Skip to content

Providers overview

Providers are configured as a JSON array, through OAX_PROVIDERS or the CLI’s --providers file. Agents refer to them by name. Without configuration, a single simulated provider is available.

[
{ "kind": "openai", "name": "openai", "baseUrl": "https://api.openai.com/v1", "apiKeySecret": "openai.key" },
{ "kind": "ollama", "name": "local", "baseUrl": "http://ollama:11434" },
{ "kind": "bedrock", "name": "bedrock", "region": "eu-central-1" },
{ "kind": "simulated", "name": "simulated" }
]
FieldMeaning
kindopenai, ollama, anthropic, bedrock, simulated
nameslug used in agents.md
clearancehighest data classification this provider may receive
proxyUrlHTTPS proxy for outbound requests
timeoutMsrequest timeout
maxRetries0 to 10 retries on 429, 5xx and network errors

Each provider has a clearance. Before the first model call, the run’s classification is compared with it; if the data is more sensitive, the run ends as blocked_by_policy.

KindDefault clearance
simulated, ollamarestricted
bedrockconfidential
openai, anthropicinternal

HTTP providers may only contact the origin of their configured base URL. A request anywhere else is refused with egress_denied. Combine this with network policies for defence in depth.