Files
OmniRoute/docs/reference/PROVIDER_REFERENCE.md
Diego Rodrigues de Sa e Souza f165efcd0b Release v3.8.28 (#4053)
* chore(release): open v3.8.28 development cycle

* fix(ws): warm SSE auth import on LiveWS startup; relocate boot test to integration (#4063)

The live dashboard WebSocket sidecar lazily import()-ed the SSE auth module
inside the connection handler, only on the API-key path. That cold import pulls
in hundreds of transitive modules and takes ~7s under tsx, blocking the
single-threaded event loop. The first API-key WebSocket connection therefore
stalled the loop long enough that any connection arriving in that window — e.g.
a same-origin cookie client — could not complete its handshake and timed out.

This was deterministic, not an "env flake": the boot test fires an API-key
connection immediately followed by a cookie connection, so the cookie connection
always raced the cold import and timed out (reproduced 3/3 locally and red on
every CI run; proven via instrumented probes — reversing the order or warming
the module first makes both connections open in ~20ms).

Fix:
- Memoize the auth-module import and warm it once at startup (before listen), so
  connection handling never pays the cold-import cost. Real improvement: the
  first API-key client no longer stalls the event loop for concurrent clients.
- Relocate the boot test from tests/unit/cli to tests/integration. It spawns a
  real subprocess + WS server + SQLite (~9-11s); under the unit suite's
  --test-concurrency=20 it contended for CPU and destabilized the shard. The
  serial integration runner is its correct home; it still guards #4004's
  cookie-parse fix on every PR via the integration CI job.
- Bump the test's startup/overall timeouts to absorb the eager auth warm.

Makes `npm run test:unit` deterministically green (the only remaining unit red).

Validated: relocated test 3/3 green via the integration runner (was 3/3 red);
typecheck:core + eslint clean; confirmed it no longer matches the test:unit glob
and does match tests/integration/*.test.ts.

* fix(ws): start LiveWS sidecar with cwd at package root (#4055) (#4064)

* chore(deps): bump ossf/scorecard-action from 2.4.0 to 2.4.3 (#4045)

Integrado em release/v3.8.28. Patch de SHA do ossf/scorecard-action (2.4.0→2.4.3), mantém SHA-pin. Reds de CI são exclusivamente os shards flaky pré-existentes branch-wide (Unit 7/8, Integration, Coverage 7/8, Node 1/2) — não relacionados ao bump (PR deps-only).

* deps: bump electron from 42.4.0 to 42.4.1 in /electron (#4049)

Integrado em release/v3.8.28. Patch do electron (42.4.0→42.4.1). Reds de CI: shards flaky pré-existentes + PR Test Policy = falso-positivo (mudança deps-only sob electron/ não comporta teste de código) + Node 26(2/2) sem step (flake/infra). Precedente #3913/#3914 (electron dependabot mergeado nessas condições).

* fix(auto): resolve built-in auto catalog combos (#4058)

Integrado em release/v3.8.28. Resolve os IDs de catálogo `auto/*` built-in (combos virtuais) — corrige o 400 "No auto combos configured" em auto/best-coding etc. Ajuste de review: os mapas AUTO_TEMPLATE_VARIANTS/VALID_AUTO_VARIANTS duplicados em chat.ts e chatHelpers.ts foram extraídos para open-sse/services/autoCombo/builtinCatalog.ts (DRY), devolvendo chatHelpers.ts <800 LOC; baseline de chat.ts rebaselinado 1432→1458 (lógica nova). Fast QG + semgrep + dast verdes; 22/22 testes.

* chore(docs): update Discord invite link to a non-expiring one (#4067)

* chore(deps): freeze @huggingface/transformers in dependabot (hard-pin) (#4066)

Integrado em release/v3.8.28. Congela @huggingface/transformers no dependabot (pin exato 3.5.2, load-bearing p/ LLMLingua + memory embeddings, VPS-validado #4014). Fast QG + semgrep + dast verdes.

* ci(quality): flip TIA impacted-unit-tests gate from advisory to blocking (#4069)

The pre-existing release unit test-debt that kept the TIA "Impacted unit tests"
step advisory has been cleared:
- #4030 restored 16 lossless Zod/registry reds (from the oyi77 modularize refactors).
- #4063 fixed the last red — the LiveWS boot test — which was a real deterministic
  event-loop stall in the WS sidecar (cold ~7s lazy auth import racing a second
  connection), not an env flake; fixed (warm the import at startup) and relocated to
  the integration suite.

A full workflow_dispatch ci.yml run on release/v3.8.28 then showed all 8 Unit Tests
shards green. The remaining Integration Tests / Quality Ratchet reds are pre-existing
and unrelated (combo/resilience env-flakes; eslint/i18n baseline drift).

Removing continue-on-error makes PR->release block on unit-test regressions in the
TIA-selected impacted set (fail-safe still runs the full unit suite on hub/unmapped
changes). typecheck:core was already blocking. Closes the fast-gates "no tests on
PR->release" hole (Quality Gate v2 / Fase 9, P2).

* docs(compression): document LLMLingua optional deps + on-demand install (#4061)

Integrado em release/v3.8.28. Docs LLMLingua optional deps + on-demand install (F3.1).

* feat(dashboard): Combo Studio connection-cooldown badge (U1b Slice 2) (#4068)

Integrado em release/v3.8.28. Combo Studio connection-cooldown badge (U1b Slice 2 / F5.1).

* feat(compression): record Context Editing telemetry (engine: context-editing) (#4062)

Integrado em release/v3.8.28. Context Editing telemetry (F4.1).

* feat(sse): Context Editing relay coverage + 400-fallback (#4065)

Integrado em release/v3.8.28. Context Editing relay coverage (cc-*) + 400-fallback (F4.2/F4.3). Conflito de file-size-baseline.json (vs #4062) resolvido por união (ambas justificativas + base.ts 1292 + chatCore.ts 5898). Validado local no tree mergeado: typecheck:core ✓, eslint ✓, check:file-size ✓, 4/4 testes ✓; semgrep + semgrep-cloud verdes. Fast QG enfileirado (saturação de runner) — mergeado nos gates de política verificados (precedente #4034/#4020).

