About OpenAI
Iru reads project configuration, usage metrics, model access settings, and org membership from platform.openai.com. Authentication usesAuthorization: Bearer with an API key. Modern sk-proj- keys are project-scoped; broader sk- or org keys expose more surface area - choose the narrowest key that satisfies your controls.
How It Works
| Detail | Value |
|---|---|
| Category | AI / platform |
| Authentication | Bearer (API key) |
Prerequisites
- Access to platform.openai.com and the project you want evidence for.
Connect OpenAI to Iru
- OpenAI
- Iru Compliance
Complete this tab before you connect the source in Compliance.
Sign in to OpenAI Platform
Open platform.openai.com and sign in with a user who can manage API keys for the target project.
Select the project
Use the project picker (or Default project) to select the OpenAI project whose usage and configuration Iru should read for compliance evidence.
Create a new secret key
Select Create new secret key (or + Create key). Enter a label such as Iru Compliance so you can revoke the correct key later.
Create the key
Confirm creation. OpenAI may ask you to re-authenticate or confirm org policy depending on your tenant settings.
Continue on the Iru Compliance tab.
Troubleshooting
Nothing opens when you turn the source on
Nothing opens when you turn the source on
Check pop-up blocker settings for the Iru site and try again.
401 Unauthorized
401 Unauthorized
Incomplete org view
Incomplete org view
sk-proj- keys only see their project - add keys per project or use org-level guidance from your program.Quota errors
Quota errors
Billing / limits on the OpenAI side - not an auth fix.
Considerations
Iru does not run inference on your behalf: it reads…
Iru does not run inference on your behalf. It reads administrative and usage metadata only.
Related Articles
Sources Management
Browse and manage every Compliance source.
Getting Started With Compliance
Frameworks, actions, and Artifacts.
Iru Overview
How Endpoint, Compliance, and Identity fit together.
Artifacts Management
Upload, review, and organize evidence from sources and actions.
