export interface FeatureFlagDefinition { key: string; label: string; description: string; descriptionI18nKey: string; category: "security" | "network" | "policies" | "runtime" | "cli" | "health"; defaultValue: string; type: "boolean" | "enum"; enumValues?: string[]; requiresRestart: boolean; warningLevel?: "info" | "caution" | "danger"; } export const FEATURE_FLAG_DEFINITIONS: FeatureFlagDefinition[] = [ // ──────────────── Security (9) ──────────────── { key: "REQUIRE_API_KEY", label: "Require API Key", description: "Require an API key for all incoming requests", descriptionI18nKey: "featureFlagRequireApiKeyDescription", category: "security", defaultValue: "false", type: "boolean", requiresRestart: false, warningLevel: "caution", }, { key: "INPUT_SANITIZER_ENABLED", label: "Input Sanitizer", description: "Enable input sanitization for all requests", descriptionI18nKey: "featureFlagInputSanitizerEnabledDescription", category: "security", defaultValue: "true", type: "boolean", requiresRestart: false, warningLevel: "info", }, { key: "INJECTION_GUARD_MODE", label: "Injection Guard Mode", description: "Set the prompt injection guard mode", descriptionI18nKey: "featureFlagInjectionGuardModeDescription", category: "security", defaultValue: "off", type: "enum", enumValues: ["off", "warn", "block", "redact"], requiresRestart: false, warningLevel: "info", }, { key: "PII_REDACTION_ENABLED", label: "PII Redaction", description: "Redact personally identifiable information from requests", descriptionI18nKey: "featureFlagPiiRedactionEnabledDescription", category: "security", defaultValue: "false", type: "boolean", requiresRestart: false, warningLevel: "info", }, { key: "PII_RESPONSE_SANITIZATION", label: "PII Response Sanitization", description: "Sanitize PII from provider responses", descriptionI18nKey: "featureFlagPiiResponseSanitizationDescription", category: "security", defaultValue: "false", type: "boolean", requiresRestart: false, warningLevel: "info", }, { key: "PII_RESPONSE_SANITIZATION_MODE", label: "PII Response Sanitization Mode", description: "Mode for PII response sanitization: redact (replace PII), warn (log only), block (reject), off (disable)", descriptionI18nKey: "featureFlagPiiResponseSanitizationModeDescription", category: "security", defaultValue: "redact", type: "enum", enumValues: ["redact", "warn", "block", "off"], requiresRestart: false, warningLevel: "info", }, { key: "OUTBOUND_SSRF_GUARD_ENABLED", label: "SSRF Guard", description: "Block outbound requests to private/internal IP ranges", descriptionI18nKey: "featureFlagOutboundSsrfGuardEnabledDescription", category: "security", defaultValue: "true", type: "boolean", requiresRestart: false, warningLevel: "info", }, { key: "ALLOW_API_KEY_REVEAL", label: "API Key Reveal", description: "Allow authenticated dashboard users to reveal stored API keys instead of only seeing masked values.", descriptionI18nKey: "featureFlagAllowApiKeyRevealDescription", category: "security", defaultValue: "false", type: "boolean", requiresRestart: false, warningLevel: "danger", }, // ──────────────── Network (7) ──────────────── { key: "ENABLE_TLS_FINGERPRINT", label: "TLS Fingerprint", description: "Enable TLS fingerprint stealth mode", descriptionI18nKey: "featureFlagEnableTlsFingerprintDescription", category: "network", defaultValue: "false", type: "boolean", requiresRestart: true, warningLevel: "info", }, { key: "ONEPROXY_ENABLED", label: "OneProxy Enabled", description: "Enable 1proxy request proxying.", descriptionI18nKey: "settings.featureFlags.oneproxyEnabled", category: "network", defaultValue: "true", type: "boolean", requiresRestart: false, warningLevel: "info", }, { key: "PROXY_AUTO_SELECT_ENABLED", label: "Proxy Auto-Selection Fallback", description: "When no proxy is assigned to a connection, auto-select the first working proxy from the registry. Off by default — otherwise any single registry proxy becomes a global fallback for all traffic (#3332).", descriptionI18nKey: "settings.featureFlags.proxyAutoSelectEnabled", category: "network", defaultValue: "false", type: "boolean", requiresRestart: false, warningLevel: "caution", }, { key: "OMNIROUTE_CONTROL_PLANE_PROXY_DIRECT_FALLBACK", label: "Control-Plane Proxy Direct Fallback", description: "Allow OAuth and provider validation flows to bypass a pinned proxy and connect directly when proxy reachability pre-checks fail. Off by default because this can change account egress IP.", descriptionI18nKey: "featureFlagOmnirouteControlPlaneProxyDirectFallbackDescription", category: "network", defaultValue: "false", type: "boolean", requiresRestart: false, warningLevel: "danger", }, { key: "MITM_DISABLE_TLS_VERIFY", label: "Disable TLS Verify (MITM)", description: "Disable TLS certificate verification for MITM