> ## Documentation Index
> Fetch the complete documentation index at: https://docs.nebius.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create

> Creates an endpoint.



## OpenAPI

````yaml https://api.nebius.cloud/openapi.json post /ai/v1/endpoints
openapi: 3.0.3
info:
  title: Nebius API
  version: version not set
servers:
  - url: https://api.nebius.cloud
security:
  - bearerAuth: []
tags:
  - name: nebius.ai.v1.EndpointService
  - name: nebius.ai.v1.JobService
  - name: nebius.applications.v1alpha1.K8sReleaseService
  - name: nebius.audit.v2.AuditEventExportService
  - name: nebius.audit.v2.AuditEventService
  - name: nebius.billing.v1.CalculatorService
  - name: nebius.billing.v1alpha1.CalculatorService
  - name: nebius.billing.v1alpha1.OneTimeExportService
  - name: nebius.capacity.v1.CapacityAllowanceService
  - name: nebius.capacity.v1.CapacityBlockGroupService
  - name: nebius.capacity.v1.CapacityIntervalService
  - name: nebius.capacity.v1.ResourceAdviceService
  - name: nebius.compute.v1.DiskService
  - name: nebius.compute.v1.DiskSnapshotService
  - name: nebius.compute.v1.FilesystemService
  - name: nebius.compute.v1.GpuClusterService
  - name: nebius.compute.v1.ImageService
  - name: nebius.compute.v1.InstanceService
  - name: nebius.compute.v1.MaintenanceService
  - name: nebius.compute.v1.NVLInstanceGroupService
  - name: nebius.compute.v1.NodeService
  - name: nebius.compute.v1.PlatformService
  - name: nebius.dns.v1.RecordService
  - name: nebius.dns.v1.ZoneService
  - name: nebius.iam.v1.AccessKeyService
  - name: nebius.iam.v1.AccessPermitService
  - name: nebius.iam.v1.AuthPublicKeyService
  - name: nebius.iam.v1.FederatedCredentialsService
  - name: nebius.iam.v1.FederationCertificateService
  - name: nebius.iam.v1.FederationService
  - name: nebius.iam.v1.GroupMembershipService
  - name: nebius.iam.v1.GroupService
  - name: nebius.iam.v1.InvitationService
  - name: nebius.iam.v1.ProfileService
  - name: nebius.iam.v1.ProjectService
  - name: nebius.iam.v1.ServiceAccountService
  - name: nebius.iam.v1.SessionManagementService
  - name: nebius.iam.v1.StaticKeyService
  - name: nebius.iam.v1.TenantService
  - name: nebius.iam.v1.TenantUserAccountService
  - name: nebius.iam.v1.TenantUserAccountWithAttributesService
  - name: nebius.iam.v2.AccessKeyService
  - name: nebius.iam.v2.ProjectService
  - name: nebius.iam.v2.TenantService
  - name: nebius.kms.v1.AsymmetricCryptoService
  - name: nebius.kms.v1.AsymmetricKeyService
  - name: nebius.kms.v1.SymmetricCryptoService
  - name: nebius.kms.v1.SymmetricKeyService
  - name: nebius.logging.agentmanager.v1.VersionService
  - name: nebius.logging.v1.LogExportService
  - name: nebius.maintenance.v1alpha1.MaintenanceService
  - name: nebius.mk8s.v1.ClusterService
  - name: nebius.mk8s.v1.NodeGroupService
  - name: nebius.mk8s.v1alpha1.ClusterService
  - name: nebius.mk8s.v1alpha1.NodeGroupService
  - name: nebius.msp.mlflow.v1alpha1.ClusterService
  - name: nebius.msp.postgresql.v1alpha1.BackupService
  - name: nebius.msp.postgresql.v1alpha1.ClusterService
  - name: nebius.mysterybox.v1.PayloadService
  - name: nebius.mysterybox.v1.SecretService
  - name: nebius.mysterybox.v1.SecretVersionService
  - name: nebius.quotas.v1.QuotaAllowanceService
  - name: nebius.registry.v1.ArtifactService
  - name: nebius.registry.v1.RegistryService
  - name: nebius.storage.v1.BucketService
  - name: nebius.storage.v1.TransferService
  - name: nebius.storage.v1alpha1.TransferService
  - name: nebius.tunnel.v1.TunnelService
  - name: nebius.vpc.v1.AllocationService
  - name: nebius.vpc.v1.NetworkService
  - name: nebius.vpc.v1.PoolService
  - name: nebius.vpc.v1.RouteService
  - name: nebius.vpc.v1.RouteTableService
  - name: nebius.vpc.v1.SecurityGroupService
  - name: nebius.vpc.v1.SecurityRuleService
  - name: nebius.vpc.v1.SubnetService
  - name: nebius.vpc.v1.TargetGroupService
  - name: nebius.vpc.v1alpha1.AllocationService
  - name: nebius.vpc.v1alpha1.NetworkService
  - name: nebius.vpc.v1alpha1.PoolService
  - name: nebius.vpc.v1alpha1.ScopeService
  - name: nebius.vpc.v1alpha1.SubnetService
paths:
  /ai/v1/endpoints:
    post:
      tags:
        - nebius.ai.v1.EndpointService
      summary: Create
      description: Creates an endpoint.
      operationId: EndpointService_Create
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/v1CreateEndpointRequest'
        required: true
        x-originalParamName: body
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/commonV1Operation'
          description: A successful response.
components:
  schemas:
    v1CreateEndpointRequest:
      properties:
        dryRun:
          description: Dry run creation of the endpoint.
          type: boolean
        metadata:
          $ref: '#/components/schemas/commonV1ResourceMetadata'
        spec:
          $ref: '#/components/schemas/v1EndpointSpec'
      required:
        - metadata
        - spec
      type: object
    commonV1Operation:
      properties:
        createdAt:
          description: Creation timestamp.
          format: date-time
          type: string
        createdBy:
          description: ID of the user or service account who initiated the operation.
          type: string
        description:
          description: Human-readable description of the operation. 0-256 characters long.
          type: string
        finishedAt:
          description: The time when the operation has finished.
          format: date-time
          type: string
        id:
          description: ID of the operation.
          type: string
        progressData:
          $ref: '#/components/schemas/protobufAny'
        progressTracker:
          $ref: '#/components/schemas/v1ProgressTracker'
        request:
          $ref: '#/components/schemas/protobufAny'
        requestHeaders:
          additionalProperties:
            $ref: '#/components/schemas/OperationRequestHeader'
          title: >-
            The request headers that are essential for the request that
            generated the operation.

            For instance, `x-resetmask`. Without these headers the request might
            have been processed

            differently if repeated.

            All the header names *must* be converted to lower case.

            Validator is based on:

            https://httpwg.org/specs/rfc9110.html#considerations.for.new.field.names
          type: object
        resourceId:
          description: >-
            ID of the resource that this operation creates, updates, deletes or
            otherwise changes.


            If the operation affects multiple resources or does not affect any
            API resources at all

            (e.g. a routine maintenance operation visible to the user), the
            [resource_id] must be empty.
          type: string
        status:
          $ref: '#/components/schemas/googleRpcStatus'
      type: object
    commonV1ResourceMetadata:
      description: Common resource metadata.
      properties:
        createdAt:
          description: Timestamp indicating when the resource was created.
          format: date-time
          readOnly: true
          type: string
        id:
          description: Identifier for the resource, unique for its resource type.
          type: string
        labels:
          additionalProperties:
            type: string
          description: Labels associated with the resource.
          type: object
        name:
          description: Human readable name for the resource.
          type: string
        parentId:
          description: Identifier of the parent resource to which the resource belongs.
          type: string
        resourceVersion:
          description: >-
            Version of the resource for safe concurrent modifications and
            consistent reads.

            Positive and monotonically increases on each resource spec change
            (but *not* on each change of the

            resource's container(s) or status).

            Service allows zero value or current.
          format: int64
          type: string
        updatedAt:
          description: Timestamp indicating when the resource was last updated.
          format: date-time
          readOnly: true
          type: string
      required:
        - parentId
      type: object
    v1EndpointSpec:
      description: EndpointSpec defines a endpoint that will be run.
      properties:
        args:
          description: The arguments to pass to the entrypoint command.
          type: string
        authToken:
          description: >-
            Authentication token needed to access the endpoint.


            Authentication can only be enabled if the endpoint exposes one and
            only one HTTP port.


            Mutually exclusive with `auth_token_mysterybox_secret`.

            If not provided, authentication will be disabled.
          type: string
        authTokenMysteryboxSecret:
          $ref: '#/components/schemas/v1EndpointSpecMysteryBoxSecretRef'
        containerCommand:
          description: The entrypoint command for the endpoint's container.
          type: string
        disk:
          $ref: '#/components/schemas/v1EndpointSpecDiskSpec'
        environmentVariables:
          description: Specifies the environment variables for the endpoint's container.
          items:
            $ref: '#/components/schemas/v1EndpointSpecEnvironmentVariable'
          type: array
        image:
          description: The Docker image to use for the endpoint's container.
          type: string
        injectedFiles:
          description: >-
            Small config files injected into the container before the user
            process

            starts. Intended for configs, not datasets.
          items:
            $ref: '#/components/schemas/v1EndpointSpecFileInjection'
          type: array
        platform:
          description: Compute platform that the endpoint will be run on.
          type: string
        ports:
          description: Specifies the ports that the endpoint exposes.
          items:
            $ref: '#/components/schemas/v1EndpointSpecPort'
          type: array
        preemptible:
          description: >-
            Whether to use a preemptible VM for the endpoint.

            Preemptible VMs are cheaper but can be stopped by the platform at
            any time.
          type: boolean
        preset:
          description: Compute preset that the endpoint will be run on.
          type: string
        publicIp:
          description: Whether to assign a public IP to the endpoint.
          type: boolean
        registryCredentials:
          $ref: '#/components/schemas/v1EndpointSpecRegistryCredentials'
        shmSizeBytes:
          description: Shared memory size in bytes for the endpoint's container.
          format: int64
          type: string
        sshAuthorizedKeys:
          description: Public keys to be authorized for SSH access to the job.
          items:
            type: string
          type: array
        subnetId:
          description: Subnet ID where the endpoint will be deployed.
          type: string
        volumes:
          description: Volumes to be mounted into the endpoint's container.
          items:
            $ref: '#/components/schemas/v1EndpointSpecVolumeMount'
          type: array
        workingDir:
          description: The working directory for the endpoint's container.
          type: string
      required:
        - image
        - platform
        - preset
        - disk
        - subnetId
      type: object
    protobufAny:
      additionalProperties: {}
      description: >-
        `Any` contains an arbitrary serialized protocol buffer message along
        with a

        URL that describes the type of the serialized message
      properties:
        '@type':
          description: >-
            A URL/resource name that uniquely identifies the type of the
            serialized

            protocol buffer message. This string must contain at least

            one "/" character. The last segment of the URL's path must represent

            the fully qualified name of the type (as in

            `path/google.protobuf.Duration`). The name should be in a canonical
            form

            (e.g., leading "." is not accepted).


            In practice, teams usually precompile into the binary all types that
            they

            expect it to use in the context of Any. However, for URLs which use
            the

            scheme `http`, `https`, or no scheme, one can optionally set up a
            type

            server that maps type URLs to message definitions as follows:


            * If no scheme is provided, `https` is assumed.

            * An HTTP GET on the URL must yield a [google.protobuf.Type][]
              value in binary format, or produce an error.
            * Applications are allowed to cache lookup results based on the
              URL, or have them precompiled into a binary to avoid any
              lookup. Therefore, binary compatibility needs to be preserved
              on changes to types. (Use versioned type names to manage
              breaking changes.)

            Note: this functionality is not currently available in the official

            protobuf release, and it is not used for type URLs beginning with

            type.googleapis.com. As of May 2023, there are no widely used type
            server

            implementations and no plans to implement one.


            Schemes other than `http`, `https` (or the empty scheme) might be

            used with implementation specific semantics.
          type: string
      type: object
    v1ProgressTracker:
      description: >-
        Information for tracking the progress of a task (e.g., an API operation
        or background maintenance action).

        This serves as a UI contract and may be directly reflected in CLI,
        Console, and other tools.
      properties:
        description:
          description: >-
            Human-readable description of the currently executing task, e.g.,
            "Downloading dat-groot-llm.tar.xz".

            Relates to the overall task, not individual steps.

            SHOULD match the Operation's `description` field when this
            ProgressTracker tracks an API Operation's progress.

            MAY provide more detailed overall information.


            MUST be suitable for display to public users.

            Even if the task is internal, this description may be shown to end
            users in overall task step descriptions.


            For individual step descriptions, use `Step.description`.
          type: string
        estimatedFinishedAt:
          description: |-
            Estimated completion timestamp for the task.
            MUST be absent if the task is completed (i.e., finished_at is set).
            MAY be absent if the estimate is unknown.
            MAY be updated as the progress estimate changes.
          format: date-time
          type: string
        finishedAt:
          description: >-
            Completion timestamp of the task.

            MUST be absent for running tasks; MUST be present for completed
            tasks.

            MUST match the operation's finished_at timestamp when tracking an
            API Operation's progress.
          format: date-time
          type: string
        startedAt:
          description: >-
            Timestamp when the overall task started.

            MUST match the operation's created_at timestamp when tracking an API
            Operation's progress.
          format: date-time
          type: string
        steps:
          description: >-
            Detailed information about the task steps that are currently running
            or have been finished.

            - For a completed task, the step list MUST either be empty or
            contain finished steps only.

            - For a running task, the step list MAY be empty if the task
            consists of a single step or no detailed information is available.
              A non-empty step list MUST include all currently running steps and MAY include some or all finished steps.
            - Service SHOULD provide both running and finished steps if the task
            has around 10-20 steps, and provide only running steps otherwise.
              Service MUST consistently choose either the "running steps only" or the "running + finished steps" behavior.
            - The UI, CLI etc. MAY choose not to display all steps provided by
            the service.
          items:
            $ref: '#/components/schemas/ProgressTrackerStep'
          type: array
        workDone:
          $ref: '#/components/schemas/ProgressTrackerWorkDone'
      type: object
    OperationRequestHeader:
      properties:
        values:
          items:
            type: string
          title: The values of a particular header from a request
          type: array
      title: >-
        Request header is a container for all the values of a particular header
        of a request because there is no such thing as

        `map<string, repeated string>`
      type: object
    googleRpcStatus:
      description: >-
        The `Status` type defines a logical error model that is suitable for

        different programming environments, including REST APIs and RPC APIs. It
        is

        used by [gRPC](https://github.com/grpc). Each `Status` message contains

        three pieces of data: error code, error message, and error details.


        You can find out more about this error model and how to work with it in
        the

        [API Design Guide](https://cloud.google.com/apis/design/errors).
      properties:
        code:
          description: |-
            The status code, which should be an enum value of
            [google.rpc.Code][google.rpc.Code].
          format: int32
          type: integer
        details:
          description: >-
            A list of messages that carry the error details.  There is a common
            set of

            message types for APIs to use.
          items:
            $ref: '#/components/schemas/protobufAny'
          type: array
        message:
          description: >-
            A developer-facing error message, which should be in English. Any

            user-facing error message should be localized and sent in the

            [google.rpc.Status.details][google.rpc.Status.details] field, or
            localized

            by the client.
          type: string
      type: object
    v1EndpointSpecMysteryBoxSecretRef:
      description: Reference to a MysteryBox secret.
      properties:
        secretId:
          description: MysteryBox secret ID.
          type: string
        versionId:
          description: MysteryBox secret version ID.
          type: string
      type: object
    v1EndpointSpecDiskSpec:
      properties:
        sizeBytes:
          description: Disk size in bytes.
          format: int64
          type: string
        type:
          $ref: '#/components/schemas/nebiusComputeV1DiskSpecDiskType'
      required:
        - type
      type: object
    v1EndpointSpecEnvironmentVariable:
      description: >-
        EnvironmentVariable defines an environment variable for the endpoint's
        container.
      properties:
        mysteryboxSecret:
          $ref: '#/components/schemas/v1EndpointSpecMysteryBoxSecretRef'
        name:
          description: The name of the environment variable.
          type: string
        value:
          description: |-
            Environment variable value.
            Mutually exclusive with `mysterybox_secret`.
          type: string
      required:
        - name
      type: object
    v1EndpointSpecFileInjection:
      description: FileInjection materializes a small file inside the container at launch.
      properties:
        containerPath:
          description: |-
            Absolute path inside the container where the content is written.

            Must be a clean absolute path: root, trailing slashes, empty path
            segments, "." and ".." are not allowed.
          type: string
        content:
          description: >-
            File content. Between 1 byte and 64 KiB (one mystery box secret
            payload).


            Not returned by read methods.
          format: byte
          type: string
      required:
        - containerPath
      type: object
    v1EndpointSpecPort:
      properties:
        containerPort:
          description: Container port.
          format: int32
          type: integer
        hostPort:
          description: |-
            Host port.

            If not specified, will be same as container_port.
          format: int32
          type: integer
        protocol:
          $ref: '#/components/schemas/v1EndpointSpecPortProtocol'
      required:
        - protocol
      type: object
    v1EndpointSpecRegistryCredentials:
      properties:
        mysteryboxSecretVersion:
          description: |-
            Secret version storing the registry credentials.
            Must have keys "REGISTRY_USERNAME" and "REGISTRY_PASSWORD".
          type: string
        password:
          description: Registry password for private Docker registry.
          type: string
        username:
          description: Registry username for private Docker registry.
          type: string
      type: object
    v1EndpointSpecVolumeMount:
      description: VolumeMount represents a volume mount for the endpoint's container.
      properties:
        containerPath:
          description: |-
            Path inside the endpoint's container where the volume is mounted.

            Must be an absolute path.
          type: string
        mode:
          $ref: '#/components/schemas/v1EndpointSpecVolumeMountMode'
        s3Config:
          $ref: '#/components/schemas/v1EndpointSpecVolumeMountS3Config'
        source:
          description: >-
            Source of the volume mount.


            Can be a name or an ID of Nebius Storage bucket or filesystem,

            or an S3 URI (e.g. "s3://bucket-name") when using external S3
            storage.
          type: string
        sourcePath:
          description: |-
            Path inside the source volume.

            Optional.
          type: string
      required:
        - mode
      type: object
    ProgressTrackerStep:
      description: |-
        Represents a basic step in the task.
        Fields are binary-compatible with ProgressTracker for easier processing.
      properties:
        description:
          description: >-
            Human-readable description of the step, e.g., "Connecting to
            localhost:8080".

            MUST be suitable for display to public users.

            Private descriptions must be filtered server-side based on the use
            case.
          type: string
        finishedAt:
          description: >-
            Timestamp when the step finished.

            MUST be absent for running steps; MUST be present for completed
            steps.
          format: date-time
          type: string
        startedAt:
          description: Timestamp when the step started.
          format: date-time
          type: string
        workDone:
          $ref: '#/components/schemas/ProgressTrackerWorkDone'
      type: object
    ProgressTrackerWorkDone:
      description: >-
        Information about the work done by the task or its step, expressed in
        ticks (abstract work units).

        Each tick may represent a real measurement (e.g., VMs created, KiB
        uploaded), number of substeps or a percentage of work completed.
      properties:
        doneTickCount:
          description: >-
            Number of ticks completed so far. MUST be between 0 and
            total_tick_count, inclusive.

            MUST equal total_tick_count if the task or step is finished.
          format: int64
          type: string
        totalTickCount:
          description: >-
            Total number of ticks (work units) to be completed. MUST be greater
            than 0.
          format: int64
          type: string
      type: object
    nebiusComputeV1DiskSpecDiskType:
      default: UNSPECIFIED
      enum:
        - UNSPECIFIED
        - NETWORK_SSD
        - NETWORK_HDD
        - NETWORK_SSD_NON_REPLICATED
        - NETWORK_SSD_IO_M3
      title: >-
        the list of available types will be clarified later, it is not final
        version
      type: string
    v1EndpointSpecPortProtocol:
      default: PROTOCOL_UNSPECIFIED
      description: |-
        Represents protocol of the endpoint's port which will be exposed.

         - HTTP: HTTP protocol.
         - TCP: TCP protocol.
         - UDP: UDP protocol.
      enum:
        - PROTOCOL_UNSPECIFIED
        - HTTP
        - TCP
        - UDP
      type: string
    v1EndpointSpecVolumeMountMode:
      default: MODE_UNSPECIFIED
      description: |-
        Mode that will be used to mount the volume.

         - READ_ONLY: Read-only mode.
         - READ_WRITE: Read-write mode.
      enum:
        - MODE_UNSPECIFIED
        - READ_ONLY
        - READ_WRITE
      type: string
    v1EndpointSpecVolumeMountS3Config:
      description: |-
        Config for accessing an external S3-compatible storage.

        The bucket name is specified in the `source` field as an S3 URI.
      properties:
        credentials:
          $ref: '#/components/schemas/v1EndpointSpecVolumeMountS3ConfigS3Credentials'
        endpoint:
          description: S3-compatible endpoint URL (e.g. "https://s3.amazonaws.com").
          type: string
        mysteryboxSecret:
          $ref: >-
            #/components/schemas/v1EndpointSpecVolumeMountS3ConfigMysteryBoxSecretRef
        region:
          description: S3 region.
          type: string
      required:
        - endpoint
        - region
      type: object
    v1EndpointSpecVolumeMountS3ConfigS3Credentials:
      description: Inline S3 credentials.
      properties:
        accessKeyId:
          description: Access key ID.
          type: string
        secretAccessKey:
          description: Secret access key.
          type: string
        sessionToken:
          description: Session token (optional, for temporary credentials).
          type: string
      required:
        - accessKeyId
        - secretAccessKey
      type: object
    v1EndpointSpecVolumeMountS3ConfigMysteryBoxSecretRef:
      description: Reference to a MysteryBox secret.
      properties:
        secretId:
          description: MysteryBox secret ID.
          type: string
        versionId:
          description: MysteryBox secret version ID.
          type: string
      type: object
  securitySchemes:
    bearerAuth:
      description: The Authorization header expects a Bearer token.
      scheme: bearer
      type: http

````