where admin alerts are delivered: an email address, a signed webhook, a Slack channel, or a Teams workflow |

Data sources: [`barndoor_idp_settings`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/data-sources/idp_settings), [`barndoor_log_export_aws_trust_info`](https://registry.terraform.io/providers/barndoor-ai/barndoor/latest/docs/data-sources/log_export_aws_trust_info).

## When to use Terraform

Terraform is the right tool when you want your Barndoor configuration to be reviewable, repeatable, and auditable — policy changes that go through pull requests, environments that can be rebuilt from code, and governance settings that can't drift silently.

A few things intentionally remain portal-only:

* **OAuth-connected MCP servers** — the interactive browser consent step can't be performed by a declarative apply. Terraform manages non-OAuth connections (`api_key`, `bearer_token`, `basic_auth`, `generic`); OAuth servers are connected in the Barndoor app.
* **SSO enforcement and break-glass accounts** — enforcement is irreversible and member-impacting, so it stays behind the portal's confirmation flow.
* **Interactive setup flows** such as provider catalogs and connectivity testing — including the Slack app install a `slack` notification channel depends on, and the channel **test** action.
* **Personal notification preferences** — a user's own in-app and email alert settings belong to that user, not to the organization, so Terraform manages only the organization-wide channels.

<Tip>
  Give each object exactly one owner: either Terraform or the portal. Managing the same policy or server from both places causes plans that fight the UI and vice versa. See [Best Practices](/terraform/best-practices#one-owner-per-object).
</Tip>

## Versioning and stability

The provider follows semantic versioning. The platform APIs it uses are covered by Barndoor's public API stability contract: changes within a major version are additive, and breaking changes ship as a new API version served in parallel with the old one for a deprecation window. Review the [provider changelog](https://github.com/barndoor-ai/terraform-provider-barndoor/blob/main/CHANGELOG.md) before upgrading, and pin a version range in your configuration:

```hcl theme={null}
terraform {
  required_providers {
    barndoor = {
      source  = "barndoor-ai/barndoor"
      version = "~> 0.3"
    }
  }
}
```


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.