refactor(ai): clarify provider naming and GG credential authority - #1069
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (73)
Included review availability: Your plan provides up to 8 included reviews per hour; 7 remain after this review. WalkthroughThe change standardizes Vercel AI Gateway naming, renames funded and BYOK credentials, updates provider adapters, adds credential tests, and documents provider selection, OIDC handling, and deployment migration. ChangesCredential and provider integration
Provider adapters and terminology
CLI and repository terminology
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~30 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to The credential rename preserves the persisted provider ID and has focused coverage for funded keys, OIDC fallback, BYOK selection, and Replicate admission. No merge-blocking issue remains. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 43.33% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 30 functions across 50 files. (23 skipped: 21 unsupported, 2 over the file limit.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
2 Skipped Deployments
|
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Refs #1039, #1066.
Clarify Vercel AI Gateway naming and distinguish Grida-funded provider credentials from contributor overrides and native BYOK. Hosted Vercel AI Gateway execution retains platform OIDC; Replicate execution now requires its explicit
GG_credential.Changes
GG_VERCEL_AI_GATEWAY_API_KEYwhen nonblank, otherwise uses the SDK's per-request OIDC resolution. An explicit empty SDK setting suppresses implicitAI_GATEWAY_API_KEYlookup without handling or caching OIDC tokens ourselves.GG_REPLICATE_API_TOKEN, trim it, and reject missing/blank configuration when a Replicate operation runs. No generic or contributor fallback; unrelated operations still load.Compatibility and scope
BYOK_AI_GATEWAY_API_KEY→BYOK_VERCEL_AI_GATEWAY_API_KEY, with no deprecated alias. OpenRouter-first precedence, authentication, and text-only billing bypass are preserved.verceldeliberately for compatibility. The installed CLI still accepts the vendor'sAI_GATEWAY_API_KEY; distributed CLI/Desktop credential custody is unchanged.GG_TRIPO_API_KEYand the unbilled OpenAI model-list reader remain unchanged. Library embeddings keep their existing shared, unbilled provider selection.Rollout — production verified and environment cleanup complete
c70e5d6ebadf0c6ab0acb8a92da02265718d92cc. Vercel's automatic production deploymentdpl_FYVfMC6MrpDToHUKaDpBfuauMiYnis READY and servesgrida.co; domain cutover completed on 2026-09-13 at 17:48:32 UTC. No manual deployment or preview promotion was needed. Fresh preview validation was explicitly excluded.GG_REPLICATE_API_TOKENis configured in Production, Preview, and Development with the same encrypted type, scopes, and value as the retained legacy entry. The read-only ReplicateGET /v1/accountcheck returned HTTP 200. Values were compared without displaying the token.VERCEL_OIDC_TOKEN; generic/static GG Vercel API keys and contributor overrides are absent./api/v1/models/catalogreturns HTTP 200 and the merged versionc70e5d6ebadf;/ai/modelsreturns HTTP 200 HTML. A bounded post-cutover runtime sample of 200 records contained only HTTP 200 responses and info-level logs. The initial sample had no missing-Replicate-credential or upstream-authentication error matches. This is deployment/configuration/public-health evidence, not live inference or metering proof.REPLICATE_API_TOKEN. Removed its single legacy Vercel project entry from Development, Preview, and Production. Read-back confirmed the legacy name is absent and the GG variable plus all unrelated environment metadata are unchanged. Production still serves the verified commit and its public catalog returns HTTP 200. The cleanup reminder was deleted. No provider token was rotated or revoked; local secret files were untouched.The initial deployment check did not run paid generation because local CLI custody was unavailable. The later user-authorized browser checks used an existing signed-in session and cost approximately $0.04 in total. No credentials were extracted, no production database was accessed, and only the obsolete Vercel project variable was subsequently removed during the authorized cleanup. No CLI/Desktop release or version bump is required for this migration. Existing deployment snapshots retain the environment with which they were built; removing the project variable governs future builds and does not require redeploying the already-verified GG-only reader. Rebuilding an old revision that reads the legacy name would require restoring that variable.
Validation
test:api: 638 tests plus API audit and local network-guard checks.test:api:http: 356 isolated production-mode Next.js HTTP cases passed.Local pnpm validation used
pnpm_config_verify_deps_before_run=falseto avoid unrelated automatic dependency installation; the repository-wide Turbo typecheck used--env-mode=looseto pass that setting to child tasks. No dependency or release-version changes are included.