Providers & Models

Where every AI credential, model and search path actually comes from — and where to change it.

This app exists because that question had no single answer. Tracing one provider key on 2026-08-24 meant reading a ConfigMap, three Key Vaults, a CSI SecretProviderClass, a git repo and the mesh. Four separate incidents that week came down to "which of those is the source of truth?"

What it shows

The rule it makes visible

A credential has ONE administered home: the ModelProvider node. Configuration is a SEED into it, never a parallel live source.

ProviderCredentialSeed fills an empty key on the node from {Section}:ApiKey on every boot, and the value is stored encrypted. So a key configured after the node was created converges instead of being invisible forever — and there is never an env key and a node key disagreeing silently.

Set one up

Set up AI providers — one card per provider you can see, with the fields it actually needs and the models it exposes.

🚨 Never store a literal key by hand. Enter it on that form:

Contents

Reconnecting…
The connection to the server was interrupted. Trying to restore it…
Trying again…
The connection could not be restored. Reloading the page…
The server was updated. Reloading the page to pick up the latest version.