* feat(providers): add OrcaRouter (OpenAI-compatible routing gateway) (#4070)

Integrado em release/v3.8.28. Adiciona o provider OrcaRouter (OpenAI-compatible, API-key, DefaultExecutor). Ajuste de review: rebaseline de file-size de providers.ts 3147→3159 (+12 da entrada OrcaRouter). Validado local no tree sincronizado: provider-consistency ✓, docs-counts STRICT 227 ✓, typecheck:core ✓, teste 3/3 ✓, eslint ✓; semgrep + semgrep-cloud verdes. Fast QG/dast enfileirados (saturação de runner) — merge nos gates de política verificados (precedente #4034/#4065).

* test(infra): isolate DATA_DIR per test process; raise Stryker concurrency 1→4 (#4078)

* test(infra): isolate DATA_DIR per test process; raise Stryker concurrency 1→4

Every test process resolved DATA_DIR to the same default (~/.omniroute) when the env
var was unset (src/lib/dataPaths.ts::resolveDataDir), so concurrent test files opened
the SAME on-disk storage.sqlite. node:test spawns a process per file and Stryker spawns
one per sandbox, so this shared file caused cross-file state races:
- SQLite lock contention that hung `npm run test:unit` under high --test-concurrency
  (the ~95-min local hang), and
- the non-deterministic baseline that forced stryker.conf.json to concurrency: 1, which
  in turn could not finish the ~15k-mutant run inside the nightly timeout (the cancelled
  2026-06-16/17 nightly-mutation runs) — blocking Quality Gate v2 / Fase 9 Onda 2.

open-sse/utils/setupPolyfill.ts could NOT host the fix: it is imported by production
(bin/omniroute.mjs, proxyFetch.ts, proxyDispatcher.ts), where redirecting DATA_DIR would
point the live SQLite DB at a throwaway temp dir. So this adds a TEST-ONLY
tests/_setup/isolateDataDir.ts that gives each process its own temp DATA_DIR when none is
set (tests that set DATA_DIR explicitly still win), wired via --import into the test,
mutation and CI invocations.

Verified:
- Stryker dry-run A/B at concurrency=4: FAILS without the isolation import
  (account-fallback-service tap exit 9, a cross-file race) and PASSES with it.
- Full `npm run test:unit` green with isolation (0 fail; a one-off
  chatcore-translation-paths timeout flake did not reproduce and passes 3/3 isolated)
  and noticeably faster — the DB lock contention is gone.
- New tests/unit/isolate-datadir.test.ts guards the contract (unique temp DATA_DIR when
  unset; explicit DATA_DIR respected).

Wired the --import into: package.json (13 test scripts), stryker.conf.json (tap.nodeArgs
+ concurrency 1→4), .github/workflows/quality.yml (TIA step), ci.yml (the 5
unit/coverage/integration commands), and bumped nightly-mutation.yml timeout 120→180 for
the first cold run before the incremental cache is seeded.

* ci(quality): run the TIA gate at CI concurrency (4) to stop oversubscription flakes

The TIA "Impacted unit tests" step (made blocking in #4069) ran its fail-safe via
`npm run test:unit` — concurrency=20, tuned for multi-core dev machines. On a 4-vCPU CI
runner that is 5x oversubscribed, so timing-sensitive tests flake under the load (e.g.
`db-backup-extended` "The database connection is not open", `chatcore-translation-paths`
upstream-timeout). That intermittently fails a blocking gate on legitimate PRs — exactly
what surfaced on the DATA_DIR-isolation PR, whose package.json/workflow changes trip the
__RUN_ALL__ fail-safe.

Run both the impacted set and the fail-safe at --test-concurrency=4, matching the stable
ci.yml unit job. Adds a `test:unit:ci` script (test:unit at concurrency=4). The DATA_DIR
isolation in this PR keeps the parallel run race-free, so the only change here is matching
the runner's core count. Verified locally: db-backup-extended passes 8/8 in isolation
(5 with isolation, 3 without).

* docs(quality-gates): reconcile gate inventory with ci.yml + add ROI rationalization backlog (#4095)

The "authoritative" gate inventory in QUALITY_GATES.md had drifted from ci.yml: it omitted
9 wired gates — `audit:deps`, `check:tracked-artifacts`, `check:lockfile`, `check:licenses`
(lint job), `check:dead-code`, `check:cognitive-complexity`, `check:type-coverage`,
`check:codeql-ratchet` (quality-gate job), and `check:pr-evidence` (pr-test-policy job).
You can't rationalize an inventory you can't trust, so this reconciles it first.

Adds those 9 rows to their job tables and a "Rationalization Backlog (ROI review)" section
capturing the Fase 9 Onda 3 findings: mechanical merge/dedup candidates (CVE scanners
audit:deps↔osv, the two complexity ESLint passes, cycles↔circular-deps, the two /api
anti-hallucination gates, the doubly-run check:docs-sync, check:node-runtime ×11) and the
operator-only flip/drop decisions (typecheck:noimplicit vs the type-coverage ratchet,
test:vitest:ui parked fails, check:secrets frozen FPs, openapi-security-tiers, pr-evidence,
the orphaned semgrep baseline). Also flags the undocumented advisory docs-lint job and the
standalone scanner workflows.

Docs-only — no gate behavior changes. The merges (CI changes) and flips (policy) are
deferred to operator-scoped follow-ups; this PR only makes the map accurate.

