Skip to content

docs(providers): call the AI Gateway from the OpenAI and Anthropic clients - #4631

Merged
kwakayama merged 14 commits into
mainfrom
docs/aigw-providers-neutral-snippets
Sep 29, 2026
Merged

kwakayama merged 14 commits into
mainfrom
docs/aigw-providers-neutral-snippets

Conversation

@kwakayama

@kwakayama kwakayama commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

The provider guide adds installable OpenAI and Anthropic examples and curl requests against the AI Gateway. Both clients use a project bearer token; Anthropic explicitly disables its inherited vendor API key and uses the /ai base that its SDK expands to /ai/v1/messages.

The integration test executes the documented snippets with pinned official SDKs and a mocked transport. A separate frozen lockfile pins transitive versions without adding these clients to runtime dependencies. It preserves the configured Deno cache, excludes host credentials, and checks URLs, methods, bearer headers, absence of the vendor API-key header, Anthropic version, and bodies.

Linux verification also exposed an existing push-conflict test that depended on directory iteration order. Its assertion now checks the same exact write paths and counts in sorted order; conflict, retry, and receipt assertions are unchanged.

Validation: the vendor-key regression failed before the fix and passes afterward; official SDK smoke passes on pinned Deno in macOS and Linux; 44 guide tests with 71 steps and Linux push-command tests with 144 steps pass. Required uncommitted and complete branch reviews are clean. Full PR and merge-group CI are required before merge.

Summary by CodeRabbit

  • Documentation
    • Added guidance for calling the Veryfront AI Gateway from external clients using OpenAI and Anthropic SDKs or curl, including project API key setup and model listing.
    • Documented the OpenAI Chat Completions and Anthropic Messages endpoints, provider/model naming, and the model format used inside Veryfront agents.
  • Tests
    • Added checks that documented client examples send the expected requests, authorization details, and request bodies to the gateway.
    • Added coverage for gateway URLs, model listing, and vendor routing.

…ients

Document the vendor-neutral /ai/v1 endpoint and the Anthropic Messages
endpoint for code outside Veryfront, with a project key that has Write.
The guide tests pin each documented base URL to the one the SDK routes
Veryfront Cloud models to, including a vendor the SDK has no entry for.

Refs veryfront/veryfront-issue-inbox#1573
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for security reviews. Please try again later.

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your trial has ended. Reactivate Greptile to resume code reviews.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review 🔄 Running since 2026-09-29T01:17:09.607315Z a330e95 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

Next included review available in 35 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Advanced

Run ID: 72bcdf15-c9b6-405d-8114-1b8df9b65134

📥 Commits

Reviewing files that changed from the base of the PR and between 76e0891 and a330e95.

📒 Files selected for processing (3)
  • docs/guides/providers.md
  • tests/docs/guide-code-examples.test.ts
  • tests/integration/docs/provider-client-examples.test.ts

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Advanced

Run ID: 08635049-8f87-4d65-8342-d3142174efc3

📥 Commits

Reviewing files that changed from the base of the PR and between c55bf74 and 76e0891.

⛔ Files ignored due to path filters (1)
  • tests/integration/docs/provider-client-examples.deno.lock is excluded by !**/*.lock
📒 Files selected for processing (3)
  • cli/commands/push/command.test.ts
  • docs/guides/providers.md
  • tests/integration/docs/provider-client-examples.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The provider guide adds instructions and examples for external AI Gateway access through OpenAI and Anthropic clients. Tests check the documented routes and execute the examples with mocked HTTP requests. A forced-push test sorts captured paths before comparing expected writes.

Changes

External AI Gateway access

Layer / File(s) Summary
Document access and check routes
docs/guides/providers.md, tests/docs/guide-code-examples.test.ts
The guide describes project API key requirements, model listing, OpenAI and Anthropic requests, and agent model naming. Route tests check OpenAI, Anthropic, and fallback URLs.
Execute and validate client examples
tests/integration/docs/provider-client-examples.test.ts, deno.json
An integration test runs the guide’s OpenAI and Anthropic examples with mocked transport. It checks request endpoints, headers, and bodies. The docs:validate task runs this test.

