Skip to main content

About OpenAI

Iru reads project configuration, usage metrics, model access settings, and org membership from platform.openai.com. Authentication uses Authorization: Bearer with an API key. Modern sk-proj- keys are project-scoped; broader sk- or org keys expose more surface area - choose the narrowest key that satisfies your controls.

How It Works

Authorization: Bearer sk-proj-xxxx
DetailValue
CategoryAI / platform
AuthenticationBearer (API key)
Official references: Authentication, API keys, Projects.

Prerequisites

  • Access to platform.openai.com and the project you want evidence for.

Connect OpenAI to Iru

Complete this tab before you connect the source in Compliance.
1

Sign in to OpenAI Platform

Open platform.openai.com and sign in with a user who can manage API keys for the target project.
2

Select the project

Use the project picker (or Default project) to select the OpenAI project whose usage and configuration Iru should read for compliance evidence.
3

Open API keys

In the left navigation, open API keys for that project.
4

Create a new secret key

Select Create new secret key (or + Create key). Enter a label such as Iru Compliance so you can revoke the correct key later.
5

Create the key

Confirm creation. OpenAI may ask you to re-authenticate or confirm org policy depending on your tenant settings.
6

Copy the key immediately

Copy the key value when OpenAI shows it. OpenAI does not show it again. Store it in a vault until you paste it into Iru.
Continue on the Iru Compliance tab.

Troubleshooting

Check pop-up blocker settings for the Iru site and try again.
Full key string; key not deleted in Platform UI.
sk-proj- keys only see their project - add keys per project or use org-level guidance from your program.
Billing / limits on the OpenAI side - not an auth fix.

Considerations

Iru does not run inference on your behalf: it reads…

Iru does not run inference on your behalf. It reads administrative and usage metadata only.

Sources Management

Browse and manage every Compliance source.

Getting Started With Compliance

Frameworks, actions, and Artifacts.

Iru Overview

How Endpoint, Compliance, and Identity fit together.

Artifacts Management

Upload, review, and organize evidence from sources and actions.