docs(providers): call the AI Gateway from the OpenAI and Anthropic clients - #4631
Conversation
…ients Document the vendor-neutral /ai/v1 endpoint and the Anthropic Messages endpoint for code outside Veryfront, with a project key that has Write. The guide tests pin each documented base URL to the one the SDK routes Veryfront Cloud models to, including a vendor the SDK has no entry for. Refs veryfront/veryfront-issue-inbox#1573
|
You have reached your Codex usage limits for security reviews. Please try again later. |
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reachedNext included review available in 35 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Repository UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (3)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository UI Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe provider guide adds instructions and examples for external AI Gateway access through OpenAI and Anthropic clients. Tests check the documented routes and execute the examples with mocked HTTP requests. A forced-push test sorts captured paths before comparing expected writes. ChangesExternal AI Gateway access
Forced-push test
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Other Merge Risk: ⚪ Minimal · up to The guide and mocked request checks show no established repository-side mismatch. Run the wired documentation validation in CI; actual project-key authorization is governed outside this repository. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The examples require a project API key and do not change the gateway itself. Tests check the requests the clients construct, but they do not establish how the live service enforces authorization. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 25.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 4 functions across 3 files. (1 skipped: 1 unsupported.) ✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1836b628e3
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
📦 Client bundle boundary
A server module in a client graph aborts hydration in the browser. New leaks fail CI; known leaks are tracked in |
Review: 68/100 — solid, well-tested docs change, but the new credential claims aren't grounded in this repo's codeStrengths
Concerns
Suggested fix before merge: confirm with whoever owns Studio/API-key issuance whether project API keys are actually a distinct credential type from Generated by Claude Code |
Pin the neutral routes in the guide test, so VERYFRONT_CLOUD_GATEWAY_ROUTES=vendor on the host does not fail it, and say how the example key variable relates to VERYFRONT_API_TOKEN.
|
You have reached your Codex usage limits for security reviews. Please try again later. |
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
|
On the credential question: project API keys are a separate credential. Studio mints them under Settings > API Keys; the API recognises them by the |
|
You have reached your Codex usage limits for security reviews. Please try again later. |
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
|
Review iteration at The guide examples previously had only string/route assertions. The follow-up now executes the extracted JavaScript examples with the official OpenAI 7.23.0 and Anthropic 0.128.0 clients, supplies an isolated transport, and verifies URLs, request methods, authentication headers and payloads. Validation: executable-client test passed; three existing provider-guide steps passed; typecheck, lint, test-layout, anti-slop and diff whitespace checks passed. The main npm package built; the full |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 37e6c40723
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
You have reached your Codex usage limits for security reviews. Please try again later. |
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
|
Independent review of The executable integration test verifies the actual documented client imports, canonical URLs, API key headers and request bodies. Its test and all three provider-guide cases pass after the canonical Messages update. Production Exact-head CI/review gates remain pending. The complete npm build is still running its package compatibility phase; the main package and extension emission have completed. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e16ad103a6
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Diagnosed CI typecheck failure at job108717076268: generate-embedded-npm-packages freshness check fails because the new official client lock entries were not reflected in the committed generated manifest. Prepared the deterministic ten-line manifest update (clients, transitive packages, and constraints). Generator freshness/focused tests pass; independent delta review98/100. Full deno task typecheck is running. No source type error was reported in the failed job, and no other CI failures are currently published. |
|
Fixed the CI manifest freshness failure in c99a961 with a deterministic generated package/constraint update. Full deno task typecheck passes; generator freshness and focused generator tests pass; final full-branch review found no actionable defects and independently passed the official-client snippet and providers-guide tests. Independent delta review98/100. Rechecked author head and existing failures before the single normal fast-forward push; no other published CI failure required a source change. New exact-head CI remains required. |
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
|
You have reached your Codex usage limits for security reviews. Please try again later. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c99a9611d9
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
|
You have reached your Codex usage limits for security reviews. Please try again later. |
|
@codex review |
|
You have reached your Codex usage limits for security reviews. Please try again later. |
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e2b10bab72
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
|
Codex review for exact head Finding[HIGH] Prevent the OpenAI example from falling back to an ambient vendor credential The documented constructor passes Fix: Read and validate Verification
The neutral OpenAI and Anthropic URLs, bearer authentication for Anthropic, catalog URL, isolated lockfile, and tolerant unlisted-provider routing otherwise match the acceptance context. The credential fallback above blocks approval. Review-Gate: |
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
|
You have reached your Codex usage limits for security reviews. Please try again later. |
|
@codex review |
|
Codex Review: Didn't find any major issues. Keep it up! Reviewed commit: ℹ️ About Codex in GitHubCodex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback". |
Codex fresh reviewReviewed exact head Findings
Verification
Verdict: REQUEST CHANGES Score: 80/100 Review-Gate: |
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
|
Addressed the three findings from the review of 906f479 in commit a330e95:
Pinned Deno 2.7.7 verification: provider client integration 3 steps pass; guide code examples 43 tests / 71 steps pass; format and diff checks pass; targeted typecheck passes with the repo's required sloppy-imports option. Plain deno check without that option stops on the pre-existing extension import resolution in src/extensions/websocket. GitHub CI for the new head is running. |
|
@codex review |
|
You have reached your Codex usage limits for security reviews. Please try again later. |
|
Codex exact-head review Reviewed SHA: a330e95 Findings: none actionable. Evidence:
Verification gap: exact-head CI is still in progress, including lint, integration, binary E2E, coverage shards, Playwright, analysis, and profile jobs. This review does not wait on or claim completion of those checks. Verdict: APPROVE Review-Gate: |
|
Codex Review: Didn't find any major issues. Breezy! Reviewed commit: ℹ️ About Codex in GitHubCodex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback". |
|



The provider guide adds installable OpenAI and Anthropic examples and curl requests against the AI Gateway. Both clients use a project bearer token; Anthropic explicitly disables its inherited vendor API key and uses the
/aibase that its SDK expands to/ai/v1/messages.The integration test executes the documented snippets with pinned official SDKs and a mocked transport. A separate frozen lockfile pins transitive versions without adding these clients to runtime dependencies. It preserves the configured Deno cache, excludes host credentials, and checks URLs, methods, bearer headers, absence of the vendor API-key header, Anthropic version, and bodies.
Linux verification also exposed an existing push-conflict test that depended on directory iteration order. Its assertion now checks the same exact write paths and counts in sorted order; conflict, retry, and receipt assertions are unchanged.
Validation: the vendor-key regression failed before the fix and passes afterward; official SDK smoke passes on pinned Deno in macOS and Linux; 44 guide tests with 71 steps and Linux push-command tests with 144 steps pass. Required uncommitted and complete branch reviews are clean. Full PR and merge-group CI are required before merge.
Summary by CodeRabbit
curl, including project API key setup and model listing.