/v1/gateway/, and Baseten enables them for Frontier Gateway workspaces. Authenticate with a workspace API key with management scope, passed as Authorization: Bearer $BASETEN_API_KEY. Requests from workspaces that aren’t onboarded return 403. The OpenAPI spec is available at api.baseten.co/v1/spec for generating API clients. It doesn’t yet cover deleting a group, revoking a group API key, or fetching group usage: see those reference pages for request and response details.