Model Providers

Add each AI provider once. Chat, agents, and every app behind the LLM Proxy can use it, and none of them sees the key. Paste an OpenAI key, sign in with your ChatGPT subscription, or point at your own vLLM server.

The Model Providers page, with personal subscription cards above the provider API keys table

Connect a Provider

Connect with an API key that your company pays for by use, or with a subscription that a person already pays for.

With an API Key

Paste a key, and Archestra tests it and loads the provider's models.

  1. Go to Model Providers in the sidebar and click Add API Key.
  2. Pick the Provider and paste the API Key.
  3. Optionally open Advanced to mark the key Primary, set a Base URL for a proxy or self-hosted endpoint, or add Extra HTTP headers that every request to the provider carries.
  4. Click Test & Create. Archestra calls the provider with the key and syncs its models.

The new key appears in the Provider API keys table as Configured, and its models appear under Models. To choose who can use it, edit the key and open its Permissions tab.

You can also set a key through an environment variable, ARCHESTRA_CHAT_<PROVIDER>_API_KEY (for example ARCHESTRA_CHAT_OPENAI_API_KEY). It is the fallback when no stored key applies.

To hide a provider your company does not use, go to Settings → LLM → Model providers and switch Available off. It leaves every picker, and nobody can add a key for it. Its existing keys keep working. On the same page, you can give a provider a display name.

With a Subscription

Already pay for ChatGPT, GitHub Copilot, Microsoft 365 Copilot, or SuperGrok? Use it instead of a metered API key. On Model Providers, click Connect on the provider's card and sign in.

These credentials belong to one person and cannot be shared. An agent that uses one always runs on the chatting user's own subscription. A user who has not connected sees a sign-in prompt in chat. If the vendor rejects the sign-in later, click Connect again; the credential keeps its model and agent selections.

  • ChatGPT: first turn on Enable device code authorization for Codex in ChatGPT under Settings → Security. It is off by default, and ChatGPT blocks the sign-in until you turn it on.
  • SuperGrok: unavailable when Bring Your Own Secrets uses a read-only external Vault, because Archestra cannot store the rotating sign-in token there. Use an xAI API key instead.
  • GitHub Copilot and Microsoft 365 Copilot have their own pages: GitHub Copilot, Microsoft 365 Copilot.

ChatGPT and SuperGrok use bills $0 in Costs. GitHub Copilot and Microsoft 365 Copilot use counts as metered. See Subscription vs Metered Cost.

Which Key Pays for a Chat

When several keys exist for one provider, the most specific one wins. Your team shares an OpenAI key, and you add your own. Your chats now run on yours, so your use stops counting against the team's key.

Chat and agents take the first match:

OrderKeyExample
1The key picked in the conversationYou switch a chat to the research team's key.
2The key set on the agentA support agent always bills the support team's key.
3Your own keyYou added a personal Anthropic key.
4A key shared with your teamsPlatform Engineering shares one OpenAI key.
5A key shared with the organizationThe company default key.
6The ARCHESTRA_CHAT_<PROVIDER>_API_KEY environment variableThe key set at install time.

When one level has several keys, the Primary key wins, then the oldest one.

  • A subscription is used only by the person who connected it, even when an agent or a conversation picks it. Anyone else uses their own subscription, or gets a sign-in prompt.
  • For vLLM, Ollama, and Azure, each key points at its own server. A key whose server does not host the model you picked is skipped for one that does.
  • Clients that call the proxy pick their key through their authentication method.

Supported Providers

Each provider has its own proxy URL, https://<archestra-host>/v1/<path>, with the provider's own API. A client that works with the provider works with the proxy. Providers marked Router also work through the Model Router. A linked name has a setup page.

ProviderPathAPIsRouterNotes
Amazon BedrockbedrockConverse, InvokeModelYesAPI key, AWS access keys, or IAM role
AnthropicanthropicMessagesYesAlso Claude on Microsoft Foundry and Vertex AI
ArchestraarchestraChat CompletionsNoAnother Archestra instance as the upstream
Azure AI FoundryazureChat Completions, Responses, EmbeddingsYesAPI key or Microsoft Entra ID
CerebrascerebrasChat CompletionsYes
CoherecohereChatYes
DeepSeekdeepseekChat CompletionsYes
GitHub Copilotgithub-copilotChat Completions, ResponsesYesPersonal sign-in only
Google GeminigeminiGenerate Content, EmbeddingsYesGoogle AI Studio or Vertex AI
GroqgroqChat CompletionsYes
JevjevDecisionsNoScores content, such as a tool call. It does not chat. See Jev.
Kimi (Moonshot AI)kimiChat CompletionsNoChina endpoint: set ARCHESTRA_KIMI_BASE_URL to https://api.moonshot.cn/v1
Microsoft 365 Copilotmicrosoft-365-copilotChat CompletionsNoPersonal sign-in only, no tools
MiniMaxminimaxChat CompletionsYesText only
Mistral AImistralChat Completions, EmbeddingsYes
Ollamaollama, ollama-nativeChat Completions, Embeddings, native Chatollama onlyNo key needed
OpenAIopenaiChat Completions, Responses, EmbeddingsYesChatGPT subscription through Connect
OpenAI-compatible serversvllmChat Completions, EmbeddingsYesvLLM, llama.cpp, LM Studio, SGLang, and others
OpenRouteropenrouterChat Completions, EmbeddingsYesSee OpenRouter Free Models
PerplexityperplexityChat Completions, ResponsesYessonar models take no tools; vendor-prefixed models such as anthropic/claude-opus-5 do
xAI (Grok)xaiChat CompletionsYesSuperGrok subscription through Connect
Zhipu AIzhipuaiChat Completions, EmbeddingsYes

Each provider's default endpoint can be changed with its ARCHESTRA_<PROVIDER>_BASE_URL variable, listed under LLM Provider Configuration.

OpenRouter Free Models

OpenRouter's :free model variants cost nothing, though they still need an OpenRouter API key. The providers behind them may use your requests to train models, so do not send sensitive data. The openrouter/free model picks a free model for each request. When you add an OpenRouter key and the organization has no default model, Archestra makes openrouter/free the default.

Jev

Jev is TypeSafe's decision model. It scores content, such as a tool call, and does not chat. Send requests to https://<archestra-host>/v1/jev/decisions with Authorization: Bearer <your-api-key>.

To use Jev through OpenRouter, set the key's base URL to https://openrouter.ai/api/alpha/decisions. To change the default endpoint, set ARCHESTRA_JEV_BASE_URL.

Model Pricing, Limits, and Modalities

Archestra fills in each model's prices, context window, and input types for you. It syncs them from the provider and a public model registry. A self-hosted or very new model can have gaps. Set any value yourself, because each one changes how Archestra treats the model:

DetailWhat it changes
PricingThe cost Archestra records for each request. Wrong prices give wrong cost reports and budgets.
Context windowWhen chat compacts a long conversation.
Max output tokensHow long one answer can be. Without it, a turn asks for 8,192 tokens, which can cut a long answer short.
ModalitiesWhich files chat sends to the model, and which models you can pick for embedding and OCR. A file the model cannot read goes to the conversation's Files panel instead.

To change one, go to Models, edit the model, and open its Pricing, Limits, or Modalities tab. Your values stay through model refreshes. Clear a field to use the synced value again.

Explore