* test(dashboard): smoke e2e for the Combo Live Studio page (#4075)

Integrated into release/v3.8.28

* fix(sse): friendly 413 message for ChatGPT web payload-too-large (#4080)

Integrated into release/v3.8.28

* feat(sse): port Claude Code quota-probe bypass + command meta-request helpers (#4083)

Integrated into release/v3.8.28

* feat(api): exact offline token counting for count_tokens fallback via tiktoken (#4087)

Integrated into release/v3.8.28

* feat(compression): RTK learn/discover (sample source + API + UI) (#4088)

Integrated into release/v3.8.28

* feat(dashboard): 2026-06-17 free-tier refresh — honest catalog, uncapped + boost tiers, Layout A budget table (#4089)

Integrated into release/v3.8.28

* feat(mitm): capture-pipeline self-test route (Gap 12) (#4093)

Integrated into release/v3.8.28

* fix(mitm): crash-safe system-state teardown + socket timeouts (ProxyBridge-inspired hardening) (#4084)

Integrated into release/v3.8.28 (Fast QG TIA red = 3 pre-existing timing flakes verified passing locally 82/82; PR own tests green)

* feat(mitm): attribute intercepted requests to originating process (Gap 1) (#4085)

Integrated into release/v3.8.28 (Fast QG TIA red = 3 pre-existing timing flakes verified passing locally 82/82; PR own tests green)

* fix(sse): route image requests only to confirmed-vision combo targets (#4071)

Integrated into release/v3.8.28

* fix(security): injection guard respects INJECTION_GUARD_MODE DB feature flag (#4077)

Integrated into release/v3.8.28

* fix(ws): proxy LAN /live-ws upgrades and add unset JWT_SECRET warning (#4079)

Integrated into release/v3.8.28

* fix(dev): force webpack in custom dev server (Turbopack 16.2.x panics) (#4092)

Integrated into release/v3.8.28

* ci(quality): dedup the doubly-run check:docs-sync + record validated ROI backlog (#4099)

Onda 3 (gate ROI-review) Phase 2. Two parts, both low-risk:

1. Remove the standalone `check:docs-sync` from the `lint` job — it already runs in the
   `docs-sync-strict` job (via `check:docs-all`) and the husky pre-commit hook, so the
   `lint`-job copy was a pure duplicate. No coverage lost.

2. Update the Rationalization Backlog in QUALITY_GATES.md with trust-but-verify findings:
   several "obvious" merges/flips from the ROI review turned out to hide debt and are NOT
   clean drop-ins —
   - CVE merge (audit:deps→osv): different semantics (hard high/critical vs regression-ratchet) — keep both.
   - cycles→circular-deps: dpdm reports 91 cycles (can't promote to blocking) and is broader-scope than the green curated check:cycles — keep both.
   - openapi-security-tiers flip: blocked by traffic-inspector routes missing the x-loopback-only annotation.
   - complexity + /api merges: valid but real config/script surgery — deferred.
   - node-runtime ×11: ~10s savings vs a cheap guard — low ROI, skip.

   The remaining flips (typecheck:noimplicit, test:vitest:ui, check:secrets, pr-evidence,
   semgrep) are operator policy decisions, left for the owner.

* chore(deps): bump actions/github-script from 7 to 9 (#4046)

Integrated into release/v3.8.28 (dependabot GH-Action bump; SHA-pin preserved)

* chore(deps): bump actions/setup-node from 4 to 6 (#4048)

Integrated into release/v3.8.28 (dependabot GH-Action bump; SHA-pin preserved)

* chore(deps): bump actions/upload-artifact from 4 to 7 (#4044)

Integrated into release/v3.8.28 (dependabot GH-Action bump; SHA-pin preserved)

* chore(deps): bump actions/cache from 4.3.0 to 5.0.5 (#4047)

Integrated into release/v3.8.28 (dependabot GH-Action bump; SHA-pin preserved)

* deps: bump the development group with 10 updates (#4051)

Integrated into release/v3.8.28 (dependabot dev group; cyclonedx 4->5 verified compatible with the SBOM invocation --ignore-npm-errors/--output-format JSON/--output-file)

* fix(dashboard): event-driven fail-open auto-refresh for embedded log views (#4054) (#4103)

The Request Logger gated each auto-refresh tick on a static
document.visibilityState === "visible" read. Hosts that report a permanent
non-"visible" state without ever firing a visibilitychange event (Docker
dashboard wrappers, embedded/proxied webviews) froze auto-refresh entirely —
only the manual Refresh button worked, a regression from 3.8.24's unconditional
polling.

The pause is now event-driven and fail-open: visibleRef starts true and is only
flipped to false on a real visibilitychange → hidden transition, so a host that
never signals a genuine background transition keeps polling, while normal
browser tabs still pause when actually backgrounded.

Regression test reproduces the misreporting-host case (RED) and the perf guard
is re-encoded under the event-driven semantics.

* fix(docker): raise build-stage Node heap to stop production-build OOM (#4076) (#4104)

The Docker builder stage ran `npm run build` with V8's default heap ceiling
(~2 GB). After #4052 forced the heavier webpack engine (Turbopack panics on this
Next.js version), the production optimization pass exceeded that ceiling and the
build died with "FATAL ERROR: ... JavaScript heap out of memory" at
[builder] npm run build.

The builder stage now sets NODE_OPTIONS=--max-old-space-size (default 4096 MB,
overridable via --build-arg OMNIROUTE_BUILD_MEMORY_MB) before the build; the
value propagates to the spawned next build (resolveNextBuildEnv spreads
process.env). Build-only — the runtime heap on the runner stage is unchanged,
and CI/local builds (which invoke npm run build directly) are unaffected.

Regression guard: tests/unit/dockerfile-build-heap-4076.test.ts asserts the
builder stage sets the heap ceiling, before npm run build, at >= 4096 MB.

* feat(agent-bridge): portable JSON import/export of config (Gap 4) (#4094)

Integrated into release/v3.8.28

* feat(cli): add 'omniroute launch' zero-config Claude Code launcher (#4097)

Integrated into release/v3.8.28 (Fast QG TIA red = pre-existing env-doc-contract drift [MITM_IDLE_TIMEOUT_MS/TURBOPACK from #4084/#4092] + opencode-plugin-dist env flake; #4097 own test 3/3 green)

* feat(mitm): loop-guard self-check + verbosity control in server.cjs (Gaps 14+15) (#4101)

Integrated into release/v3.8.28 (rebased onto release — dropped the already-squash-merged #4084 commits; only the Gaps 14+15 loop-guard/verbosity delta remains)

* feat(sse): generic 400 field-downgrade retry + Groq field stripping (#4096)

Integrated into release/v3.8.28

* feat(providers): add Wafer AI (Anthropic-compatible, Bearer auth) (#4098)

Integrated into release/v3.8.28

* chore(docs)

* fix(responses): clear /v1/responses keepalive timer on cancel/abort (timer + CPU leak) (#4105)

Integrated into release/v3.8.28 (r7).

