Skip to content

refactor(ai): clarify provider naming and GG credential authority - #1069

Merged
softmarshmallow merged 1 commit into
mainfrom
chore/ai-provider-credentials
Sep 13, 2026
Merged

softmarshmallow merged 1 commit into
mainfrom
chore/ai-provider-credentials

Conversation

@softmarshmallow

@softmarshmallow softmarshmallow commented Sep 13, 2026 •

Copy link
Copy Markdown
Member

Refs #1039, #1066.

Clarify Vercel AI Gateway naming and distinguish Grida-funded provider credentials from contributor overrides and native BYOK. Hosted Vercel AI Gateway execution retains platform OIDC; Replicate execution now requires its explicit GG_ credential.

Changes

  • Use Vercel AI Gateway consistently in provider symbols, factories, labels, tests, and maintained documentation. Update consumers after the shared AI package moves recorded in refactor(ai): standardize Vercel AI Gateway naming #1039.
  • Funded Vercel AI Gateway reads GG_VERCEL_AI_GATEWAY_API_KEY when nonblank, otherwise uses the SDK's per-request OIDC resolution. An explicit empty SDK setting suppresses implicit AI_GATEWAY_API_KEY lookup without handling or caching OIDC tokens ourselves.
  • Rename the funded Replicate reader to GG_REPLICATE_API_TOKEN, trim it, and reject missing/blank configuration when a Replicate operation runs. No generic or contributor fallback; unrelated operations still load.
  • Update environment examples, Turborepo forwarding, the security registry, and the credential mapping/rollout instructions in the contributor billing guide.

Compatibility and scope

  • Direct contributor rename: BYOK_AI_GATEWAY_API_KEY → BYOK_VERCEL_AI_GATEWAY_API_KEY, with no deprecated alias. OpenRouter-first precedence, authentication, and text-only billing bypass are preserved.
  • Retain the Grida-owned persisted/wire provider ID vercel deliberately for compatibility. The installed CLI still accepts the vendor's AI_GATEWAY_API_KEY; distributed CLI/Desktop credential custody is unchanged.
  • Preserve vendor SDK exports, URLs, protocol fields, and provider option namespaces. GG_TRIPO_API_KEY and the unbilled OpenAI model-list reader remain unchanged. Library embeddings keep their existing shared, unbilled provider selection.
  • The two skill references and historical document in refactor(ai): standardize Vercel AI Gateway naming #1039 remain inventory-only, as that issue specifies.

Rollout — production verified and environment cleanup complete

  • Merged and deployed with explicit GO: squash commit c70e5d6ebadf0c6ab0acb8a92da02265718d92cc. Vercel's automatic production deployment dpl_FYVfMC6MrpDToHUKaDpBfuauMiYn is READY and serves grida.co; domain cutover completed on 2026-09-13 at 17:48:32 UTC. No manual deployment or preview promotion was needed. Fresh preview validation was explicitly excluded.
  • B1 complete: GG_REPLICATE_API_TOKEN is configured in Production, Preview, and Development with the same encrypted type, scopes, and value as the retained legacy entry. The read-only Replicate GET /v1/account check returned HTTP 200. Values were compared without displaying the token.
  • Production configuration verified: build and runtime environment-name snapshots contain both Replicate names and platform VERCEL_OIDC_TOKEN; generic/static GG Vercel API keys and contributor overrides are absent.
  • Public health verified: /api/v1/models/catalog returns HTTP 200 and the merged version c70e5d6ebadf; /ai/models returns HTTP 200 HTML. A bounded post-cutover runtime sample of 200 records contained only HTTP 200 responses and info-level logs. The initial sample had no missing-Replicate-credential or upstream-authentication error matches. This is deployment/configuration/public-health evidence, not live inference or metering proof.
  • Focused live browser checks completed with explicit authorization: GPT-5.6 Luna returned the requested one-word reply; Lyria 3 through Replicate generated a playable 30-second piano MP3. Comparable refreshed live credit balances decreased by the expected $0.04 for music; the text request is below cent display precision. A fresh semantic Library query returned populated results through the shared unbilled embedding path. No runtime error records appeared in the bounded test-window scan. These are focused success-path checks, not exhaustive billing lifecycle verification.
  • B2 cleanup completed with explicit GO on 2026-09-14: an independent final source audit confirmed no remaining runtime consumer of REPLICATE_API_TOKEN. Removed its single legacy Vercel project entry from Development, Preview, and Production. Read-back confirmed the legacy name is absent and the GG variable plus all unrelated environment metadata are unchanged. Production still serves the verified commit and its public catalog returns HTTP 200. The cleanup reminder was deleted. No provider token was rotated or revoked; local secret files were untouched.

The initial deployment check did not run paid generation because local CLI custody was unavailable. The later user-authorized browser checks used an existing signed-in session and cost approximately $0.04 in total. No credentials were extracted, no production database was accessed, and only the obsolete Vercel project variable was subsequently removed during the authorized cleanup. No CLI/Desktop release or version bump is required for this migration. Existing deployment snapshots retain the environment with which they were built; removing the project variable governs future builds and does not require redeploying the already-verified GG-only reader. Rebuilding an old revision that reads the legacy name would require restoring that variable.

