Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
29 changes: 22 additions & 7 deletions docs-site/src/content/docs/guides/providers.md
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,7 @@ labels local presets separately; those normally omit both `authMode` and `apiKey
| --- | --- | --- |
| `key` | Sends your API key (`Authorization: Bearer …`, or `x-api-key` / `api-key` per adapter). The key may be a literal or an `${ENV_VAR}` reference. | Most providers. |
| `forward` | Relays **your incoming Codex auth headers** verbatim to the provider — no key stored. This is the ChatGPT-login passthrough. | OpenAI (`openai-responses` adapter). |
| `oauth` | Resolves a stored OAuth access token (auto-refreshed before expiry) and uses it as the bearer key. | xAI, Anthropic, Kimi, Kiro, Google Antigravity, Cursor, GitHub Copilot. |
| `oauth` | Resolves a stored access token (refreshed or re-imported according to provider policy) and uses it as the bearer key. | xAI, Anthropic, Kimi, Kiro, Google Antigravity, Cursor, GitHub Copilot, WorkBuddy. |

## 1. ChatGPT login (forward / passthrough)

Expand All @@ -63,9 +63,9 @@ The ChatGPT passthrough catalog also layers in the bare GPT-5.6 Sol/Terra/Luna s

## 2. Account login (OAuth)

Six provider presets use OAuth login — plus GitHub Copilot via an experimental unofficial
device-flow bridge. opencodex stores their credentials in
`~/.opencodex/auth.json` and refreshes them automatically. `chatgpt` is also accepted by the login
Eight provider presets use account login. GitHub Copilot uses an experimental unofficial
device-flow bridge, while WorkBuddy imports its signed-in desktop session. opencodex stores their credentials in
`~/.opencodex/auth.json` and follows each provider's refresh policy. `chatgpt` is also accepted by the login
CLI; it acquires a ChatGPT credential while creating a `forward`-mode provider entry.

```bash
Expand All @@ -76,6 +76,7 @@ ocx login kiro # import kiro-cli credentials (or token fallback)
ocx login google-antigravity
ocx login cursor # standalone Cursor PKCE login
ocx login github-copilot # GitHub device flow → Copilot token (Copilot Pro/Business)
ocx login workbuddy # import the current WorkBuddy desktop session (macOS)
ocx login chatgpt # standalone ChatGPT OAuth login
ocx logout <provider>
```
Expand All @@ -89,6 +90,7 @@ ocx logout <provider>
| `google-antigravity` | `google` | `https://daily-cloudcode-pa.googleapis.com` | Google OAuth over the Cloud Code Assist wire. |
| `cursor` | `cursor` | `https://api2.cursor.sh` | Experimental PKCE login, live HTTP/2 transport, and account-filtered model discovery. |
| `github-copilot` | `openai-chat` | `https://api.githubcopilot.com` | Experimental. GitHub device flow + `copilot_internal` exchange (VS Code OAuth client). Requires an active Copilot subscription; not an official third-party API. |
| `workbuddy` | `openai-chat` | `https://copilot.tencent.com/v2` | Experimental. Imports the current WorkBuddy desktop session and sends WorkBuddy's required client headers. |

For the canonical Kimi Coding Plan presets (`kimi` account login and `kimi-code` API key),
opencodex forwards only a caller-supplied stable `prompt_cache_key` to the Chat Completions request;
Expand All @@ -105,7 +107,8 @@ OAuth providers whose credentials include a stable account id or email can keep
login. The Providers page shows those accounts in a dropdown, lets you add another, and switches the
active account without logging the others out. Only identity-less Kimi credentials replace the
active slot; Kiro accounts are keyed by profile ARN. `chatgpt` is always single-slot because Codex
pool accounts have a separate ledger.
pool accounts have a separate ledger. WorkBuddy is also single-slot because its current desktop
session is the credential authority.
Tokens stay in `~/.opencodex/auth.json`; `/api/oauth/accounts` returns masked metadata only.

### OAuth reliability
Expand Down Expand Up @@ -183,10 +186,22 @@ from the live CLI store, or when an existing primary CLI database has no recogni
Repair or remove the unreadable database under the normal `kiro-cli` data path, unset those import
selectors, then retry. Signing in from a machine with no existing `kiro-cli` session is unaffected.

