curl --request PATCH \
--url https://api.usehasp.com/v1/model-access \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"default_model_id": "<string>",
"allowed_model_ids": [],
"disallowed_providers": [],
"fallback_chain": []
}
'import requests
url = "https://api.usehasp.com/v1/model-access"
payload = {
"default_model_id": "<string>",
"allowed_model_ids": [],
"disallowed_providers": [],
"fallback_chain": []
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PATCH',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
default_model_id: '<string>',
allowed_model_ids: [],
disallowed_providers: [],
fallback_chain: []
})
};
fetch('https://api.usehasp.com/v1/model-access', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.usehasp.com/v1/model-access",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_POSTFIELDS => json_encode([
'default_model_id' => '<string>',
'allowed_model_ids' => [
],
'disallowed_providers' => [
],
'fallback_chain' => [
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.usehasp.com/v1/model-access"
payload := strings.NewReader("{\n \"default_model_id\": \"<string>\",\n \"allowed_model_ids\": [],\n \"disallowed_providers\": [],\n \"fallback_chain\": []\n}")
req, _ := http.NewRequest("PATCH", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.patch("https://api.usehasp.com/v1/model-access")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"default_model_id\": \"<string>\",\n \"allowed_model_ids\": [],\n \"disallowed_providers\": [],\n \"fallback_chain\": []\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.usehasp.com/v1/model-access")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Patch.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"default_model_id\": \"<string>\",\n \"allowed_model_ids\": [],\n \"disallowed_providers\": [],\n \"fallback_chain\": []\n}"
response = http.request(request)
puts response.read_body{
"success": true,
"data": {
"allowed_model_ids": [
"<string>"
],
"default_model_id": "<string>",
"disallowed_providers": [
"<string>"
],
"fallback_mode": "<string>",
"fallback_chain": [
"<string>"
]
}
}{
"success": false,
"error": {
"type": "authentication",
"code": "INVALID_API_KEY",
"message": "Bearer token is missing, malformed, or revoked.",
"param": null,
"details": null,
"retryable": false,
"request_id": "01JQREQ7XZQK5N6PZ1VVXHYB8T"
},
"meta": {
"request_id": "01JQREQ7XZQK5N6PZ1VVXHYB8T"
}
}{
"success": false,
"error": {
"type": "permission",
"code": "MISSING_SCOPE",
"message": "The caller is authenticated but lacks the scope or capability this route requires.",
"param": null,
"details": null,
"retryable": false,
"request_id": "01JQREQ7XZQK5N6PZ1VVXHYB8T"
},
"meta": {
"request_id": "01JQREQ7XZQK5N6PZ1VVXHYB8T"
}
}{
"message": "<string>",
"errors": {}
}Update any of the model-access fields
Every field is optional — only sent fields change; an empty body returns current state. Non-API models the org enabled in-app are preserved by the merge.
curl --request PATCH \
--url https://api.usehasp.com/v1/model-access \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"default_model_id": "<string>",
"allowed_model_ids": [],
"disallowed_providers": [],
"fallback_chain": []
}
'import requests
url = "https://api.usehasp.com/v1/model-access"
payload = {
"default_model_id": "<string>",
"allowed_model_ids": [],
"disallowed_providers": [],
"fallback_chain": []
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PATCH',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
default_model_id: '<string>',
allowed_model_ids: [],
disallowed_providers: [],
fallback_chain: []
})
};
fetch('https://api.usehasp.com/v1/model-access', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.usehasp.com/v1/model-access",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_POSTFIELDS => json_encode([
'default_model_id' => '<string>',
'allowed_model_ids' => [
],
'disallowed_providers' => [
],
'fallback_chain' => [
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.usehasp.com/v1/model-access"
payload := strings.NewReader("{\n \"default_model_id\": \"<string>\",\n \"allowed_model_ids\": [],\n \"disallowed_providers\": [],\n \"fallback_chain\": []\n}")
req, _ := http.NewRequest("PATCH", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.patch("https://api.usehasp.com/v1/model-access")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"default_model_id\": \"<string>\",\n \"allowed_model_ids\": [],\n \"disallowed_providers\": [],\n \"fallback_chain\": []\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.usehasp.com/v1/model-access")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Patch.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"default_model_id\": \"<string>\",\n \"allowed_model_ids\": [],\n \"disallowed_providers\": [],\n \"fallback_chain\": []\n}"
response = http.request(request)
puts response.read_body{
"success": true,
"data": {
"allowed_model_ids": [
"<string>"
],
"default_model_id": "<string>",
"disallowed_providers": [
"<string>"
],
"fallback_mode": "<string>",
"fallback_chain": [
"<string>"
]
}
}{
"success": false,
"error": {
"type": "authentication",
"code": "INVALID_API_KEY",
"message": "Bearer token is missing, malformed, or revoked.",
"param": null,
"details": null,
"retryable": false,
"request_id": "01JQREQ7XZQK5N6PZ1VVXHYB8T"
},
"meta": {
"request_id": "01JQREQ7XZQK5N6PZ1VVXHYB8T"
}
}{
"success": false,
"error": {
"type": "permission",
"code": "MISSING_SCOPE",
"message": "The caller is authenticated but lacks the scope or capability this route requires.",
"param": null,
"details": null,
"retryable": false,
"request_id": "01JQREQ7XZQK5N6PZ1VVXHYB8T"
},
"meta": {
"request_id": "01JQREQ7XZQK5N6PZ1VVXHYB8T"
}
}{
"message": "<string>",
"errors": {}
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Body
Validation for PUT /v1/model-access — the public control-plane mirror of
the in-app Settings → Models page (Settings\UpdateModelAccessRequest).
Every field is optional (partial update): a client sends only what it wants
to change, and an empty body is a no-op. The accepted model vocabulary is
scoped to models exposing the api surface — the only ones a public API
consumer can invoke — while non-api models the org enabled in-app are
preserved untouched by the merge in {@see resolvedState()}.
All cross-field consistency (default ∈ enabled, no disabled-provider default, manual-mode chain rules) is checked against the resolved post-merge state, not the raw request body, so a partial change can't leave the org in an inconsistent state.
Not restricted to API-surface ids: the resolved default must be in the (post-merge) enabled list, which is enforced in withValidator(). Keeping it a bare string lets a client echo back a non-API default that is already enabled in-app without the round-trip 422-ing.
off, auto, manual claude-haiku-4-5, claude-opus-4-6, claude-opus-4-7, claude-sonnet-4-6, gpt-5.3-codex, gpt-5.4, gpt-5.4-mini, gpt-5.5, gpt-5.5-pro anthropic, openai claude-haiku-4-5, claude-opus-4-6, claude-opus-4-7, claude-sonnet-4-6, gpt-5.3-codex, gpt-5.4, gpt-5.4-mini, gpt-5.5, gpt-5.5-pro