Validation

  • 315 focused editor tests, including actual installed-SDK authentication with synthetic requests, per-request OIDC selection, conflicting credentials, direct BYOK cutover, Replicate gate → provider → metering order, and unbilled Library embeddings.
  • Package AI/model suites and focused agent/CLI provider and media suites passed.
  • test:api: 638 tests plus API audit and local network-guard checks.
  • test:api:http: 356 isolated production-mode Next.js HTTP cases passed.
  • Local packaged CLI media proof: 28 cases passed, plus 4 network-isolation tests; synthetic credentials and owned loopback fixtures only.
  • Repository-wide typecheck: 52 tasks passed. Lint: zero errors, three existing TODO warnings. Formatting and AI seam audit passed. Independent security review passed.
  • Unrun coverage: the full Stripe/Metronome lifecycle E2E suite requires a verified external sandbox and was not run. This PR changes credential readers, not billing modules, schemas, webhooks, entitlement, or metering logic; that broad suite is outside the focused merge gate. The credential tests exercise the unchanged billing seam. The focused live success-path evidence is recorded above; the broad lifecycle suite remains unrun.

Local pnpm validation used pnpm_config_verify_deps_before_run=false to avoid unrelated automatic dependency installation; the repository-wide Turbo typecheck used --env-mode=loose to pass that setting to child tasks. No dependency or release-version changes are included.

@coderabbitai

coderabbitai Bot commented Sep 13, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 0927622a-8cae-4cac-ae74-1ff2ba8df00f

📥 Commits

Reviewing files that changed from the base of the PR and between 7dc0bf4 and c16d830.

📒 Files selected for processing (73)
  • SECURITY.md
  • docs/cli/providers.md
  • docs/contributing/billing.md
  • docs/editor/desktop/chatgpt-subscription.md
  • docs/editor/desktop/local-models.md
  • docs/models/index.md
  • docs/wg/ai/agent/chatgpt-subscription-provider.md
  • docs/wg/cli/credential-custody.md
  • docs/wg/platform/billing/known-issues.md
  • docs/wg/platform/hosted-ai.md
  • editor/.env.example
  • editor/app/(api)/(public)/api/v1/ai/chat/completions/route.byok.test.ts
  • editor/app/(api)/(public)/api/v1/ai/chat/completions/route.test.ts
  • editor/app/(api)/(public)/api/v1/ai/chat/completions/route.ts
  • editor/app/(api)/(public)/api/v1/ai/images/generations/route.test.ts
  • editor/app/(api)/(public)/api/v1/ai/images/generations/route.ts
  • editor/app/(api)/(public)/api/v1/ai/models/route.test.ts
  • editor/app/(api)/private/ai/chat/route.ts
  • editor/app/(www)/(ai)/ai/_page.tsx
  • editor/app/(www)/(ai)/ai/models/page.tsx
  • editor/app/desktop/settings/_components/media-model-readiness.test.ts
  • editor/app/desktop/settings/_components/media-model-readiness.ts
  • editor/grida-canvas-hosted/ai/types.ts
  • editor/lib/ai/__tests__/generate-video.test.ts
  • editor/lib/ai/__tests__/models.test.ts
  • editor/lib/ai/__tests__/replicate-credentials.test.ts
  • editor/lib/ai/__tests__/server.test.ts
  • editor/lib/ai/image-cost.ts
  • editor/lib/ai/models.ts
  • editor/lib/ai/openai-compat/hosted-models.test.ts
  • editor/lib/ai/openai-compat/hosted-models.ts
  • editor/lib/ai/server.ts
  • editor/lib/api/README.md
  • editor/lib/desktop/bridge.ts
  • editor/scaffolds/desktop/shared/media-model-availability.test.ts
  • editor/scaffolds/desktop/shared/media-model-availability.ts
  • editor/scaffolds/desktop/video-gen/video-playground.tsx
  • editor/turbo.json
  • packages/grida-ai-agent/README.md
  • packages/grida-ai-agent/src/__public-api__.test.ts
  • packages/grida-ai-agent/src/http/routes/video.test.ts
  • packages/grida-ai-agent/src/providers/byok.ts
  • packages/grida-ai-agent/src/providers/http.test.ts
  • packages/grida-ai-agent/src/providers/index.test.ts
  • packages/grida-ai-agent/src/providers/index.ts
  • packages/grida-ai-agent/src/providers/resolve-image.test.ts
  • packages/grida-ai-agent/src/providers/resolve-video.test.ts
  • packages/grida-ai-agent/src/runtime/image-generation.test.ts
  • packages/grida-ai-models/README.md
  • packages/grida-ai-models/__tests__/grida/modelSpecById.test.ts
  • packages/grida-ai-models/__tests__/grida/models.test.ts
  • packages/grida-ai-models/src/grida/catalog.ts
  • packages/grida-ai-models/src/models.ts
  • packages/grida-ai/README.md
  • packages/grida-ai/src/image-byok.test.ts
  • packages/grida-ai/src/image-byok.ts
  • packages/grida-ai/src/image-client.test.ts
  • packages/grida-ai/src/media-operations.test.ts
  • packages/grida-ai/src/provider-credentials.test.ts
  • packages/grida-ai/src/provider-ids.ts
  • packages/grida-ai/src/video-client.test.ts
  • packages/grida-ai/src/video-client.ts
  • packages/grida-ai/src/video-models.ts
  • packages/grida-cli/README.md
  • packages/grida-cli/src/cli.ts
  • packages/grida-cli/src/media-http.test.ts
  • packages/grida-cli/src/media-http.ts
  • packages/grida-cli/src/provider-credentials.test.ts
  • scripts/ai-local/README.md
  • scripts/cli-media-local/README.md
  • scripts/cli-media-local/proof.mjs
  • test/billing-quota-and-ai.md
  • turbo.json

