Skip to content

Core: Vault metered API-key BYOK providers #231

Description

@ReBoticsAI

Summary

Add first-class Vault API key / metered BYOK provider cards so Cloud users can connect OpenAI-compatible (and native) inference without relying on free-form "AI platform secrets" name matching. Complements the subscription-backed providers issue.

Providers in scope (metered or credit top-up)

Prefer named cards with base URL + key (models.dev / aiEmployeesFrappe style) over opaque secret names:

  • OpenAI Platform (API key)
  • Anthropic Console (API key; not Claude.ai Pro/Max)
  • Google AI Studio / Gemini API and/or Vertex
  • OpenRouter
  • Groq
  • Together
  • Fireworks
  • DeepSeek (pay-as-you-go platform key)
  • xAI console API key (metered; SuperGrok OAuth is on the subscriptions issue)
  • Z.AI / Moonshot-style payg keys (distinct from Coding Plan / Kimi Code subscription keys)
  • MiniMax payg interface key (distinct from Token Plan subscription key)
  • Other OpenAI-compatible endpoints (custom base URL + key) as a generic escape hatch

Out of scope

  • Subscription / OAuth "use your plan" cards (companion subscriptions issue)
  • Claude Pro/Max or Gemini Advanced consumer login

Acceptance

  • Vault API keys section with clear provider cards (Connect / Apply into Intelligence)
  • Secrets map to the correct backend/catalog without requiring magic secret names
  • SaaS FirstRunWizard / Vault copy accurately describes API-key BYOK
  • Per-tenant storage only; works with existing Vault encryption model

Related

Companion: subscription-backed inference providers (see linked issue).

Metadata

Metadata

Assignees

No one assigned

    Labels

    coreControl Center Core roadmapenhancementNew feature or requesttrack-bPriority track B: secure multi-tenant VPS/SaaS

    Projects

    Status
    Ready

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions