Providers & Models

Where every AI credential, model and search path actually comes from — and where to change it.

This app exists because that question had no single answer. Tracing one provider key on 2026-08-24 meant reading a ConfigMap, three Key Vaults, a CSI SecretProviderClass, a git repo and the mesh. Four separate incidents that week came down to "which of those is the source of truth?"

What it shows

The rule it makes visible

A credential has ONE administered home: the ModelProvider node. Configuration is a SEED into it, never a parallel live source.

ProviderCredentialSeed fills an empty key on the node from {Section}:ApiKey on every boot, and the value is stored encrypted. So a key configured after the node was created converges instead of being invisible forever — and there is never an env key and a node key disagreeing silently.

Set one up

Set up AI providers — one card per provider you can see, with the fields it actually needs and the models it exposes.

🚨 Never store a literal key by hand. Enter it on that form:

Contents

Reconnecting…
The server was updated. Reloading the page to pick up the latest version.