Skip to content

Declare the native model routes and credentials the credential gateway relays - #343

Merged
SaladDay merged 2 commits into
feature/agent-outside-sandboxfrom
aos/model-routes
Oct 1, 2026
Merged

SaladDay merged 2 commits into
feature/agent-outside-sandboxfrom
aos/model-routes

Conversation

@SaladDay

@SaladDay SaladDay commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Changes the Harness–Model provider protocol for the agent-outside-sandbox shape: the Harness never holds the model key. A Session-local credential gateway on the agent host relays the native protocol unchanged and injects the key. This PR declares what that gateway relays. It contains no gateway code; that is a later lane.

  • internal/modelprovider/config.go, the boundary's protocol file, now declares:

    • each protocol's native routes, as a method plus a path relative to the base URL, using each SDK's convention;
    • each protocol's upstream credential header;
    • one list of stripped inbound credential headers, in canonical form, removed case-insensitively with every value: Authorization, Proxy-Authorization, Cookie, X-Api-Key, Api-Key, X-Openai-Actor-Authorization, Cf-Aig-Authorization and X-Amz-Security-Token;
    • a non-secret Placeholder;
    • LookupRoute, which returns the typed misses ErrRouteNotFound and ErrMethodNotAllowed;
    • UpstreamPath, the single join rule: the base URL's escaped path with every trailing / removed, followed by the route path.

    It has no per-Harness branch: each protocol's routes are the union of the routes the pinned Harnesses call.

Protocol Routes Upstream credential
anthropic POST /v1/messages, POST /v1/messages/count_tokens X-Api-Key: <key>
responses POST /responses Authorization: Bearer <key>
chat_completions POST /chat/completions Authorization: Bearer <key>
  • Routes were verified against Claude Code 2.1.269 (recorded traffic), Codex 0.153.4 (source) and MiniMax Code at its pinned revision (source and SDK versions from its lockfile). No WebSocket route is declared: the pinned Codex does not use the Responses WebSocket transport for custom providers.
  • For anthropic, Claude Code sends Authorization: Bearer upstream today, while MiniMax Code and the Anthropic SDK's API-key path send X-Api-Key. The protocol declares X-Api-Key, the Anthropic Messages API's API-key header. Claude Code's upstream header form therefore changes once the gateway is wired.
  • contracts/agents-api/model-execution.md gains a "Credential gateway" section with the gateway rule, which replaces "no model API proxy, passthrough gateway". The dispatch paragraph now says that the gateway holds the key in memory and that the key never enters the Harness's environment, configuration or home, or the sandbox. The Harness onboarding guide, the Agents API guide and the harnessconfig package comment now link to it instead of restating the old rule.

No adapter changes; adapter wiring is a later lane.

Checks:

  • go test, go vet and gofmt over internal/modelprovider and internal/harnessconfig
  • darwin and windows builds
  • relative links in the edited docs

Part of the agent-outside-sandbox work, milestone M1, lane L6p.

…y relays

internal/modelprovider declares each protocol's native routes, upstream
credential header, the stripped inbound credential headers and the
non-secret placeholder, with LookupRoute returning a typed miss.
model-execution.md replaces the no-proxy rule with the credential
gateway rule.
@SaladDay
SaladDay merged commit 4bd566b into feature/agent-outside-sandbox Oct 1, 2026
@SaladDay
SaladDay deleted the aos/model-routes branch October 1, 2026 00:37
…join

StrippedHeaders adds Cookie and the Codex, Cloudflare AI Gateway and AWS
credential headers in canonical form, removed case-insensitively with
every value. UpstreamPath trims the base path's trailing slashes and
appends the route. model-execution.md keeps the key in the gateway's
memory, out of the Harness and the sandbox.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant