Prerequisites
- A Braintrust account in an organization whose data plane is in the US, Braintrust’s default.
- The ability to create an API key in your organization settings.
CloudThinker connects to Braintrust’s US endpoint,
api.braintrust.dev. Braintrust serves EU data plane organizations and self-hosted deployments from different endpoints, which this connection does not use.Setup
1
Open API keys
Sign in to Braintrust and go to Settings → API keys.
2
Create the key
Click + API key and enter a name such as
cloudthinker. Choose an expiration, which defaults to one year and cannot be changed after creation. Click Create.3
Copy the key
Copy the key right away. Braintrust shows it only once and cannot recover it later, so a lost key means creating a new one.
4
Add the connection in CloudThinker
Go to Connections → Braintrust, paste the key into BRAINTRUST_API_KEY, and click Connect. CloudThinker shows a Connected status.
Connection details
Required permissions
Braintrust says an API key inherits the permissions of the user who created it, and that a personal API key cannot be scoped below that user’s own permissions.Agent capabilities
Once connected, agents use a fixed set of read-only actions.
Agents report names and counts, and show an object ID only when you ask for it. They cannot run SQL queries over logs, list automations, or create, edit, or run anything in Braintrust.
Verify the connection
Example prompts
Troubleshooting
Calls fail with 403 or an object is missing
Calls fail with 403 or an object is missing
Braintrust’s API returns 403 when the key lacks permission for the request. The key has only the access of the account that created it, so check that account’s access to the project or experiment.
The connection stopped working after about a year
The connection stopped working after about a year
Braintrust API keys can expire, and a new key defaults to one year. An expired key stops authenticating and cannot be renewed. Create a new key and update the connection.
The agent refuses to run a query or change something
The agent refuses to run a query or change something
The connection is read-only by design and covers only the actions in the table above. Run SQL queries, edit datasets, and create alerts or scorers in Braintrust itself.
Security
- Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
- Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
- Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
- Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
- Expiration — set an expiration you can track, and rotate the key before it lapses.
- Account scope — the key acts as its creator, so create it from an account with only the access agents need.
Related
Langfuse Connection
LLM traces, prompts, and evaluations
Datadog Connection
Log search, metrics, and monitoring