* perf(gemini): cache reasoning close-tag regex instead of recompiling per token (#4106)

Integrated into release/v3.8.28 (r7).

* fix(usage): reap orphaned pending-request details (unbounded memory leak) (#4107)

Integrated into release/v3.8.28 (r7).

* perf(stream): use structuredClone instead of JSON round-trip for per-chunk reasoning split (#4108)

Integrated into release/v3.8.28 (r7).

* fix(dashboard): restore Update Available banner with npm-binary-free version fallback (#4100) (#4112)

getLatestNpmVersion() derived the latest version only from the npm CLI binary and returned null on any error, so Docker/desktop/locked-down installs without npm on PATH silently hid the home banner even when an update existed. Add resolveLatestVersion() (npm CLI -> registry HTTP fallback -> logged warning) and harden version parsing for v-prefix/pre-release strings. Extracted into testable src/lib/system/versionCheck.ts with TDD coverage.

* fix(auth): prune expired entries from login brute-force guard map (unbounded growth) (#4111)

Integrated into release/v3.8.28 (r8)

* fix(logger): hard-cap the error-dedup map to bound memory under unique-message bursts (#4113)

Integrated into release/v3.8.28 (r8)

* fix(circuit-breaker): enforce MAX_REGISTRY_SIZE (declared but never applied) (#4114)

Integrated into release/v3.8.28 (r8)

* perf(obfuscation): cache per-word regexes instead of recompiling every request (#4109)

Integrated into release/v3.8.28 (r8)

* perf(registry): precompute model->provider index in parseModelFromRegistry (#4110)

Integrated into release/v3.8.28 (r8)

* fix(timers): unref background interval timers so they don't block clean shutdown (#4117)

Integrated into release/v3.8.28 (r8)

* fix(webhook): clear abort timer in finally to avoid dangling timers on fetch error (#4115)

Integrated into release/v3.8.28 (r8)

* fix(combo): detach per-target listener from shared hedge abort signal (#4116)

Integrated into release/v3.8.28 (r8)

* chore(release): finalize v3.8.28 CHANGELOG + reconcile env-doc contract

- Build the complete [3.8.28] CHANGELOG section (55 bullets) covering every
  commit since v3.8.27, grouped by type with PR back-references and human
  contributor attribution (artickc's memory-leak/perf cluster, OrcaRouter,
  Wafer AI, MITM gaps, etc.); move the OrcaRouter bullet out of [Unreleased].
- Inject the EN [3.8.28] section into all 41 i18n CHANGELOG mirrors (parity).
- Reconcile the env/docs contract: document MITM_IDLE_TIMEOUT_MS + MITM_VERBOSE
  in .env.example and ENVIRONMENT.md; allowlist the framework-internal TURBOPACK
  and the Claude Code ANTHROPIC_AUTH_TOKEN in check-env-doc-sync.
- Fix 3 broken relative links in docs/providers/AGENTROUTER.md (regressed when
  the file was relocated this cycle) so docs-sync-strict passes.

* fix(quality): treat test→test renames as relocations, not deletions

The anti-test-masking gate's subcheck-1 collected deleted AND renamed test
files via `--diff-filter=DR --name-only` and flagged every one as "deleted —
human review required", contradicting its own documented contract ("DELETADOS
ou renomeados-e-NÃO-substituídos"): a rename test→test IS a substitution (the
test moved, coverage preserved). This false-positived on #4063's legitimate
relocation of live-ws-startup.test.ts (unit/cli → integration, asserts 2→2)
and would block every PR that relocates a test — surfacing only at release-day
because the Fast QG (PR→release) doesn't run test-masking.

The gate now parses `--name-status -M`: true deletions and test→non-test
renames still flag; a test→test rename is run through the assert-reduction
check across the move, so a clean relocation passes while gutting-via-rename
(dropped asserts / new tautologies / skips) still fires. Adds
partitionDeletedRenamed + 6 regression tests.

---------

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Demiurge The Single <megamen932@gmail.com>
Co-authored-by: jinhaosong-source <jinhao.song@myflashcloud.com>
Co-authored-by: diego-anselmo <contato@diegoanselmo.com.br>
Co-authored-by: Felipe Almeman <4226997+zhiru@users.noreply.github.com>
Co-authored-by: Rahul sharma <sharmaR0810@gmail.com>
Co-authored-by: Chirag Singhal <76880977+chirag127@users.noreply.github.com>
Co-authored-by: NOXX - Commiter <artur1992123@mail.ru>
2026-06-17 19:26:32 -03:00

96 KiB
Raw Blame History

title, version, lastUpdated
title version lastUpdated
Provider Reference 3.8.27 2026-06-17

Provider Reference

Auto-generated from src/shared/constants/providers.ts — do not edit by hand. Regenerate with: npm run gen:provider-reference Last generated: 2026-06-17

Total providers: 227. See category breakdown below.

Categories

  • Free — free tier with API key (configured via dashboard)
  • OAuth — sign-in flow handled by OmniRoute, no API key needed
  • Web cookie — wraps the provider's web app via cookie auth
  • API key — paid provider configured via API key (free credits may apply)
  • Local — runs on the user's machine (Ollama, LM Studio, vLLM, etc.)
  • Search — web search providers
  • Audio — audio-only providers (TTS/STT)
  • Upstream proxy — providers that proxy to other providers
  • Cloud agent — long-running coding agents (Codex Cloud, Devin, Jules)
  • System — OmniRoute-internal providers (loopback, etc.)

Additional tags: image, video, aggregator, enterprise, embed/rerank, self-hosted.

Use the dashboard at /dashboard/providers to enable, configure, and test each provider.


OAuth Providers (19)

ID Alias Name Tags Website Notes
agy agy Antigravity CLI OAuth link Import your Antigravity CLI (agy) login (paste/upload its token file), auto-detect a local CLI login, or sign in with Google. Shares the Antigravity backend (incl. Claude models).
amazon-q aq Amazon Q OAuth link Uses the same AWS Builder ID or imported refresh-token flow as Kiro, but keeps Amazon Q connections separate.
antigravity Antigravity OAuth
claude cc Claude Code OAuth
cline cl Cline OAuth
codex cx OpenAI Codex OAuth
cursor cu Cursor IDE OAuth
devin-cli dv Devin CLI (Official) OAuth link Requires the Devin CLI binary. Run devin auth login to authenticate, or provide your WINDSURF_API_KEY. Install: https://cli.devin.ai
gemini-cli gemini-cli Gemini CLI OAuth Uses Gemini CLI OAuth / Cloud Code credentials. Pro models require an eligible Google account or paid plan.
github gh GitHub Copilot OAuth
gitlab-duo gitlab-duo GitLab Duo OAuth link OAuth application with ai_features + read_user scopes. Configure GITLAB_DUO_OAUTH_CLIENT_ID and optionally GITLAB_DUO_OAUTH_CLIENT_SECRET on this OmniRoute instance.
kilocode kc Kilo Code OAuth
kimi-coding kmc Kimi Coding OAuth
kiro kr Kiro AI OAuth Free tier: 50 credits/month (~25K100K tokens). ⚠️ Kiro ToS prohibits third-party proxy/harness use.
qoder if Qoder AI OAuth
qwen qw Qwen Code OAuth ⚠️ DEPRECATED. Qwen OAuth free tier was discontinued on 2026-04-15. Use 'bailian-coding-plan', 'alibaba', 'alibaba-cn', or 'openrouter' provider with API key instead.
trae tr Trae OAuth link Trae is an AI-native IDE by ByteDance (SOLO remote agent). Authorize via trae.ai in the popup, or sign in at solo.trae.ai and paste the Cloud-IDE-JWT (sent as 'Authorization: Cloud-IDE-JWT ', ~14-day lifetime) as the access token; web_id/biz_user_id/user_unique_id/scope/tenant/region propagate via providerSpecificData. No headless refresh for pasted tokens — re-paste on expiry.
windsurf ws Windsurf (Devin CLI) OAuth link In the Windsurf / VS Code IDE, open the command palette and run Windsurf: Provide Auth Token (or click the Jupyter "Get Windsurf Authentication Token" button), then copy the shown token and paste it here. Note: opening windsurf.com/show-auth-token directly only renders a "Redirecting" page — the IDE must initiate the flow (it adds a ?state=... param) for the token to appear.
zed zd Zed IDE OAuth link Zed stores LLM provider credentials (OpenAI, Anthropic, Google, Mistral, xAI) in the OS keychain. Use the Import button below to discover and import them automatically.
ID Alias Name Tags Website Notes
adapta-web adp-web Adapta.org (Adapta One Web) Web cookie link Paste your __client cookie value from .clerk.agent.adapta.one (DevTools → Application → Cookies)
blackbox-web bb-web Blackbox Web (Subscription) Web cookie link Paste your __Secure-authjs.session-token value or full cookie header from app.blackbox.ai
chatgpt-web cgpt-web ChatGPT Web (Plus/Pro) Web cookie link Paste your __Secure-next-auth.session-token cookie value from chatgpt.com
claude-web cw Claude Web Web cookie link Paste your session cookie from claude.ai
copilot-web copilot Microsoft Copilot Web Web cookie link Paste your access_token from copilot.microsoft.com (or export a .har file from DevTools while logged in)
deepseek-web ds-web DeepSeek Web Web cookie link Paste your userToken from chat.deepseek.com — DevTools → Application → Local Storage → userToken
doubao-web db Doubao Web (ByteDance) Web cookie link Paste your session cookie from doubao.com (DevTools → Application → Cookies)
gemini-business gembiz Gemini Business (Enterprise) Web cookie link From your enterprise account: open business.gemini.google/home/cid/{your-cid}, then copy **Secure-1PSID and **Secure-1PSIDTS cookies from DevTools → Application → Cookies. Paste as a cookie header below.
gemini-web gweb Gemini Web (Free) Web cookie link Paste your **Secure-1PSID cookie value from gemini.google.com. Optionally add **Secure-1PSIDTS separated by semicolon.
grok-web gw Grok Web (Subscription) Web cookie link Paste the full grok.com cookie line from DevTools → Application → Cookies. Include both sso and sso-rw (e.g. sso=...; sso-rw=...) — Grok's anti-bot rejects sso on its own.
huggingchat huggingchat HuggingChat (Free) Web cookie link Paste your hf-chat cookie value from huggingface.co/chat (DevTools → Application → Cookies → hf-chat). Optional — works without auth for basic use.
inner-ai in-ai Inner.ai (Subscription) Web cookie link Paste your token cookie and email separated by a space: open DevTools → Application → Cookies → .innerai.com, copy the token value, then append a space and your Inner.ai login email. Example: eyJhbG... user@example.com
kimi-web kimi-web Kimi Web (Moonshot AI) Web cookie link Paste your session cookie from kimi.moonshot.cn (DevTools → Application → Cookies)
lmarena lma LMArena (Free) Web cookie link Paste your session cookie from lmarena.ai (DevTools → Application → Cookies). Optional — works with free tier for basic comparisons.
muse-spark-web ms-web Muse Spark Web (Meta AI) Web cookie link Paste your abra_sess value or full cookie header from meta.ai
perplexity-web pplx-web Perplexity Web (Pro/Max) Web cookie link Paste your __Secure-next-auth.session-token cookie value from perplexity.ai
phind ph Phind (Free) Web cookie link Paste your session cookie from phind.com (DevTools → Application → Cookies). Optional — works with free tier.
poe-web poe Poe Web (Subscription) Web cookie link Paste your p-b cookie value from poe.com (DevTools → Application → Cookies → p-b)
qwen-web qwen-web Qwen Web (Free) Web cookie link Open chat.qwen.ai, log in, then open DevTools → Application → Local Storage → copy the "token" value (or use tongyi_sso_ticket cookie as Bearer token).
t3-web t3chat t3.chat (Pro/Free) Web cookie link Open t3.chat in your browser, log in, then open DevTools → Application → Local Storage → https://t3.chat. Copy the value of 'convex-session-id'. Also open DevTools → Network, copy the Cookie header from any request. Paste both values here. See provider setup docs for a step-by-step guide.
v0-vercel-web v0 v0 Vercel Web (Code Gen) Web cookie link Paste your session cookie from v0.dev (DevTools → Application → Cookies)
venice-web ven Venice Web (Privacy) Web cookie link Paste your session cookie from venice.ai (DevTools → Application → Cookies)

API Key Providers (paid / paid-with-free-credits) (153)

ID Alias Name Tags Website Notes
360ai 360ai 360 AI API key link Get API key at ai.360.cn
agentrouter agentrouter AgentRouter API key, aggregator link $200 free credits on signup - multi-model routing gateway
ai21 ai21 AI21 Labs API key link $10 trial credits on signup (valid 3 months), no credit card required
aimlapi aiml AI/ML API API key, aggregator link $0.025/day free credits — 200+ models (GPT-4o, Claude, Gemini, Llama) via single endpoint
alibaba ali Alibaba API key link
alibaba-cn ali-cn Alibaba (China) API key link
anthropic anthropic Anthropic API key link
api-airforce af Api.airforce API key link 55 free tier models including Grok-3, Claude 3.7, Qwen3, Kimi-K2, Gemini 2.5 Flash, DeepSeek-V3
arcee-ai arcee Arcee AI API key link Get API key at arcee.ai
azure-ai azure-ai Azure AI Foundry API key, enterprise link Use your Azure AI Foundry key. Base URL can be https://.services.ai.azure.com/openai/v1/ or https://.openai.azure.com/openai/v1/.
azure-openai azure Azure OpenAI API key, enterprise link Use your Azure OpenAI API key. Base URL should be your resource endpoint, for example https://my-resource.openai.azure.com.
baichuan baichuan Baichuan API key link Get API key at platform.baichuan-ai.com
baidu baidu Baidu (ERNIE) API key link Get API key at console.bce.baidu.com
bailian-coding-plan bcp Alibaba Coding Plan API key link
baseten baseten Baseten API key link $30 free trial credits for GPU inference
bazaarlink bzl BazaarLink API key link Free tier with auto:free routing — zero-cost inference, no credit card required
bedrock bedrock Amazon Bedrock API key, enterprise link Use your Amazon Bedrock API key and configure the AWS region where your models are enabled (for example eu-west-2). OmniRoute calls Bedrock's native Converse API directly.
black-forest-labs bfl Black Forest Labs API key, image link
blackbox bb Blackbox AI API key link Free tier: unlimited basic chat plus Minimax-M2.5, no credit card required
bluesminds bm BluesMinds API key link Free daily pi credits — supports 200+ models including GPT-4o, GPT-4.1, Claude Sonnet 4.5, Gemini 2.0 Flash, DeepSeek V4, Qwen, Kimi K2
byteplus bpm BytePlus ModelArk API key link
bytez bytez Bytez API key link $1 free credits, refreshes every 4 weeks
cablyai cablyai CablyAI API key, aggregator link Bearer API key for the CablyAI OpenAI-compatible gateway.
cerebras cerebras Cerebras API key link Free Trial: 1M tokens/day, 30K TPM, 5 RPM — no credit card.
chutes chutes Chutes.ai API key, aggregator link Bearer API key for the Chutes OpenAI-compatible gateway.
clarifai clarifai Clarifai API key, enterprise link Use your Clarifai PAT or app-specific API key. OmniRoute targets the OpenAI-compatible endpoint at https://api.clarifai.com/v2/ext/openai/v1 and authenticates with Authorization: Key .
cloudflare-ai cf Cloudflare Workers AI API key link Requires API Token AND Account ID (found at dash.cloudflare.com)
codestral codestral Codestral API key link
cohere cohere Cohere API key link Free Trial: 1,000 API calls/month for testing, no credit card required
command-code cmd Command Code API key link Use a Command Code API key. Requests are sent to Command Code's /alpha/generate endpoint.
coze coze Coze API key link Get API key at coze.com/open/api
crof crof CrofAI API key link
databricks databricks Databricks API key, enterprise link
datarobot datarobot DataRobot API key, enterprise link Use your DataRobot API token. Optional Base URL can be the account root (for LLM Gateway) or a deployment URL under /api/v2/deployments/.
deepinfra deepinfra DeepInfra API key link Free signup credits for API testing and model exploration
deepseek ds DeepSeek API key link 5M free tokens on signup - no credit card required
dify dify Dify API key link Get API key from your Dify instance.
doubao doubao Doubao API key link Get API key at console.volcengine.com
empower empower Empower API key, aggregator link Bearer API key for the Empower OpenAI-compatible endpoint.
fal-ai fal Fal.ai API key, image link
featherless-ai featherless Featherless AI API key link Free tier available — no credit card required
fenayai fenayai FenayAI API key, aggregator link Bearer API key for the FenayAI OpenAI-compatible gateway.
firecrawl fc Firecrawl API key link
fireworks fireworks Fireworks AI API key link $1 free starter credits on signup for API testing
freeaiapikey faik FreeAIAPIKey API key link
freemodel-dev fmd FreeModel.dev API key link $300 free credits on signup — no credit card required. Access GPT-5.4 and GPT-5.5 (OpenAI's latest flagship models) through an OpenAI-compatible API.
friendliai friendli FriendliAI API key link Free tier for serverless inference — no credit card required
galadriel galadriel Galadriel API key link
gemini gemini Gemini (Google AI Studio) API key link Free forever: 1,500 req/day for Gemini 2.5 Flash — no credit card, get key at aistudio.google.com
getgoapi ggo GoAPI API key, aggregator link
gigachat gigachat GigaChat (Sber) API key link
github-models ghm GitHub Models API key link Create a GitHub PAT with 'models: read' scope at github.com/settings/tokens
gitlab gitlab GitLab Duo PAT API key link GitLab personal access token for the public Code Suggestions API. Configure a self-hosted base URL when not using gitlab.com.
gitlawb glb Gitlawb Opengateway (MiMo) API key link Free tier available — no credit card required
gitlawb-gmi glb-gmi Gitlawb Opengateway (GMI Cloud) API key link Free tier available — no credit card required
glhf glhf GLHF Chat API key, aggregator link Bearer API key for the GLHF OpenAI-compatible gateway.
glm glm GLM Coding API key link
glm-cn glmcn GLM Coding (China) API key link
glmt glmt GLM Thinking API key link
groq groq Groq API key link Free tier: 30 RPM / 14.4K RPD — no credit card
hackclub hc Hackclub AI API key, aggregator link Sign in with your Hack Club account at ai.hackclub.com.
haiper hp Haiper API key, video link Get API key at haiper.ai/haiper-api
heroku heroku Heroku AI API key, enterprise link
huggingchat huggingchat HuggingChat API key link No API key required for basic access.
huggingface hf HuggingFace API key link Free Inference API for thousands of models (Whisper, VITS, SDXL…)
hyperbolic hyp Hyperbolic API key link $1-5 trial credits on signup for serverless inference
ideogram ideo Ideogram API key link Get API key at ideogram.ai/docs/api
iflytek iflytek iFlytek Spark API key link Get API key at console.xfyun.cn
inclusionai inclusion InclusionAI API key link Get API key at inclusionai.com
inference-net inet Inference.net API key link $25 free credits on signup plus research grants available
jina-ai jina Jina AI API key, embed/rerank link Bearer API key for the Jina AI rerank API.
