Files
OmniRoute/docs/research/DISCOVERY_TOOL_DESIGN.md
Diego Rodrigues de Sa e Souza c315a2394c Release v3.8.21 (#3593)
* chore(release): open v3.8.21 development cycle

* fix: pass through valid max_tokens-truncated responses instead of fake 502 (#3572) (#3595)

* fix: /v1/completions returns legacy text-completion format, not chat (#3571) (#3596)

* fix: z.ai/GLM coding plan no longer shows Monthly 0% when no monthly cap (#3580) (#3597)

* docs: mark DISCOVERY_TOOL_DESIGN endpoints as Phase-2 not-yet-implemented (#3498) (#3599)

* fix(agent-bridge): add validate-only upstream-ca/test route (#3488) (#3600)

* fix(gamification): add level/badges/badges-earned profile routes (#3484)

* security(oauth): migrate 5 public client_ids to resolvePublicCred (#3493)

* fix(mcp): ship MCP server source closure in npm files + coverage gate (#3578)

* fix: add reasoning token buffer for combo routing (fixes #3587) (#3588)

Integrated into release/v3.8.21

* Refactor: Extract chatCore phases into modular files (#3598)

Integrated into release/v3.8.21 — chatCore phase modularization. Adjusted: re-derive idempotencyKey for the save path after the check moved into the module (co-authored). Thanks @oyi77!

* docs(changelog): credit #3598 (chatCore modularization) + #3588 (combo reasoning buffer)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(api): implement GET /api/guardrails + POST /api/guardrails/test, drop shadow/guardrails doc-fiction (#3496) (#3602)

Integrated into release/v3.8.21 — implements GET /api/guardrails + POST /api/guardrails/test, removes shadow/guardrails doc-fiction. TDD-validated (5/5) + check-docs-symbols/typecheck/eslint green.

* fix(gemini): isolate textual reasoning wrappers (#3605)

Split-out PR C from #3584. Isolates textual reasoning wrappers (<think>/<thinking>/<thought>/<internal_thought>, including malformed/open tags) into reasoning_content across both the non-streaming sanitizer and the Gemini streaming translator, with split-chunk buffering. Additive to the existing textual tool-call pipeline; does not touch the #3569 native functionResponse path. Integrated into release/v3.8.21. Thanks @dhaern!

* fix(antigravity): normalize Gemini 3.5 Flash tier IDs (#3603)

Split-out PR A from #3584. Normalizes the Antigravity/agy Gemini 3.5 Flash tier IDs to clean public names (gemini-3.5-flash-low/medium/high), maps them to the live upstream IDs at the executor boundary, and removes Antigravity from the global model resolver so the executor owns wire normalization. Maintainer follow-up: kept gemini-3.5-flash-preview as a hidden backward-compat alias routing to the High tier (so saved combos/configs keep working). Live-validated the tier set via the agy CLI catalog. Integrated into release/v3.8.21. Thanks @dhaern!

* fix(agent-bridge): surface real MITM startup-failure cause, not always port 443 (#3606) (#3608)

Integrated into release/v3.8.21 (#3606)

* fix(oauth): surface real Kiro import-token failure cause, not a bare 500 (#3589) (#3609)

Integrated into release/v3.8.21 (#3589)

* docs(opencode-provider): soft-deprecate in favor of @omniroute/opencode-plugin (#3419) (#3613)

Integrated into release/v3.8.21 (#3419)

* fix(usage): normalize Antigravity and agy provider quotas (#3604)

Split-out PR B from #3584. Normalizes Antigravity/agy provider quotas: prefers retrieveUserQuota for live consumption, falls back to fetchAvailableModels and local usage_history, sanitizes cached Provider Limits so retired upstream IDs are not re-exposed, and schedules a deduplicated post-usage refresh. Maintainer follow-up: decoupled the post-usage refresh via a lightweight usageEvents bus (usageHistory no longer dynamic-imports providerLimits) so it does not pull the executors/translator graph into the typecheck-core surface — typecheck:core stays at 0. Integrated into release/v3.8.21. Thanks @dhaern!

* feat(cli): add autostart on/off/toggle shorthand for headless serve mode (#3331) (#3614)

Integrated into release/v3.8.21 (#3331)

* docs(changelog): credit #3603 (Flash tier IDs) + #3604 (provider quotas) + #3605 (reasoning wrappers)

Co-authored-by: diegosouzapw <diegosouza.pw@gmail.com>

* fix(review): resolve findings from /review-reviews battery (v3.8.21 hardening) (#3618)

Pre-release hardening from the /review-reviews battery — 15 findings resolved (L1-L13,L15) + L14 live-verified WONTFIX, convergence re-review clean. lint/typecheck:core/test:vitest(146)/build green; zero new test:unit failures vs baseline 797de433f.