### WorkBuddy desktop session import

Open WorkBuddy and sign in before running `ocx login workbuddy`. On macOS, opencodex reads
`~/Library/Application Support/CodeBuddyExtension/Data/Public/auth/workbuddy-desktop.info`; set
`WORKBUDDY_AUTH_FILE` when the session file is stored elsewhere.

The import reads only the current access token, expiry, account id, and domain. WorkBuddy keeps
ownership of refresh rotation: opencodex stores an external-session sentinel instead of copying the
desktop refresh token, and re-imports the current access token before routed requests and after an
upstream `401`. The integration is unofficial and may require updates when WorkBuddy changes its
desktop session or request format.

## 3. API-key catalog

opencodex ships 53 built-in presets: 42 key-based, seven OAuth, three local, and the default
ChatGPT-forward preset. The dashboard's **Add provider** picker opens a key provider's dashboard,
opencodex ships a built-in catalog of key-based, OAuth, local, and default ChatGPT-forward presets.
The dashboard's **Add provider** picker opens a key provider's dashboard,
validates the key, and stores it. Notable entries:

| Provider | Base URL |
Expand Down
24 changes: 18 additions & 6 deletions docs-site/src/content/docs/ja/guides/providers.md
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ max input 922,000 で `*-pro` virtual ID は公開状態を維持し、wire で
--- | --- | --- |
| `key` | API キーを送信します(`Authorization: Bearer …`、またはアダプターにより `x-api-key` / `api-key`)。キーはリテラルまたは `${ENV_VAR}` 参照です。 | 大半のプロバイダー。 |
| `forward` | **受け取った Codex 認証ヘッダーを**プロバイダーにそのまま中継します — キーを保存しません。ChatGPT ログインのパススルーです。 | OpenAI(`openai-responses` アダプター)。 |
| `oauth` | 保存された OAuth アクセストークンを読み込み bearer キーとして使い、期限切れ前に自動更新します。 | xAI、Anthropic、Kimi、Kiro、Google Antigravity、Cursor。 |
| `oauth` | 保存されたアクセストークンを読み込み、プロバイダーのポリシーに従って更新または再取り込みし、bearer キーとして使います。 | xAI、Anthropic、Kimi、Kiro、Google Antigravity、Cursor、GitHub Copilot、WorkBuddy。 |

## 1. ChatGPT ログイン(forward / パススルー)

Expand All @@ -60,8 +60,8 @@ ChatGPT パススルーカタログには GPT-5.6 Sol/Terra/Luna の名前空間

## 2. アカウントログイン(OAuth)

OAuth ログインを使うプロバイダープリセットは 6 つです。認証情報は
`~/.opencodex/auth.json` に保存され、自動更新されます。ログイン CLI は `chatgpt` も受け付けます。
アカウントログインを使うプロバイダープリセットは 8 つです。認証情報は
`~/.opencodex/auth.json` に保存され、各プロバイダーの更新ポリシーに従います。ログイン CLI は `chatgpt` も受け付けます。
このコマンドは ChatGPT 認証情報を発行し `forward` モードのプロバイダーエントリを作成します。

```bash
Expand All @@ -71,6 +71,8 @@ ocx login kimi # Moonshot Kimi
ocx login kiro # kiro-cli 認証情報の取り込み(トークンフォールバック対応)
ocx login google-antigravity
ocx login cursor # Cursor 専用 PKCE ログイン
ocx login github-copilot # GitHub device flow → Copilot トークン
ocx login workbuddy # 現在の WorkBuddy デスクトップセッションを取り込む (macOS)
ocx login chatgpt # 別途 ChatGPT OAuth ログイン
ocx logout <provider>
```
Expand All @@ -83,6 +85,8 @@ ocx logout <provider>
| `kiro` | `kiro` | `https://runtime.us-east-1.kiro.dev` | 初回ログインは Kiro CLI をインストール(`curl -fsSL https://cli.kiro.dev/install | bash`)し、`kiro-cli login` でサインインした既存セッションを取り込みます。**アカウントを追加**は `kiro-cli` をログアウトして新しいブラウザログインを開始し、`kiro-cli` 自体のアカウントを切り替えてアカウント別プロファイルメタデータを保存します。既存の OpenCodex アカウントは保持され、キャンセルまたは失敗時には以前の `kiro-cli` セッションが復元されます。 |
| `google-antigravity` | `google` | `https://daily-cloudcode-pa.googleapis.com` | Google OAuth を Cloud Code Assist wire で使用。 |
| `cursor` | `cursor` | `https://api2.cursor.sh` | 実験的 PKCE ログイン、HTTP/2 トランスポート、アカウント別モデル探索をサポート。 |
| `github-copilot` | `openai-chat` | `https://api.githubcopilot.com` | 実験的な非公式 device-flow ブリッジ。 |
| `workbuddy` | `openai-chat` | `https://copilot.tencent.com/v2` | 実験的。現在の WorkBuddy デスクトップセッションを取り込み、必要なクライアントヘッダーを送信します。 |

正規の Kimi Coding Plan プリセット(`kimi` アカウントログインと `kimi-code` API key)では、
opencodex は呼び出し元が指定した安定した `prompt_cache_key` だけを Chat Completions リクエストへ
Expand All @@ -98,7 +102,7 @@ opt-in した上流がこのフィールドを拒否しても、opencodex はフ
認証情報に固定アカウント ID やメールがある OAuth プロバイダーはログインを複数保持できます。
Providers ページでアカウントを追加し、別アカウントをログアウトせずにアクティブアカウントだけを切り替えられます。
アカウント識別情報がない Kimi 認証情報だけがアクティブスロットを差し替え、Kiro アカウントはプロファイル ARN をキーに保存されます。
`chatgpt` は Codex アカウントプールに別の保存場所があり、常に単一スロットのみ書き込みます。トークンは `~/.opencodex/auth.json` に保存され、
`chatgpt` は Codex アカウントプールに別の保存場所があり、常に単一スロットのみ書き込みます。WorkBuddy も現在のデスクトップセッションを正として単一スロットを使います。トークンは `~/.opencodex/auth.json` に保存され、
`/api/oauth/accounts` はマスク済みメタデータのみを返します。

### Kiro 認証情報の取り込み
Expand All @@ -114,10 +118,18 @@ Kiro のログインには Kiro CLI が必要です。`curl -fsSL https://cli.ki

ロールバックはスナップショットがある場合にのみ可能なため、セッションストアが存在するのに取得できない場合(ファイルが読めない、スキーマの不一致、トークン選択があいまい)、`KIROCLI_DB_PATH` / `KIRO_CLI_DB_FILE` が実際の CLI ストアと異なるインポート先を指す場合、またはプライマリ CLI データベースに認識できるトークン行がない場合、**アカウントを追加**は `kiro-cli` のログアウトを拒否します。通常の `kiro-cli` データパス上の壊れたデータベースを修復または削除し、インポート専用セレクタが設定されていれば解除してから再試行してください。既存の `kiro-cli` セッションがまったくない環境には影響しません。

### WorkBuddy デスクトップセッションの取り込み

`ocx login workbuddy` の前に WorkBuddy を開いてサインインしてください。macOS では
`~/Library/Application Support/CodeBuddyExtension/Data/Public/auth/workbuddy-desktop.info` を読みます。
別の場所にある場合は `WORKBUDDY_AUTH_FILE` を設定します。アクセストークン、有効期限、アカウント ID、
ドメインだけを読み取り、デスクトップのリフレッシュトークンはコピーしません。この非公式連携は
WorkBuddy のセッション形式やリクエスト形式が変わると更新が必要になる場合があります。

## 3. API キーカタログ

opencodex v2.7.1 には組み込みプリセットが 50 個含まれています。キー方式 40、OAuth 6、ローカル 3、
デフォルト ChatGPT 転送プリセット 1 です。ダッシュボードの **Add provider** ピッカーはキー発行ページを開き、
opencodex にはキー方式、OAuth、ローカル、デフォルト ChatGPT 転送の組み込みカタログがあります。
ダッシュボードの **Add provider** ピッカーはキー発行ページを開き、
入力したキーを検証した後保存します。主な項目は以下のとおりです:

| プロバイダー | ベース URL |
Expand Down
24 changes: 18 additions & 6 deletions docs-site/src/content/docs/ko/guides/providers.md
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ shipped v1 config는 marker 2의 단일 옵션 행으로 자동 이관됩니다.
| --- | --- | --- |
| `key` | API 키를 전송합니다(`Authorization: Bearer …`, 또는 어댑터에 따라 `x-api-key` / `api-key`). 키는 리터럴이거나 `${ENV_VAR}` 참조일 수 있습니다. | 대부분의 프로바이더. |
| `forward` | **수신된 Codex 인증 헤더를** 프로바이더에 그대로 중계합니다 — 키를 저장하지 않습니다. ChatGPT 로그인 패스스루입니다. | OpenAI (`openai-responses` 어댑터). |
| `oauth` | 저장된 OAuth 액세스 토큰을 불러와 bearer 키로 사용하며, 만료 전에 자동 갱신합니다. | xAI, Anthropic, Kimi, Kiro, Google Antigravity, Cursor. |
| `oauth` | 저장된 액세스 토큰을 불러와 프로바이더 정책에 따라 갱신하거나 다시 가져온 뒤 bearer 키로 사용합니다. | xAI, Anthropic, Kimi, Kiro, Google Antigravity, Cursor, GitHub Copilot, WorkBuddy. |

## 1. ChatGPT 로그인 (forward / 패스스루)

Expand All @@ -60,8 +60,8 @@ ChatGPT 패스스루 카탈로그에는 GPT-5.6 Sol/Terra/Luna의 네임스페

## 2. 계정 로그인 (OAuth)

OAuth 로그인을 사용하는 프로바이더 프리셋은 여섯 개입니다. 자격 증명은
`~/.opencodex/auth.json`에 저장되고 자동으로 갱신됩니다. 로그인 CLI는 `chatgpt`도 받습니다.
계정 로그인을 사용하는 프로바이더 프리셋은 여덟 개입니다. 자격 증명은
`~/.opencodex/auth.json`에 저장되고 각 프로바이더의 갱신 정책을 따릅니다. 로그인 CLI는 `chatgpt`도 받습니다.
이 명령은 ChatGPT 자격 증명을 발급받고 `forward` 모드 프로바이더 항목을 만듭니다.

```bash
Expand All @@ -71,6 +71,8 @@ ocx login kimi # Moonshot Kimi
ocx login kiro # kiro-cli 자격 증명 가져오기(토큰 폴백 지원)
ocx login google-antigravity
ocx login cursor # Cursor 전용 PKCE 로그인
ocx login github-copilot # GitHub device flow → Copilot 토큰
ocx login workbuddy # 현재 WorkBuddy 데스크톱 세션 가져오기 (macOS)
ocx login chatgpt # 별도 ChatGPT OAuth 로그인
ocx logout <provider>
```
Expand All @@ -83,6 +85,8 @@ ocx logout <provider>
| `kiro` | `kiro` | `https://runtime.us-east-1.kiro.dev` | 최초 로그인은 Kiro CLI를 설치(`curl -fsSL https://cli.kiro.dev/install | bash`)하고 `kiro-cli login`으로 로그인한 기존 세션을 가져옵니다. **계정 추가**는 `kiro-cli`에서 로그아웃한 뒤 새 브라우저 로그인을 시작하여 `kiro-cli` 자체의 계정을 전환하고, 계정별 프로필 메타데이터를 저장합니다. 기존 OpenCodex 계정은 유지되며, 취소되거나 실패하면 이전 `kiro-cli` 세션을 복원합니다. |
| `google-antigravity` | `google` | `https://daily-cloudcode-pa.googleapis.com` | Google OAuth를 Cloud Code Assist wire로 사용합니다. |
| `cursor` | `cursor` | `https://api2.cursor.sh` | 실험적 PKCE 로그인, HTTP/2 전송, 계정별 모델 탐색을 지원합니다. |
| `github-copilot` | `openai-chat` | `https://api.githubcopilot.com` | 실험적인 비공식 device-flow 브리지입니다. |
| `workbuddy` | `openai-chat` | `https://copilot.tencent.com/v2` | 실험적입니다. 현재 WorkBuddy 데스크톱 세션을 가져와 필요한 클라이언트 헤더를 전송합니다. |

