Skip to main content

Model Providers

Three different things need a model provider, and they are configured in three different places.

1. The instance's own LLM setting​

vagaris onboard (interactive) and vagaris configure --section llm ask "Configure an LLM provider now?" and offer two choices:

ChoiceStored as
Claude (Anthropic)llm.provider = "claude" plus the API key
OpenAIllm.provider = "openai" plus the API key

The value lives in the instance config.json under llm. It is optional — quickstart (onboard --yes) leaves it unset, and vagaris onboard on an existing install reports LLM: not configured in its summary. vagaris doctor includes an "LLM provider" check that reports this setting.

vagaris configure --section llm

2. Adapter credentials for server-hosted agents​

Agents run on the server through adapters, and each adapter reads its provider's own environment variable — ANTHROPIC_API_KEY for Claude Local, OPENAI_API_KEY for Codex Local, and so on (see Environment Variables). The recommended way to hold those values is a Vagaris secret rather than a plain env var on the agent:

vagaris secrets create --company-id <company-id> --name anthropic-api-key --value-env ANTHROPIC_API_KEY
vagaris secrets list --company-id <company-id>
vagaris secrets doctor --company-id <company-id>

secrets create reads the value from the named environment variable so it never appears on the command line. secrets link references a secret that lives in an external provider without storing its value; secrets migrate-inline-env --apply converts inline sensitive agent env values into secret references. secrets providers lists the configured provider descriptors. The full flow is on Secrets.

3. Credentials for a CLI-hosted executor​

When vagaris dev spawns claude or codex on your machine, the executor authenticates the way it always does — its own login or the provider variable in your shell. The CLI sanitises the child environment (product variables, interpreter hooks, infrastructure write tokens and seat-forbidden secrets are stripped) but does not inject provider keys. If the executor cannot authenticate, the run fails with the executor's own error and the report's spawn.exitCode is non-zero.

The session envelope passed with --agent/--native carries a model policy from the server session; an envelope-aware frontend applies it. See Developer Mode.

Which model an agent uses​

Model selection per agent (and per adapter) is agent configuration in the UI, not a CLI setting. The CLI only carries the policy the server decides into the run.