* chore(release): v3.8.21 CHANGELOG + i18n + env-doc sync

---------

Co-authored-by: Hernan Javier Ardila Sanchez <hjasgr@gmail.com>
Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Raxxoor <manker_lol@hotmail.com>
2026-06-11 04:01:24 -03:00

5.2 KiB

Discovery Tool — Design Document

Status: Design + Stub (Phase 1) Related: Issue #2885

Overview

The Discovery Tool is an automated service that scans LLM providers for free/unlimited access methods, tests authentication bypasses, validates endpoints, and reports findings. It integrates into OmniRoute as an opt-in service (default off).

Architecture

┌─────────────────────────────────────────────┐
│           Discovery Service                  │
│  ┌──────────┐  ┌──────────┐  ┌──────────┐  │
│  │ Scanner  │  │ Tester   │  │ Reporter │  │
│  │          │  │          │  │          │  │
│  │ - Probe  │  │ - Auth   │  │ - JSON   │  │
│  │   URLs   │  │   bypass │  │   report │  │
│  │ - Detect │  │ - Cookie │  │ - DB     │  │
│  │   APIs   │  │   extract│  │   store  │  │
│  │ - Model  │  │ - Rate   │  │ - Notify │  │
│  │   disco  │  │   limits │  │          │  │
│  └──────────┘  └──────────┘  └──────────┘  │
└─────────────────────────────────────────────┘
         │               │               │
         ▼               ▼               ▼
    Provider DB    Test Results    User Dashboard

Components

1. Scanner

  • Probes known provider URLs for API endpoints
  • Detects authentication requirements (none, cookie, API key, OAuth)
  • Discovers available models via /v1/models or equivalent
  • Checks for rate limits and free tier availability

2. Tester

  • Tests authentication bypass methods (cookie extraction, public endpoints)
  • Validates session token freshness
  • Measures rate limits and quotas
  • Tests streaming support

3. Reporter

  • Generates structured JSON reports
  • Stores findings in SQLite (discovery_results table)
  • Sends notifications for high-value discoveries
  • Updates provider registry suggestions

Configuration

interface DiscoveryConfig {
  enabled: boolean;           // Default: false (opt-in)
  scanInterval: number;       // ms between scans (default: 24h)
  maxConcurrentScans: number; // parallel scan limit (default: 3)
  targetProviders: string[];  // specific providers to scan (empty = all known)
  notificationWebhook?: string; // URL for discovery notifications
}

DB Schema

CREATE TABLE discovery_results (
  id INTEGER PRIMARY KEY AUTOINCREMENT,
  provider_id TEXT NOT NULL,
  method TEXT NOT NULL,           -- 'free_tier', 'web_cookie', 'auto_register', 'trial'
  endpoint TEXT,
  auth_type TEXT,                 -- 'none', 'cookie', 'api_key', 'oauth'
  models TEXT,                    -- JSON array of discovered models
  rate_limit TEXT,
  feasibility INTEGER,            -- 1-5 scale
  risk_level TEXT,                -- 'none', 'low', 'medium', 'high', 'critical'
  status TEXT DEFAULT 'pending',  -- 'pending', 'testing', 'verified', 'rejected'
  notes TEXT,
  discovered_at TEXT DEFAULT (datetime('now')),
  verified_at TEXT,
  UNIQUE(provider_id, method, endpoint)
);

API Endpoints

⚠️ Not yet implemented — Phase 2 (Future). The routes below are a design proposal, not live endpoints. src/lib/discovery/index.ts is an explicit Phase-1 stub and none of the discovery routes exist yet. They are intentionally documented here as the planned surface; the check-docs-symbols quality gate suppresses them via KNOWN_STALE_DOC_REFS until Phase 2 lands. See Implementation Plan → Phase 2.

Method Path Description
GET /api/discovery/results List all discovery results
GET /api/discovery/results/:id Get specific result
POST /api/discovery/scan Trigger manual scan
POST /api/discovery/verify/:id Verify a discovery
DELETE /api/discovery/results/:id Delete a result

Settings Toggle

In OmniRoute dashboard settings:

{
  discovery: {
    enabled: false,           // Default off
    scanInterval: 86400000,   // 24 hours
    maxConcurrentScans: 3,
    targetProviders: [],
  }
}

Implementation Plan

Phase 1 (Current — Stub)

  • Design doc
  • Stub service (src/lib/discovery/index.ts)
  • DB migration for discovery_results table
  • Settings toggle in settings API
  • Basic scanner that probes a single URL

Phase 2 (Future)

  • Full scanner with multi-provider support
  • Auth bypass testing
  • Model discovery
  • Rate limit detection
  • Dashboard UI tab

Phase 3 (Future)

  • Auto-registration integration
  • Session pool management
  • Continuous scanning
  • Notification webhooks

Security Considerations

  • Discovery results may contain sensitive endpoint information
  • Cookie/session data should be encrypted at rest
  • Scan requests should respect rate limits to avoid IP bans
  • Results should be user-scoped (not shared across instances)