jina-reader jr Jina Reader API key link
kie kie KIE.AI API key link
kilo-gateway kg Kilo Gateway API key, aggregator link
kimi kimi Kimi API key link
kimi-coding-apikey kmca Kimi Coding (API Key) API key link
kluster kluster Kluster AI API key link $5 free credits on signup - DeepSeek R1, Llama 4 Maverick/Scout, Qwen3 235B
lambda-ai lambda Lambda AI API key link
laozhang lz LaoZhang AI API key, aggregator link
leonardo leo Leonardo AI API key, video link Get API key at leonardo.ai/developer
liquid liquid Liquid AI API key link Get API key at liquid.ai
llamagate llamagate LlamaGate API key link
llm7 llm7 LLM7.io API key link No signup required - 2 req/s, 20 RPM, 100 req/hr free tier
longcat lc LongCat AI API key link Free: 5M tokens/day on LongCat-2.0-Preview (Flash models retired 2026-05-29); up to 120M/day via feedback.
maritalk maritalk Maritalk API key link
meta-llama meta Meta Llama API API key link
minimax minimax Minimax Coding API key, video link
minimax-cn minimax-cn Minimax (China) API key link
mistral mistral Mistral API key link Free Experiment tier: rate-limited access to all models, no credit card required
modal mdl Modal API key, enterprise link Use the bearer token that protects your Modal deployment, if enabled. Base URL should point to your OpenAI-compatible Modal app, for example https://--.modal.run/v1.
monsterapi monster MonsterAPI API key link Get API key at monsterapi.ai
moonshot moonshot Moonshot AI API key link
morph morph Morph API key link Free tier: 250K credits/month, $0
nanogpt nanogpt NanoGPT API key link
nebius nebius Nebius AI API key link ~$1 trial credits on signup for API testing
nlpcloud nlpc NLP Cloud API key link Use your NLP Cloud API key in Authorization: Token . OmniRoute targets the chatbot endpoint on https://api.nlpcloud.io/v1/gpu//chatbot by default.
nomic nomic Nomic API key link Get API key at atlas.nomic.ai
nous-research nous Nous Research API key link Use your Nous Portal API key. OmniRoute targets the official OpenAI-compatible inference endpoint at https://inference-api.nousresearch.com/v1.
novita novita Novita AI API key, aggregator link $0.50 trial credits on signup (valid about 1 year)
nscale nscale nScale API key link $5 free credits on signup for inference testing
nvidia nvidia NVIDIA NIM API key link Free dev access: ~40 RPM, 70+ models (Kimi K2.5, GLM 4.7, DeepSeek V3.2...)
oci oci OCI Generative AI API key, enterprise link Use your OCI Generative AI API key or IAM bearer token. Base URL can be https://inference.generativeai..oci.oraclecloud.com/openai/v1/.
ollama-cloud ollamacloud Ollama Cloud API key link
openai openai OpenAI API key link
opencode-go opencode-go OpenCode Go API key link
opencode-zen opencode-zen OpenCode Zen API key link
openrouter openrouter OpenRouter API key, aggregator link Free models at $0/token with :free suffix - 20 RPM / 200 RPD
orcarouter orcarouter OrcaRouter API key link
ovhcloud ovh OVHcloud AI API key link
perplexity pplx Perplexity API key link
phind phind Phind API key link Get API key at phind.com
piapi pi PiAPI API key, aggregator link
poe poe Poe API key, aggregator link Bearer API key for the Poe OpenAI-compatible API.
pollinations pol Pollinations AI API key, video link No API key required for free public endpoint. Optional Spore tier: ~0.01 pollen/hour.
predibase predibase Predibase API key link $25 free trial credits (30-day validity)
publicai publicai PublicAI API key link Requires an API key — one-time signup credit, then paid
puter pu Puter AI API key link Get token at puter.com/dashboard → Copy Auth Token
qianfan qianfan Baidu Qianfan API key link
recraft recraft Recraft API key, image link
reka reka Reka API key link Use your Reka API key. OmniRoute supports the OpenAI-compatible base URL https://api.reka.ai/v1 and sends both Authorization and X-Api-Key headers for compatibility.
runwayml runway Runway API key, video link Use your Runway API key in Authorization: Bearer . OmniRoute targets the current Runway API at https://api.dev.runwayml.com/v1 and sends the required X-Runway-Version header automatically.
sambanova samba SambaNova API key link $5 free credits on signup (30-day validity), no credit card required
sap sap SAP Generative AI Hub API key, enterprise link Use your SAP AI Core bearer token. Base URL can be your AI_API_URL root or a deploymentUrl from Generative AI Hub.
scaleway scw Scaleway AI API key link 1M free tokens for new accounts — EU/GDPR compliant (Paris), Qwen3 235B & Llama 70B
sensenova sensenova SenseNova API key link Get API key at platform.sensenova.cn
siliconflow siliconflow SiliconFlow API key link $1 free credits plus permanently free models after identity verification
snowflake snowflake Snowflake Cortex API key, enterprise link
sparkdesk sparkdesk SparkDesk API key link Get API key at console.xfyun.cn
stability-ai stability Stability AI API key, image link
stepfun stepfun StepFun API key link Get API key at platform.stepfun.com
suno suno Suno API key link Paste session cookie from suno.ai (Clerk auth)
synthetic synthetic Synthetic API key, aggregator link
tencent tencent Tencent Hunyuan API key link Get API key at console.cloud.tencent.com
thebai thebai TheB.AI API key, aggregator link Bearer API key for the TheB.AI OpenAI-compatible gateway.
together together Together AI API key, video link $25 signup credits + 3 permanently free models: Llama 3.3 70B, Vision, DeepSeek-R1 distill
topaz topaz Topaz API key, image link
udio udio Udio API key link Paste session cookie from udio.com (Supabase auth)
uncloseai unc UncloseAI API key link No auth required. API accepts any non-empty string as key for identification.
upstage upstage Upstage API key link
v0-vercel v0 v0 (Vercel) API key link
venice venice Venice.ai API key link
vercel-ai-gateway vag Vercel AI Gateway API key, aggregator link
vertex vertex Vertex AI API key, enterprise link Provide Service Account JSON or OAuth access_token
vertex-partner vp Vertex AI Partners API key, enterprise link Provide the same Service Account JSON used for Vertex AI partner models.
volcengine volcengine Volcengine API key link
voyage-ai voyage Voyage AI API key, embed/rerank link Bearer API key for Voyage AI embeddings and rerank APIs.
wandb wandb Weights & Biases Inference API key link
watsonx watsonx IBM watsonx.ai Gateway API key, enterprise link Use your watsonx bearer token. Base URL can be https://.ml.cloud.ibm.com/ml/gateway/v1/ or a self-managed /ml/gateway/v1 endpoint.
xai xai xAI (Grok) API key link
xiaomi-mimo mimo Xiaomi MiMo API key link
yi yi Yi (01.AI) API key link Get API key at platform.lingyiwanwu.com
zai zai Z.AI API key link
zenmux zm ZenMux API key link Use your ZenMux API key in Authorization: Bearer . ZenMux is fully OpenAI-compatible. Base URL: https://zenmux.ai/api/v1.

