> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orq.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Terraform

> Manage Orq.ai workspaces as code with the official Terraform provider: projects, model access, budgets, guardrails, API keys, and routing rules.

The official **Orq.ai** Terraform provider manages workspace configuration as code: projects, model access, credentials, budgets, guardrails, evaluators, and routing rules. It works with both Terraform and OpenTofu.

## Registries

<CardGroup cols={2}>
  <Card title="Terraform Registry" icon="cube" href="https://registry.terraform.io/providers/orq-ai/orq/latest/docs" cta="Full provider documentation">
    Complete schema reference and examples for every resource.
  </Card>

  <Card title="GitHub" icon="github" href="https://github.com/orq-ai/terraform-provider-orq" cta="Source and issues">
    Provider source code, releases, and issue tracker.
  </Card>
</CardGroup>

## Installation

Add the provider to the `required_providers` block. The same source address works for Terraform and OpenTofu.

```hcl theme={"theme":{"light":"github-light","dark":"github-dark"}}
terraform {
  required_providers {
    orq = {
      source  = "orq-ai/orq"
      version = "~> 0.2"
    }
  }
}
```

## Authentication

The provider authenticates with a [Management Key](/ai-studio/organization/management-keys). Create one in the **Orq.ai** dashboard, then pass it via the environment:

```bash theme={"theme":{"light":"github-light","dark":"github-dark"}}
export ORQ_API_KEY="sk-orq-..."
```

```hcl theme={"theme":{"light":"github-light","dark":"github-dark"}}
provider "orq" {
  # api_key is read from ORQ_API_KEY when omitted.
  # url defaults to https://my.orq.ai; override with ORQ_API_BASE_URL
  # for on-prem installs.
}
```

A key created with the `ALL` permission mode can manage every supported resource, including minting further API keys and Management Keys. A `RESTRICTED` key manages only the domains it was granted.

## Next steps

<CardGroup cols={2}>
  <Card title="Quickstart" icon="rocket" href="/reference/terraform/quickstart">
    Provision a project, enable a model, and mint a scoped API key in one apply.
  </Card>

  <Card title="Supported resources" icon="list" href="/reference/terraform/resources">
    Every resource the provider manages, with links to the full reference.
  </Card>

  <Card title="Importing resources" icon="file-import" href="/reference/terraform/importing">
    Adopt dashboard-created resources, one at a time or an entire workspace at once.
  </Card>

  <Card title="Enterprise baseline" icon="shield-check" href="/reference/terraform/enterprise-baseline">
    A pre-written locked-down setup: model enforcement, PII redaction, secret detection, and a hard budget.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.