Forced-push test

Layer / File(s) Summary
Sort captured paths in assertion
cli/commands/push/command.test.ts
The test sorts captured PUT paths before checking that the expected writes occurred.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 76e08

The guide and mocked request checks show no established repository-side mismatch. Run the wired documentation validation in CI; actual project-key authorization is governed outside this repository.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 76e08

The examples require a project API key and do not change the gateway itself. Tests check the requests the clients construct, but they do not establish how the live service enforces authorization.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — External clients following the guide can submit inference requests using a project API key. The documented key scope is one project; this change does not show a new production route or a broader authorization scope.

Trust Boundaries and Controls

  • observed — The examples use the project key as Bearer authorization. The test checks that both clients construct that header and that the Anthropic request does not send an x-api-key header.
  • observed — The test subprocess receives fixture credentials in a cleared environment, while its fetch replacement records requests instead of sending them to the gateway. These controls validate client behavior, not production authorization.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 25.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 4 functions across 3 files. (1 skipped: 1… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the primary change: documenting how to call the AI Gateway with the OpenAI and Anthropic clients.
Full details: Docstring Coverage

Explanation

Docstring coverage is 25.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 4 functions across 3 files. (1 skipped: 1 unsupported.)

✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gitar-bot

gitar-bot Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Gitar is working

Gitar

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1836b628e3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tests/docs/guide-code-examples.test.ts Outdated
@github-actions

github-actions Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

📦 Client bundle boundary

Entrypoint Modules Source size Server leaks
src/index.client.ts 293 2335 KiB ✅ 0

A server module in a client graph aborts hydration in the browser. New leaks fail CI; known leaks are tracked in scripts/lint/client-bundle-baseline.json to burn down.

Copy link
Copy Markdown
Contributor Author

Review: 68/100 — solid, well-tested docs change, but the new credential claims aren't grounded in this repo's code

Strengths

  • The gateway URLs (https://api.veryfront.com/ai/v1, .../ai/anthropic/v1, plus the acme-labs/unknown-vendor fallback) are pinned to getVeryfrontCloudGatewayBaseUrl in src/provider/veryfront-cloud/shared.ts rather than hardcoded, so this doc can't silently drift from the SDK's own routing (resolveVeryfrontCloudGatewayRoute). That's exactly the "keep public schemas close to runtime behavior" pattern this repo asks for, and I verified the routing logic (default neutral paths vs. VERYFRONT_CLOUD_GATEWAY_ROUTES=vendor) matches what the new test and doc both assume.
  • Minimal, focused diff (docs + one test file), sentence-case heading, no em/en dashes, placeholders/env-vars used correctly, consistent with the rest of providers.md.
  • Good scoping: correctly limits the Anthropic Messages protocol claim to Anthropic models only, and documents the veryfront-cloud/<provider>/<model> equivalent for code inside a Veryfront agent.
  • Trivial/mechanical risk is low — no runtime code changes, and the PR description transparently flags the follow-up dependency (/ai/v1/messages, fix(integrations): hide HubSpot and request Figma user scope #1904/feat(provider): send Anthropic Messages to /ai/v1 #4615).

Concerns

  • The new section introduces a "project API key" concept — Write vs. Read-only permission tiers gating inference, a vf_ key prefix, and a distinct VERYFRONT_API_KEY env var — that I could not find any support for in src/ or cli/. The only credential this codebase implements for the AI Gateway is VERYFRONT_API_TOKEN (a plain Bearer token, checked only for being a non-empty visible-ASCII string — no permission/scope field at all in provider-request-init.ts). That same token is what this very doc file already documents two paragraphs above ("This is a separate credential from a model provider key: it selects the AI Gateway...") for the identical job of authenticating to the gateway.
  • Concretely: if VERYFRONT_API_KEY isn't a real, separate Studio-issued credential, every code sample in the new section (process.env.VERYFRONT_API_KEY, both curl examples) is wrong and will 401 for anyone who copies it — they'd need VERYFRONT_API_TOKEN instead. If it is real (e.g. a Studio-side scoped key that isn't visible in this OSS repo because key issuance lives in a separate control-plane service), the PR should say so explicitly and reconcile it with the existing VERYFRONT_API_TOKEN mention, since right now the same doc quietly presents two different-looking credentials for the same purpose with no cross-reference.
  • None of the three claims (Write-permission requirement, vf_ prefix, VERYFRONT_API_KEY name) are covered by the new test — the test only pins base URLs, not the auth story, so this is the one part of the PR that ships unverified.

Suggested fix before merge: confirm with whoever owns Studio/API-key issuance whether project API keys are actually a distinct credential type from VERYFRONT_API_TOKEN. If yes, add a sentence distinguishing the two (why an external OpenAI/Anthropic client needs a project key rather than the token used elsewhere in this file) so readers aren't confused; if no, replace VERYFRONT_API_KEY/the Write-permission language with the existing VERYFRONT_API_TOKEN credential this repo actually implements.


Generated by Claude Code

Pin the neutral routes in the guide test, so VERYFRONT_CLOUD_GATEWAY_ROUTES=vendor
on the host does not fail it, and say how the example key variable relates to
VERYFRONT_API_TOKEN.
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for security reviews. Please try again later.

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your trial has ended. Reactivate Greptile to resume code reviews.

@kwakayama

kwakayama commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor Author

On the credential question: project API keys are a separate credential. Studio mints them under Settings > API Keys; the API recognises them by the vf_ prefix (veryfront-api src/api/shared/auth/extract-token.ts), and every POST needs the key's Write scope (actionForMethod in src/shared/permissions/project-token-grant.ts). None of that lives in this repo, so the guide test can't pin it. 01c4168 adds a sentence saying that VERYFRONT_API_KEY is only a name for the reader's own code, and that the CLI and SDK read VERYFRONT_API_TOKEN.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for security reviews. Please try again later.

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your trial has ended. Reactivate Greptile to resume code reviews.

@kwakayama

Copy link
Copy Markdown
Contributor Author

Review iteration at 37e6c4072: 92/100, pending exact-head CI and external review.

The guide examples previously had only string/route assertions. The follow-up now executes the extracted JavaScript examples with the official OpenAI 7.23.0 and Anthropic 0.128.0 clients, supplies an isolated transport, and verifies URLs, request methods, authentication headers and payloads. docs:validate runs this integration test. The guidance now scopes Chat Completions to models supporting that operation.

Validation: executable-client test passed; three existing provider-guide steps passed; typecheck, lint, test-layout, anti-slop and diff whitespace checks passed. The main npm package built; the full build:npm extension pass is still running. This does not claim live inference qualification.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 37e6c40723

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tests/integration/docs/provider-client-examples.test.ts Outdated
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for security reviews. Please try again later.

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your trial has ended. Reactivate Greptile to resume code reviews.

@kwakayama

Copy link
Copy Markdown
Contributor Author

Independent review of e16ad103a: 98/100, no actionable correctness finding.

The executable integration test verifies the actual documented client imports, canonical URLs, API key headers and request bodies. Its test and all three provider-guide cases pass after the canonical Messages update. Production POST /ai/v1/messages was independently probed and returned the Anthropic authentication envelope (401), confirming route availability without claiming authenticated inference.

Exact-head CI/review gates remain pending. The complete npm build is still running its package compatibility phase; the main package and extension emission have completed.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e16ad103a6

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/guides/providers.md Outdated
@kwakayama

Copy link
Copy Markdown
Contributor Author

Diagnosed CI typecheck failure at job108717076268: generate-embedded-npm-packages freshness check fails because the new official client lock entries were not reflected in the committed generated manifest. Prepared the deterministic ten-line manifest update (clients, transitive packages, and constraints). Generator freshness/focused tests pass; independent delta review98/100. Full deno task typecheck is running. No source type error was reported in the failed job, and no other CI failures are currently published.

@kwakayama

Copy link
Copy Markdown
Contributor Author

Fixed the CI manifest freshness failure in c99a961 with a deterministic generated package/constraint update. Full deno task typecheck passes; generator freshness and focused generator tests pass; final full-branch review found no actionable defects and independently passed the official-client snippet and providers-guide tests. Independent delta review98/100. Rechecked author head and existing failures before the single normal fast-forward push; no other published CI failure required a source change. New exact-head CI remains required.

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your trial has ended. Reactivate Greptile to resume code reviews.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for security reviews. Please try again later.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c99a9611d9

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/guides/providers.md Outdated

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your trial has ended. Reactivate Greptile to resume code reviews.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for security reviews. Please try again later.

@github-actions

Copy link
Copy Markdown

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for security reviews. Please try again later.

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your trial has ended. Reactivate Greptile to resume code reviews.