Local Providers (11)

ID Alias Name Tags Website Notes
comfyui comfyui ComfyUI Local link No API key required. Configure the local ComfyUI base URL (default: http://localhost:8188).
docker-model-runner dmr Docker Model Runner Local, self-hosted link API key optional. Configure the local Docker Model Runner OpenAI-compatible base URL (default: http://localhost:12434/v1).
lemonade lemonade Lemonade Server Local, self-hosted link API key optional. Configure the local Lemonade OpenAI-compatible base URL (default: http://localhost:13305/api/v1).
llama-cpp llamacpp llama.cpp Local, self-hosted link API key optional (use any value, e.g. sk-no-key-required). Configure the llama-server OpenAI-compatible base URL (default: http://127.0.0.1:8080/v1). Note: if Llamafile is also installed, both default to port 8080 — run only one at a time or override the port.
llamafile llamafile Llamafile Local, self-hosted link API key optional. Configure the local Llamafile OpenAI-compatible base URL (default: http://127.0.0.1:8080/v1).
lm-studio lmstudio LM Studio Local, self-hosted link API key optional. Configure the local LM Studio OpenAI-compatible base URL (default: http://localhost:1234/v1).
oobabooga ooba oobabooga Local, self-hosted link API key optional. Configure the local oobabooga OpenAI-compatible base URL (default: http://localhost:5000/v1).
sdwebui sdwebui SD WebUI Local link No API key required. Configure the local WebUI base URL (default: http://localhost:7860).
triton triton NVIDIA Triton Local, self-hosted link API key optional. Configure the Triton OpenAI-compatible base URL (default: http://localhost:8000/v1).
vllm vllm vLLM Local, self-hosted link API key optional. Configure the local vLLM OpenAI-compatible base URL (default: http://localhost:8000/v1).
xinference xinference XInference Local, self-hosted link API key optional. Configure the local XInference OpenAI-compatible base URL (default: http://localhost:9997/v1).

Search Providers (11)

ID Alias Name Tags Website Notes
brave-search brave-search Brave Search Search link Subscription token from Brave Search API dashboard
exa-search exa-search Exa Search Search link API key from dashboard.exa.ai
google-pse-search google-pse Google Programmable Search Search link Requires a Google API key and your Programmable Search Engine ID (cx)
linkup-search linkup Linkup Search Search link Bearer API key from the Linkup dashboard
ollama-search ollama-search Ollama Search Search link Same API key as Ollama Cloud (from ollama.com/settings/api-keys)
perplexity-search pplx-search Perplexity Search Search link Same API key as Perplexity (pplx-...)
searchapi-search searchapi SearchAPI Search link API key from SearchAPI (query param or Bearer auth)
searxng-search searxng SearXNG Search Search link API key is optional. Set your SearXNG base URL. Some instances may require a bearer token for access.
serper-search serper-search Serper Search Search link API key from serper.dev dashboard
tavily-search tavily-search Tavily Search Search link API key from app.tavily.com (format: tvly-...)
youcom-search youcom-search You.com Search Search link X-API-Key from the You.com platform dashboard

Audio-only Providers (7)

ID Alias Name Tags Website Notes
assemblyai aai AssemblyAI Audio link
aws-polly polly AWS Polly Audio link Use AWS Secret Access Key as API key; set providerSpecificData.accessKeyId and optional region.
cartesia cartesia Cartesia Audio link
deepgram dg Deepgram Audio link
elevenlabs el ElevenLabs Audio link
inworld inworld Inworld Audio link
playht playht PlayHT Audio link

Upstream Proxy Providers (2)

ID Alias Name Tags Website Notes
9router nr 9router Upstream proxy link
cliproxyapi cpa CLIProxyAPI Upstream proxy link

Cloud Agent Providers (3)

ID Alias Name Tags Website Notes
codex-cloud codex-cloud Codex Cloud Cloud agent link OpenAI API key with Codex Cloud task access.
devin devin Devin Cloud agent link Devin API key for cloud agent sessions.
jules jules Google Jules Cloud agent link Jules API key for creating and managing cloud coding tasks.

System Providers (1)

ID Alias Name Tags Website Notes
auto auto Auto (Zero-Config) System

Sources of truth

See Also