정식 Kimi Coding Plan 프리셋(`kimi` 계정 로그인과 `kimi-code` API key)의 경우, opencodex는
호출자가 제공한 안정적인 `prompt_cache_key`만 Chat Completions 요청으로 전달하며 직접 생성하지
Expand All @@ -98,7 +102,7 @@ deny-by-default 상태로 유지됩니다.
자격 증명에 고정된 계정 id나 이메일이 있는 OAuth 프로바이더는 로그인을 여러 개 보관할 수 있습니다.
Providers 페이지에서 계정을 추가하고, 다른 계정을 로그아웃하지 않은 채 활성 계정만 바꿀 수 있습니다.
계정 식별 정보가 없는 Kimi 자격 증명만 활성 슬롯을 교체하며, Kiro 계정은 프로필 ARN을 키로 저장됩니다.
`chatgpt`는 Codex 계정 풀에 별도 저장소가 있어 항상 단일 슬롯만 씁니다. 토큰은 `~/.opencodex/auth.json`에 저장되고,
`chatgpt`는 Codex 계정 풀에 별도 저장소가 있어 항상 단일 슬롯만 씁니다. WorkBuddy도 현재 데스크톱 세션을 기준으로 단일 슬롯을 사용합니다. 토큰은 `~/.opencodex/auth.json`에 저장되고,
`/api/oauth/accounts`는 마스킹된 메타데이터만 반환합니다.

### Kiro 자격 증명 가져오기
Expand All @@ -114,10 +118,18 @@ Kiro 로그인에는 Kiro CLI가 필요합니다. `curl -fsSL https://cli.kiro.d

롤백은 스냅샷이 있을 때만 가능하므로, 세션 저장소가 존재하지만 캡처할 수 없는 경우(파일을 읽을 수 없음, 스키마 불일치, 토큰 선택 모호), `KIROCLI_DB_PATH` / `KIRO_CLI_DB_FILE`이 실제 CLI 저장소와 다른 가져오기 경로를 가리키는 경우, 또는 기본 CLI 데이터베이스에 인식 가능한 토큰 행이 없는 경우 **계정 추가**는 `kiro-cli` 로그아웃을 거부합니다. 일반 `kiro-cli` 데이터 경로의 손상된 데이터베이스를 수리하거나 제거하고, 가져오기 전용 선택자가 설정돼 있으면 해제한 뒤 다시 시도하세요. 기존 `kiro-cli` 세션이 아예 없는 환경에서는 영향이 없습니다.

### WorkBuddy 데스크톱 세션 가져오기

`ocx login workbuddy`를 실행하기 전에 WorkBuddy를 열고 로그인하세요. macOS에서는
`~/Library/Application Support/CodeBuddyExtension/Data/Public/auth/workbuddy-desktop.info`를 읽습니다.
파일 위치가 다르면 `WORKBUDDY_AUTH_FILE`을 설정하세요. 액세스 토큰, 만료 시각, 계정 ID, 도메인만
읽으며 데스크톱 refresh token은 복사하지 않습니다. 이 비공식 연동은 WorkBuddy의 세션 또는 요청
형식이 바뀌면 업데이트가 필요할 수 있습니다.

## 3. API 키 카탈로그

opencodex v2.7.1에는 빌트인 프리셋이 50개 들어 있습니다. 키 방식 40개, OAuth 6개, 로컬 3개,
기본 ChatGPT 포워드 프리셋 1개입니다. 대시보드의 **Add provider** 선택기는 키 발급 페이지를 열고,
opencodex에는 키 방식, OAuth, 로컬, 기본 ChatGPT 포워드 프리셋의 빌트인 카탈로그가 있습니다.
대시보드의 **Add provider** 선택기는 키 발급 페이지를 열고,
입력한 키를 검증한 뒤 저장합니다. 주요 항목은 다음과 같습니다:

| 프로바이더 | 베이스 URL |
Expand Down
Loading
Loading