Skip to content

models.providers custom pricing never reaches the api-proxy; custom/BYOK models still 400 with unknown_model_ai_credits #47365

Description

@strawgate

The models.providers frontmatter field (added in #38276, documented in the FAQ from #44450) is meant to let you price a model missing from the models.dev catalog so it passes the AI-credits guard. In practice the override reaches the agent-side catalog but is stripped from the api-proxy config, so the proxy still rejects the model with unknown_model_ai_credits before the first turn.

Environment

gh-aw v0.82.14, AWF firewall/api-proxy 0.27.37. claude engine pointed at an Anthropic-compatible endpoint via ANTHROPIC_BASE_URL (BYOK), with ANTHROPIC_MODEL set to a model not in the models.dev catalog.

Repro (pricing supplied exactly per the FAQ)

engine:
  id: claude
  api-target: api.fireworks.ai
  env:
    ANTHROPIC_BASE_URL: https://api.fireworks.ai/inference
    ANTHROPIC_MODEL: accounts/fireworks/models/minimax-m3
models:
  providers:
    anthropic:
      models:
        accounts/fireworks/models/minimax-m3:
          cost: { input: '3e-07', output: '1.5e-06', cache_read: '3e-08', cache_write: '3.75e-07' }

Expected: the api-proxy prices the model from the override and the run proceeds.
Actual: API Error: 400 … unknown_model_ai_credits on turn 1; the agent spends 0 tokens; the harness retries 4× with the same 400.

Root cause (from run artifacts)

The compiler emits the override to the agent-side catalog and to the lock's apiProxy.providers template, but not to what the proxy actually enforces against:

Where minimax priced? used for
activation/models.json (GH_AW_MODELS_JSON_PATH) yes agent-side AIC reporting only
container awf-config.jsonapiProxy noproviders stripped, maxAiCredits: 1000 credit-enforcement gate
proxy api-proxy-logs/models.json no (anthropic.models: null) proxy pricing lookup

So apiProxy.providers is dropped during config resolution, and the agent-side override never propagates into the api-proxy's pricing catalog — leaving the model unknown to the guard.

Also affects threat-detection

The detection sub-agent runs the same model behind its own guardrail (GH_AW_DEFAULT_DETECTION_MAX_AI_CREDITS, default 400) with no override reaching it, so it 400s and every safe-output gets the agentic threat detected / results could not be parsed banner. The main-agent workaround (max-ai-credits: -1, which makes the compiler omit maxAiCredits) isn't available there: the detection config hard-codes maxAiCredits, and -1 is then rejected by the firewall as maxAiCredits must be > 0.

Related

#38276, #44450, #46986 (the BYOK guardrail-skip only checks COPILOT_PROVIDER_*, not custom ANTHROPIC_BASE_URL/OPENAI_BASE_URL), #45923 / #46077.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions