---
title: "Validate a draft private endpoint"
method: POST
path: "/private-endpoints/{id}/validate"
tags: ["Private Endpoints"]
---

# Validate a draft private endpoint

`POST /private-endpoints/{id}/validate`

Send a live test request to the draft endpoint using the given workspace's BYOK credential for its provider. A passing validation is required before activation. Failed checks return 200 with `passed: false`. [Management key](/docs/guides/overview/auth/management-api-keys) required.

## Path parameters

- `id` string, uuid, required — Stable identifier of the private endpoint.

## Request body

- ValidatePrivateEndpointRequest
  - `workspace_id` string, uuid, required — Workspace whose BYOK credential is used for the live validation call. The workspace must belong to your account.

## Response `200`

Validation checks

- PrivateEndpointValidationResponse
  - `data` PrivateEndpointValidation, required
    - `checks` PrivateEndpointCheck[], required
      - `actual_model` string, nullable — Model the upstream reported serving, when it differs from the request.
      - `name` string, required — Check name.
      - `passed` boolean, required
      - `reason` 'database_error' | 'endpoint_limit_reached' | 'invalid_base_url' | 'model_not_found' | 'provider_not_found' | 'endpoint_not_found' | 'workspace_not_found' | 'no_byok_key' | 'key_decryption_failed' | 'upstream_error' | 'invalid_response' | 'invalid_stream' | 'missing_usage' | 'model_mismatch' | 'not_validated' | 'validation_stale' — Why the check failed.
      - `upstream_message` string, nullable — Error message returned by your deployment when the call failed.
      - `upstream_status` integer — HTTP status returned by your deployment when the call failed.
    - `passed` boolean, required — Whether every check passed.

## Other responses

- `400` — Bad Request - Invalid request parameters or malformed input
- `401` — Unauthorized - Authentication required or invalid credentials
- `403` — Forbidden - Authentication successful but insufficient permissions
- `404` — Not Found - Resource does not exist
- `408` — Request Timeout - Operation exceeded time limit
- `409` — Conflict - Resource conflict or concurrent modification
- `422` — Unprocessable Entity - Semantic validation failure
- `500` — Internal Server Error - Unexpected server error
- `502` — Bad Gateway - Provider/upstream API failure

## Changes

- **2026-09-28** `057102d53272` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/openrouterteam/apis/openrouter-api/changes/private-endpoints/:id/validate/post.md)

---

[API](https://skmtc.dev/openrouterteam/apis/openrouter-api.md) · [All operations](https://skmtc.dev/openrouterteam/apis/openrouter-api/llms.txt) · [OpenAPI document](https://skmtc.dev/openrouterteam/apis/openrouter-api/revisions/ae97b5c6983d?raw)