proxy", descriptionI18nKey: "featureFlagMitmDisableTlsVerifyDescription", category: "network", defaultValue: "false", type: "boolean", requiresRestart: true, warningLevel: "danger", }, { key: "OMNIROUTE_ALLOW_PRIVATE_PROVIDER_URLS", label: "Allow Private Provider URLs", description: "Allow provider URLs pointing to private/internal networks", descriptionI18nKey: "featureFlagOmnirouteAllowPrivateProviderUrlsDescription", category: "network", defaultValue: "false", type: "boolean", requiresRestart: false, warningLevel: "caution", }, { key: "OMNIROUTE_ALLOW_LOCAL_PROVIDER_URLS", label: "Allow Local Provider URLs", description: "Allow adding and validating providers on local/private addresses (127.0.0.1, localhost, LAN, private IP ranges) — needed for local OpenAI-compatible models. Enabled by default (OmniRoute is local-first); turn it OFF to enforce strict public-only blocking if you only use public providers. Cloud-metadata endpoints (e.g. 169.254.169.254) stay blocked either way.", descriptionI18nKey: "featureFlagOmnirouteAllowLocalProviderUrlsDescription", category: "network", defaultValue: "true", type: "boolean", requiresRestart: false, warningLevel: "caution", }, { key: "ENABLE_CC_COMPATIBLE_PROVIDER", label: "CC Compatible Provider", description: "Enable Claude Code compatible provider mode", descriptionI18nKey: "featureFlagEnableCcCompatibleProviderDescription", category: "network", defaultValue: "false", type: "boolean", requiresRestart: true, warningLevel: "info", }, // ──────────────── Policies (3) ──────────────── { key: "TOOL_POLICY_MODE", label: "Tool Policy Mode", description: "Set the tool use policy enforcement mode", descriptionI18nKey: "featureFlagToolPolicyModeDescription", category: "policies", defaultValue: "disabled", type: "enum", enumValues: ["disabled", "warn", "block"], requiresRestart: false, warningLevel: "info", }, { key: "RATE_LIMIT_AUTO_ENABLE", label: "Rate Limit Auto-Enable", description: "Automatically enable rate limiting based on usage patterns", descriptionI18nKey: "featureFlagRateLimitAutoEnableDescription", category: "policies", defaultValue: "false", type: "boolean", requiresRestart: false, warningLevel: "info", }, { key: "ALLOW_MULTI_CONNECTIONS_PER_COMPAT_NODE", label: "Multi Connections per Compat Node", description: "Allow multiple connections per compatibility node", descriptionI18nKey: "featureFlagAllowMultiConnectionsPerCompatNodeDescription", category: "policies", defaultValue: "false", type: "boolean", requiresRestart: true, warningLevel: "info", }, // ──────────────── Runtime (12) ──────────────── { key: "OMNIROUTE_MCP_ENFORCE_SCOPES", label: "MCP Enforce Scopes", description: "Enforce scope restrictions on MCP tool access", descriptionI18nKey: "featureFlagOmnirouteMcpEnforceScopesDescription", category: "runtime", defaultValue: "true", type: "boolean", requiresRestart: false, warningLevel: "caution", }, { key: "OMNIROUTE_MCP_COMPRESS_DESCRIPTIONS", label: "MCP Compress Descriptions", description: "Compress MCP tool descriptions to reduce token usage", descriptionI18nKey: "featureFlagOmnirouteMcpCompressDescriptionsDescription", category: "runtime", defaultValue: "false", type: "boolean", requiresRestart: false, warningLevel: "info", }, { key: "OMNIROUTE_ENABLE_RUNTIME_BACKGROUND_TASKS", label: "Runtime Background Tasks", description: "Enable background task processing at runtime", descriptionI18nKey: "featureFlagOmnirouteEnableRuntimeBackgroundTasksDescription", category: "runtime", defaultValue: "false", type: "boolean", requiresRestart: false, warningLevel: "info", }, { key: "OMNIROUTE_DISABLE_BACKGROUND_SERVICES", label: "Disable Background Services", description: "Disable all background services (quota refresh, sync, etc)", descriptionI18nKey: "featureFlagOmnirouteDisableBackgroundServicesDescription", category: "runtime", defaultValue: "false", type: "boolean", requiresRestart: true, warningLevel: "caution", }, { key: "OMNIROUTE_RTK_TRUST_PROJECT_FILTERS", label: "RTK Trust Project Filters", description: "Trust project-level filters from RTK without validation", descriptionI18nKey: "featureFlagOmnirouteRtkTrustProjectFiltersDescription", category: "runtime", defaultValue: "false", type: "boolean", requiresRestart: false, warningLevel: "caution", }, { key: "OMNIROUTE_ENABLE_LIVE_WS", label: "Live Dashboard WebSocket", description: "Start the real-time dashboard WebSocket server on import (port 20129, loopback-bound by default). Default: enabled. Set to '0' or 'false' to disable. LAN exposure requires LIVE_WS_HOST=0.0.0.0 + LIVE_WS_ALLOWED_ORIGINS.", descriptionI18nKey: "featureFlagOmnirouteEnableLiveWsDescription", category: "runtime", defaultValue: "true", type: "boolean", requiresRestart: true, warningLevel: "info", }, { key: "OMNIROUTE_CODEX_WS_ENABLED", label: "Codex Responses WebSocket", description: "Allow Codex to use the Responses-over-WebSocket transport (the codex CLI WS endpoint and codexTransport=websocket). When off, Codex falls back to HTTP Responses.", descriptionI18nKey: "featureFlagOmnirouteCodexWsEnabledDescription", category: "runtime", defaultValue: "true", type: "boolean", requiresRestart: false, warningLevel: "info", }, { key: "OMNIROUTE_EMERGENCY_FALLBACK", label: "Emergency Fallback", description: "Route budget-exhausted requests to the emergency free fallback provider/model.", descriptionI18nKey: "featureFlagOmnirouteEmergencyFallbackDescription", category: "runtime", defaultValue: "true", type: "boolean", requiresRestart: false, warningLevel: "caution", }, { key: "STREAM_RECOVERY_ENABLED", label: "Stream Recovery", description: "Enable transparent early retry for truncated upstream SSE streams before any response bytes reach the client.", descriptionI18nKey: "featureFlagStreamRecoveryEnabledDescription", category: "runtime", defaultValue: "false", type: "boolean", requiresRestart: false, warningLevel: "caution", }, { key: "STREAM_RECOVERY_MIDSTREAM_ENABLED", label: "Mid-Stream Continuation", description: "Allow stream recovery to re-request and stitch a response after bytes have already reached the client.", descriptionI18nKey: "featureFlagStreamRecoveryMidstreamEnabledDescription", category: "runtime", defaultValue: "false", type: "boolean", requiresRestart: false, warningLevel: "danger", }, { key: "MODEL_CATALOG_INCLUDE_NAMES", label: "Model Catalog Names", description: "Include display-friendly name fields in /v1/models responses. Disable for clients that expect model IDs only.", descriptionI18nKey: "settings.featureFlags.modelCatalogIncludeNames", category: "runtime", defaultValue: "true", type: "boolean", requiresRestart: false, warningLevel: "info", }, { key: "MODELS_CATALOG_PREFIX_MODE", label: "Models Catalog Prefix Mode", description: "Controls how model IDs are prefixed in /v1/models. 'dual' (default) emits both alias and canonical provider-id prefixes for backward compatibility. 'alias' emits only the short alias prefix (e.g. ds-web/model, not deepseek-web/model). 'canonical' emits only the full provider-id prefix.", descriptionI18nKey: "featureFlagModelsCatalogPrefixModeDescription", category: "runtime", defaultValue: "dual", type: "enum", enumValues: ["dual", "alias", "canonical"], requiresRestart: false, warningLevel: "info", }, { key: "ARENA_ELO_SYNC_ENABLED", label: "Arena ELO Sync", description: "Enable periodic Arena AI leaderboard ELO sync for model intelligence rankings.", descriptionI18nKey: "featureFlagArenaEloSyncEnabledDescription", category: "runtime", defaultValue: "true", type: "boolean", requiresRestart: false, warningLevel: "info", }, // ──────────────── CLI (3) ──────────────── { key: "CLI_COMPAT_ALL", label: "CLI Compat All", description: "Enable compatibility mode for all CLI clients", descriptionI18nKey: "featureFlagCliCompatAllDescription", category: "cli", defaultValue: "false", type: "boolean", requiresRestart: true, warningLevel: "info", }, { key: "MODEL_ALIAS_COMPAT_ENABLED", label: "Model Alias Compat", description: "Enable model alias compatibility layer", descriptionI18nKey: "featureFlagModelAliasCompatEnabledDescription", category: "cli", defaultValue: "false", type: "boolean", requiresRestart: false, warningLevel: "info", }, { key: "PRICING_SYNC_ENABLED", label: "Pricing Sync", description: "Enable automatic pricing data synchronization (requires the PRICING_SYNC_ENABLED environment variable to be set to true)", descriptionI18nKey: "featureFlagPricingSyncEnabledDescription", category: "cli", defaultValue: "false", type: "boolean", requiresRestart: false, warningLevel: "info", }, // ──────────────── Health (3) ──────────────── { key: "OMNIROUTE_DISABLE_LOCAL_HEALTHCHECK", label: "Disable Local Health Check", description: "Disable the local instance health check endpoint", descriptionI18nKey: "featureFlagOmnirouteDisableLocalHealthcheckDescription", category: "health", defaultValue: "false", type: "boolean", requiresRestart: false, warningLevel: "info", }, { key: "OMNIROUTE_DISABLE_TOKEN_HEALTHCHECK", label: "Disable Token Health Check", description: "Disable the token validation health check", descriptionI18nKey: "featureFlagOmnirouteDisableTokenHealthcheckDescription", category: "health", defaultValue: "false", type: "boolean", requiresRestart: false, warningLevel: "info", }, { key: "SKILLS_SANDBOX_NETWORK_ENABLED", label: "Skills Sandbox Network", description: "Enable network access in the skills sandbox environment", descriptionI18nKey: "featureFlagSkillsSandboxNetworkEnabledDescription", category: "health", defaultValue: "false", type: "boolean", requiresRestart: false, warningLevel: "caution", }, ];