Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -83,6 +83,7 @@ cleans up after itself.
the models included in your subscription.
2. **API keys (BYOK).** Paste a key from OpenRouter, Anthropic, OpenAI, xAI,
Google Gemini, Amazon Bedrock, Vercel AI Gateway,
Cloudflare AI Gateway, Cloudflare Workers AI,
Baseten, Together AI, Moonshot AI (Kimi), Kimi for Coding, MiniMax,
Z.AI (including Coding Plan), OpenCode Zen / Go, or GitHub Copilot.

Expand Down Expand Up @@ -243,7 +244,8 @@ it runs.
**What models does it support?**
Two options. Connect your ChatGPT Plus or Pro subscription directly (no API key
needed), or paste an API key from OpenRouter, Anthropic, OpenAI, xAI, Google
Gemini, Amazon Bedrock, Vercel AI Gateway, Baseten,
Gemini, Amazon Bedrock, Vercel AI Gateway, Cloudflare AI Gateway,
Cloudflare Workers AI, Baseten,
Together AI, Moonshot AI (Kimi), Kimi for Coding, MiniMax, Z.AI (including
Coding Plan), OpenCode Zen / Go, or GitHub Copilot.

Expand Down
16 changes: 12 additions & 4 deletions SELF_HOSTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -407,11 +407,19 @@ model. When unset, exploration falls back to the task's active coding model:
R_EXPLORE_MODEL=openrouter/openai/gpt-5.6-luna
```

The provider is the first segment of the model id. Roomote forwards these
common provider keys into worker containers:
The provider is the first segment of the model id. Configure these common
provider keys on the Roomote control plane. When the inference gateway is
enabled, API tokens stay on the control plane and sandboxes authenticate with
a run token. Non-secret identity values such as account IDs and gateway IDs
remain available to the task runtime:

- `OPENROUTER_API_KEY`
- `AI_GATEWAY_API_KEY` (Vercel AI Gateway, `vercel/...` models)
- `CLOUDFLARE_AI_GATEWAY_API_TOKEN`, `CLOUDFLARE_AI_GATEWAY_ACCOUNT_ID`,
and `CLOUDFLARE_AI_GATEWAY_ID` (Cloudflare AI Gateway,
`cloudflare-ai-gateway/...` models)
- `CLOUDFLARE_WORKERS_AI_API_TOKEN` and `CLOUDFLARE_WORKERS_AI_ACCOUNT_ID`
(Cloudflare Workers AI, `cloudflare-workers-ai/...` models)
- `OPENAI_API_KEY`
- `ANTHROPIC_API_KEY`
- `MOONSHOT_API_KEY`
Expand All @@ -433,8 +441,8 @@ R_MODEL_ENV_KEYS=CUSTOM_PROVIDER_API_KEY
CUSTOM_PROVIDER_API_KEY=...
```

The checked-in Compose files forward the common provider keys above and the
sample `CUSTOM_PROVIDER_API_KEY`. If you use a different custom provider key
The checked-in Compose files accept the common provider keys above and the
sample `CUSTOM_PROVIDER_API_KEY` on the control-plane services. If you use a different custom provider key
name in a Compose deployment, add that key to the service environment block or
provide it through your deployment secret mechanism.

Expand Down
210 changes: 210 additions & 0 deletions apps/api/src/handlers/inference/__tests__/inference-gateway.test.ts

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

9 changes: 9 additions & 0 deletions apps/api/src/handlers/inference/index.ts
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@ import { Hono } from 'hono';
import {
formatSingleLineLog,
rebaseRoomoteModelIdToUpstream,
rewriteCloudflareAiGatewayRequestBody,
ROOMOTE_INFERENCE_PROVIDER_ID,
} from '@roomote/types';
import {
Expand Down Expand Up @@ -452,6 +453,14 @@ inference.on(['POST', 'GET'], '/:provider/*', async (c) => {
}
}

// Cloudflare /ai/v1 expects models.dev's hosted Workers AI slugs without
// the `workers-ai/` catalog namespace the AI Gateway provider uses.
if (providerId === 'cloudflare-ai-gateway' && method === 'POST') {
const bodyText = await c.req.text();
requestBody = rewriteCloudflareAiGatewayRequestBody(bodyText);
useDuplexHalf = false;
}