Included review availability: Your plan provides up to 8 included reviews per hour; 7 remain after this review.


Walkthrough

The change standardizes Vercel AI Gateway naming, renames funded and BYOK credentials, updates provider adapters, adds credential tests, and documents provider selection, OIDC handling, and deployment migration.

Changes

Credential and provider integration

Layer / File(s) Summary
Credential contract and documentation
SECURITY.md, docs/contributing/billing.md, editor/.env.example, turbo.json
Documents the GG_ and BYOK_ credential conventions, renames the BYOK variable, and describes OIDC fallback and migration steps.
Editor provider seam
editor/lib/ai/models.ts, editor/lib/ai/server.ts, editor/turbo.json
Renames the exported provider to vercelAiGateway, uses the new credential names, and updates Replicate credential loading.
Credential validation tests
editor/lib/ai/__tests__/models.test.ts, editor/lib/ai/__tests__/replicate-credentials.test.ts
Tests funded credentials, OIDC authority, BYOK precedence, Replicate admission, billing, and independent OpenAI model listing.

Provider adapters and terminology

Layer / File(s) Summary
Agent provider factory
packages/grida-ai-agent/src/providers/*
Renames the Vercel factory and gateway construction calls to Vercel AI Gateway names.
Model catalog
packages/grida-ai-models/src/models.ts, packages/grida-ai-models/__tests__/*
Updates provider labels, pricing identifiers, binding documentation, and token-pricing notes.
Image and video adapters
packages/grida-ai/src/image-byok.ts, packages/grida-ai/src/video-models.ts, packages/grida-ai/src/video-client.ts
Renames adapter helpers and the video base-URL constant while preserving provider values and request behavior.

CLI and repository terminology

Layer / File(s) Summary
CLI and local proofs
packages/grida-cli/*, scripts/cli-media-local/*, scripts/ai-local/*, turbo.json
Updates verification text, synthetic credentials, proof names, fixtures, and environment pass-through entries.
Cross-repository terminology
docs/*, packages/*/README.md, editor/app/*, editor/scaffolds/*
Replaces generic Vercel or gateway references with Vercel AI Gateway and clarifies catalog model identifiers.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~30 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to c16d8

The credential rename preserves the persisted provider ID and has focused coverage for funded keys, OIDC fallback, BYOK selection, and Replicate admission. No merge-blocking issue remains.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 43.33% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 30 functions across 50 files. (23 skipped… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly summarizes the main changes: provider naming clarification and GG credential authority updates.
Description check ✅ Passed The description directly explains the provider naming changes, credential authority changes, compatibility scope, rollout status, and validation results.
Full details: Docstring Coverage

Explanation

Docstring coverage is 43.33% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 30 functions across 50 files. (23 skipped: 21 unsupported, 2 over the file limit.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/ai-provider-credentials

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@vercel

vercel Bot commented Sep 13, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
blog Ready Ready Preview Sep 13, 2026 2:25pm UTC
docs Ready Ready Preview Sep 13, 2026 2:25pm UTC
grida Ready Ready Preview Sep 13, 2026 2:25pm UTC
viewer Ready Ready Preview Sep 13, 2026 2:25pm UTC
2 Skipped Deployments
Project Deployment Actions Updated
backgrounds Ignored Ignored Sep 13, 2026 2:25pm UTC
code Ignored Ignored Sep 13, 2026 2:25pm UTC

Request Review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 13, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-13T15:11:08.904868Z c16d830 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@softmarshmallow
softmarshmallow merged commit c70e5d6 into main Sep 13, 2026
25 checks passed

This branch was successfully deployed

4 active deployments
Preview – grida — c16d8305 Deployed Sep 13, 2026 by vercel[bot]
Preview – docs — c16d8305 Deployed Sep 13, 2026 by vercel[bot]
Preview – viewer — c16d8305 Deployed Sep 13, 2026 by vercel[bot]
Preview – blog — c16d8305 Deployed Sep 13, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant