> ## Documentation Index
> Fetch the complete documentation index at: https://klef.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# OpenAI

<div className="page-title-row">
  <img src="https://mintcdn.com/klef/xJ0kXbcegZOD2G3h/images/connectors/openai.svg?fit=max&auto=format&n=xJ0kXbcegZOD2G3h&q=85&s=a646ab981876b528bd230145a3679613" alt="" noZoom width="800" height="800" data-path="images/connectors/openai.svg" />

  <h1>OpenAI</h1>
</div>

## Connection

### Settings

| Setting       | Required | Description                                                                                           |
| ------------- | -------- | ----------------------------------------------------------------------------------------------------- |
| Admin API key | Yes      | Admin key created by an organization owner under Organization settings, Admin keys. Stored encrypted. |

### Permissions

Minimum permissions the connection requires.

| Capability     | Required | Granted by (any one)              |
| -------------- | -------- | --------------------------------- |
| Manage members | Yes      | `Admin key`, `Organization owner` |
| Read projects  | Yes      | `Admin key`, `Organization owner` |

## openai.user

### Fields

| Field        | Type   | Required | Description                                                                                                                 |
| ------------ | ------ | -------- | --------------------------------------------------------------------------------------------------------------------------- |
| `email`      | string | Yes      | Email address the invite goes to and the member signs in with. Klef does not change it.                                     |
| `role`       | enum   |          | Organization role. Defaults to reader. Values: `reader` (Reader), `owner` (Owner).                                          |
| `projects`   | grant  |          | Projects the member belongs to. Applied once the member has accepted their invite. One row grants one project.              |
| `projects[]` | string |          | Project ID.                                                                                                                 |
| `active`     | bool   |          | Whether the person belongs to the organization. Switching it off removes a member, or withdraws an invite not yet accepted. |

### Default Account Matching Rules

When Klef [adopts](/docs/adoption) an account that already exists in OpenAI, it works out whose it is by trying these in order. A connection can override them.

| Account field | Worker field            |
| ------------- | ----------------------- |
| `email`       | `worker.business_email` |

## Examples

### OpenAI members

An OpenAI organization invite for every engineer, removed when they go, or withdrawn if never accepted.

```hcl theme={null}
stage active {
  target openai.user {
    email  = worker.business_email
    role   = "reader"
    active = true
  }
}
```