// Roomote model ids are an aliased namespace over OpenRouter; rewrite a
// catalog-id model reference onto the upstream slug OpenRouter expects.
if (providerId === ROOMOTE_INFERENCE_PROVIDER_ID && method === 'POST') {
Expand Down
41 changes: 38 additions & 3 deletions apps/api/src/handlers/inference/registry.ts
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
import {
CHATGPT_ACCOUNT_ID_HEADER,
getInferenceGatewayProvider,
INFERENCE_GATEWAY_IDENTITY_PATTERN,
INFERENCE_GATEWAY_RESOURCE_PATTERN,
INFERENCE_GATEWAY_REGION_PATTERN,
ROOMOTE_INFERENCE_PROVIDER_ID,
Expand Down Expand Up @@ -126,23 +127,57 @@ export async function resolveGatewayUpstream(
};
}

const requiredHeaders = await resolveRequiredForwardHeaders(provider);

return {
ok: true,
resolved: {
upstreamUrl: `${upstreamBaseUrl}${upstreamPath}${search}`,
headers:
apiKey && provider.authHeader
headers: {
...requiredHeaders,
...(apiKey && provider.authHeader
? {
[provider.authHeader.name]: formatProviderAuthHeaderValue(
provider,
apiKey,
),
}
: {},
: {}),
},
},
};
}

async function resolveRequiredForwardHeaders(
provider: InferenceGatewayProvider,
): Promise<Record<string, string>> {
if (!provider.requiredHeaders?.length) {
return {};
}

const headers: Record<string, string> = {};

for (const spec of provider.requiredHeaders) {
const value = await resolveModelProviderEnvValue([spec.envVarName]);

if (!value) {
throw new Error(
`${spec.envVarName} must be configured for ${provider.name}.`,
);
}

if (!INFERENCE_GATEWAY_IDENTITY_PATTERN.test(value)) {
throw new Error(
`${spec.envVarName} must be a valid identity value for ${provider.name}. Received "${value}".`,
);
}

headers[spec.headerName] = value;
}

return headers;
}

/**
* xAI supports both SuperGrok OAuth and a BYOK API key. Prefer a connected
* subscription (fresh access token) so subscription users never need a key;
Expand Down
2 changes: 2 additions & 0 deletions apps/docs/docs.json
Original file line number Diff line number Diff line change
Expand Up @@ -78,6 +78,8 @@
"providers/inference/azure-foundry",
"providers/inference/azure-openai",
"providers/inference/baseten",
"providers/inference/cloudflare-ai-gateway",
"providers/inference/cloudflare-workers-ai",
"providers/inference/chatgpt",
"providers/inference/deepseek",
"providers/inference/github-copilot",
Expand Down
7 changes: 6 additions & 1 deletion apps/docs/environment-variables.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -213,7 +213,12 @@ manifest changes.
| `REQUESTY_API_KEY` | Provider key | Requesty API key. Can also be saved from **Settings > Models**. |
| `AI_GATEWAY_API_KEY` | Provider key | Vercel AI Gateway API key. |
| `BASETEN_API_KEY` | Provider key | Baseten API key. |
| `TOGETHER_API_KEY` | Provider key | Together AI API key. |
| `TOGETHER_API_KEY` | Provider key | Together AI API key.
| `CLOUDFLARE_AI_GATEWAY_API_TOKEN` | Provider key | Cloudflare AI Gateway API token. Does not connect Workers AI.
| `CLOUDFLARE_AI_GATEWAY_ACCOUNT_ID` | Provider config | Cloudflare account ID for AI Gateway requests.
| `CLOUDFLARE_AI_GATEWAY_ID` | Provider config | Cloudflare AI Gateway ID, for example `default`.
| `CLOUDFLARE_WORKERS_AI_API_TOKEN` | Provider key | Cloudflare Workers AI API token. Does not connect AI Gateway.
| `CLOUDFLARE_WORKERS_AI_ACCOUNT_ID` | Provider config | Cloudflare account ID for Workers AI requests. A gateway ID is not used. |
| `DEEPSEEK_API_KEY` | Provider key | DeepSeek API key. Can also be saved from **Settings > Models**. |
| `OPENAI_API_KEY` | Provider key | OpenAI API key. |
| `AZURE_API_KEY` | Provider key | Azure OpenAI API key. |
Expand Down
2 changes: 2 additions & 0 deletions apps/docs/models.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -73,6 +73,8 @@ These connections use metered API billing or a provider-managed gateway:
| [Azure AI Foundry](/providers/inference/azure-foundry) | Azure AI Services API key and resource name | Azure subscription |
| [Azure OpenAI](/providers/inference/azure-openai) | Azure OpenAI API key and resource name | Azure subscription |
| [Baseten](/providers/inference/baseten) | Baseten API key | Baseten workspace |
| [Cloudflare AI Gateway](/providers/inference/cloudflare-ai-gateway) | Cloudflare API token, account ID, and gateway ID | Cloudflare account |
| [Cloudflare Workers AI](/providers/inference/cloudflare-workers-ai) | Cloudflare API token and account ID | Cloudflare account |
| [DeepSeek](/providers/inference/deepseek) | DeepSeek API key | DeepSeek platform balance |
| [Google Gemini](/providers/inference/google-gemini) | Google AI Studio key | Google Cloud project |
| [MiniMax](/providers/inference/minimax) | MiniMax API key | MiniMax account |
Expand Down
Loading
Loading