Skip to content

Your keys, your models

Roadmap The provider adapters are described in the providers overview. This page covers the key and catalog design that builds on them.

A provider connection holds a secret reference, never the secret value. The value is resolved inside the worker at call time and is redacted from prompts, logs and the audit trail.

Keys can be scoped to the platform, a tenant, a team or a single agent. The narrowest scope that matches wins, so one agent can use a dedicated key with its own spending limit.

The list of models, their context sizes and their prices is imported from a pinned snapshot of models.dev data:

  • the snapshot is vendored as a JSON file in the repository,
  • it is refreshed by a reviewed pull request or a scheduled job in the repository,
  • agents and workers never fetch it at run time.

That keeps the air-gapped mode intact and makes every price in an audit entry reproducible. Private or local models (for example Ollama) get local overrides next to the snapshot.

The price table is derived from the catalog plus your overrides, so a new model shows up with a price instead of as an unpriced call.