Skip to content

Providers and authentication

Nerve derives built-in provider capabilities from the installed pi-ai integration and exposes them through Workbench provider/model APIs. Treat what the installed Settings UI offers as the support boundary; internal transport code does not guarantee a tested product integration for every possible provider.

A provider stores either an API key or OAuth credentials. Browser API-key submission can use an RSA-OAEP/AES-GCM envelope before it reaches the secret store. Server-side credentials use Nerve’s encrypted secret provider. Replacing authentication changes the credential type atomically.

OAuth can involve a browser callback, device code, pasted code, or provider-specific choice. Only one callback-server flow can run at a time for Anthropic, OpenAI Codex, and Radius. Cancel a stale flow before starting another.

Never reuse a possibly PKCE-bound authorization code after a TLS/proxy failure; restart the flow.

Tests currently observe subscription metadata for Anthropic, GitHub Copilot, Kimi Coding, OpenAI Codex, OpenRouter, Radius, and xAI. This is not a frozen support matrix. Provider behavior, terms, and authentication options can change independently.

Removing a custom provider also removes its custom models and associated stored credential. Built-in provider credential removal makes its models unavailable until reauthenticated; stale scoped selections can remain visible as unavailable settings.