@kwakayama kwakayama removed the needs-human-input Maintainer action required label Sep 29, 2026
@github-actions

Copy link
Copy Markdown

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e2b10bab72

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread docs/guides/providers.md
@kwakayama

Copy link
Copy Markdown
Contributor Author

Codex review for exact head e2b10bab72c6e3d3fe15d6d887fceef682b017b3 against c13795842c7f042ce92d35bfbf009cb478109a43.

Finding

[HIGH] Prevent the OpenAI example from falling back to an ambient vendor credential
Files: docs/guides/providers.md:94-97, tests/integration/docs/provider-client-examples.test.ts:48-53

The documented constructor passes apiKey: process.env.VERYFRONT_API_KEY. With the pinned official OpenAI 7.23.0 client, an undefined value activates its default process.env.OPENAI_API_KEY. I reproduced the documented configuration with VERYFRONT_API_KEY absent and OPENAI_API_KEY=vendor-key-must-not-be-sent; the request to https://api.veryfront.com/ai/v1/chat/completions carried Authorization: Bearer vendor-key-must-not-be-sent. This contradicts the guide's separate-credential contract and can disclose a model-vendor secret to the gateway. The regression test supplies VERYFRONT_API_KEY and an ambient ANTHROPIC_API_KEY, but no ambient OPENAI_API_KEY, so it cannot catch this path.

Fix: Read and validate VERYFRONT_API_KEY before constructing OpenAI, then pass the proven nonempty string. Add a regression case with the Veryfront key absent and OPENAI_API_KEY set that proves the snippet fails before fetch and never emits the vendor key; retain the present success-path assertion.

Verification

  • Inspected the complete six-file diff and relevant gateway routing, served-catalog, unknown-vendor, documentation, and official-client tests.
  • Confirmed the PR head/base stayed pinned to the SHAs above and all 9 review threads are resolved.
  • On repository-pinned Deno 2.7.7: provider-client snippet test passed (1 test/1 step), guide example tests passed (43 tests/70 steps), and served-only unknown-provider coverage passed (1 test/13 steps).
  • Format check and the new integration-test type check passed locally. Exact-head CI had format, typecheck, integration-client coverage, npm compatibility, and browser E2E green when reviewed; remaining jobs were still pending.
  • Gap: no live gateway or vendor-network call was made; transport was captured locally as intended.

The neutral OpenAI and Anthropic URLs, bearer authentication for Anthropic, catalog URL, isolated lockfile, and tolerant unlisted-provider routing otherwise match the acceptance context. The credential fallback above blocks approval.

Review-Gate:
Reviewer: Codex
Reviewed-SHA: e2b10ba
Score: 68/100
Actionable-Findings: 1
Verdict: REQUEST_CHANGES

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your trial has ended. Reactivate Greptile to resume code reviews.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for security reviews. Please try again later.

@github-actions

Copy link
Copy Markdown

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Keep it up!

Reviewed commit: 906f47994c

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

@kwakayama

Copy link
Copy Markdown
Contributor Author

Codex fresh review

Reviewed exact head 906f47994c3b4ba4df546d0a472cba6aa17747b3 against base c13795842c7f042ce92d35bfbf009cb478109a43.

Findings

  • [MEDIUM] The new missing-key regression test does not type-check. tests/integration/docs/provider-client-examples.test.ts:182 reads error.message, but the repository assertRejects returns unknown. A strict check reports TS18046. Narrow with assertInstanceOf(error, Error) before reading the message, or use the established explicit cast pattern.
  • [MEDIUM] The curl examples still omit the project-key setup step. docs/guides/providers.md:66-77 says the examples read VERYFRONT_API_KEY, but never assigns or exports it. A reader following the catalog and inference curl blocks gets an empty bearer value. Add a safe export VERYFRONT_API_KEY="<API_KEY>" example before the first request.
  • [MEDIUM] The unknown-vendor guidance is not exercised by an external-client snippet. tests/docs/guide-code-examples.test.ts:248-253 only calls the internal route helper and checks placeholder text; it sends no unknown-vendor request. The official-client test instead asserts the known mistral/mistral-small-2503 body at tests/integration/docs/provider-client-examples.test.ts:164-167. Execute a documented served-only or otherwise unlisted provider/model through the official client and assert its URL and body.

Verification

  • Confirmed the OpenAI snippet now requires VERYFRONT_API_KEY, passes it explicitly as apiKey, and does not fall back to ambient OPENAI_API_KEY; the test also keeps an ambient Anthropic key and verifies no x-api-key header.
  • Confirmed documented routes: catalog GET /ai/models; OpenAI inference /ai/v1/chat/completions; Anthropic SDK base /ai resolving to /ai/v1/messages.
  • Pinned Deno 2.7.7: provider-client test 2/2 steps passed; provider guide route test 3/3 passed; push divergence suite 24/24 passed; formatting and git diff --check passed.
  • Strict check of the modified TypeScript files fails on the line 182 error above.
  • CI snapshot: 28 passed, 14 pending, 1 failed, 10 skipped. The macOS failure is a dependency-cache download error for sql.js@1.14.1; remaining checks must settle.

Verdict: REQUEST CHANGES

Score: 80/100

Review-Gate:
Reviewer: Codex
Reviewed-SHA: 906f479
Score: 80/100
Actionable-Findings: 3
Verdict: REQUEST_CHANGES

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your trial has ended. Reactivate Greptile to resume code reviews.

@kwakayama

Copy link
Copy Markdown
Contributor Author

Addressed the three findings from the review of 906f479 in commit a330e95:

  • Narrowed the rejection result with an Error check before reading its message.
  • Added an explicit shell export for VERYFRONT_API_KEY and retained the guard that refuses to fall back to OPENAI_API_KEY.
  • Added an official-client integration case that sends an unrecognized vendor/model identifier unchanged; renamed the route-helper test so it describes exactly what it checks.

Pinned Deno 2.7.7 verification: provider client integration 3 steps pass; guide code examples 43 tests / 71 steps pass; format and diff checks pass; targeted typecheck passes with the repo's required sloppy-imports option. Plain deno check without that option stops on the pre-existing extension import resolution in src/extensions/websocket. GitHub CI for the new head is running.

@github-actions

Copy link
Copy Markdown

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for security reviews. Please try again later.

@kwakayama

Copy link
Copy Markdown
Contributor Author

Codex exact-head review

Reviewed SHA: a330e95
Base SHA: c137958

Findings: none actionable.

Evidence:

  • Spec compliance: the provider guide now gives project-key setup, client installation, the served GET /ai/models catalog endpoint, OpenAI and Anthropic examples, and the inside-Veryfront model form.
  • Authentication: the OpenAI example rejects a missing VERYFRONT_API_KEY before the OpenAI SDK can inherit OPENAI_API_KEY. The Anthropic example sets apiKey to null and uses authToken, and the official-client test asserts Authorization bearer auth plus absence of x-api-key while hostile vendor-key fixtures are present.
  • URLs and clients: official OpenAI 7.23.0 and Anthropic 0.128.0 constructors are exercised. Captured requests are POST /ai/v1/chat/completions and POST /ai/v1/messages, matching the gateway routing implementation. GET /ai/models matches the catalog client.
  • Unknown vendors: the official OpenAI client test replaces the documented model with acme-labs/model-not-in-the-built-in-catalog and asserts the exact model id reaches the neutral request body.
  • Docs and scope: the README AI Gateway link resolves successfully. The added push-test change only removes filesystem directory-order dependence while retaining the exact write multiset and conflict assertions.
  • Diagnostics: a fresh targeted Deno check passed for tests/integration/docs/provider-client-examples.test.ts. Current exact-head CI has format, typecheck, test-layout, integration-client coverage, Windows localhost routing, RSC browser E2E, proxy binary, dependency audit, and other jobs green.

Verification gap: exact-head CI is still in progress, including lint, integration, binary E2E, coverage shards, Playwright, analysis, and profile jobs. This review does not wait on or claim completion of those checks.

Verdict: APPROVE
Score: 97/100

Review-Gate:
Reviewer: Codex
Reviewed-SHA: a330e95
Score: 97/100
Actionable-Findings: 0
Verdict: APPROVE

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Breezy!

Reviewed commit: a330e95862

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

@kwakayama
kwakayama enabled auto-merge September 29, 2026 01:20
@sonarqubecloud

Copy link
Copy Markdown

@kwakayama
kwakayama added this pull request to the merge queue Sep 29, 2026
Merged via the queue into main with commit 858ea1d Sep 29, 2026
68 checks passed
@kwakayama
kwakayama deleted the docs/aigw-providers-neutral-snippets branch September 29, 2026 01:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants