Skip to content

Add bring-your-own OpenAI and Jev API keys - #94

Merged
jerelvelarde merged 2 commits into
mainfrom
jerel/bring-your-own-keys
Oct 9, 2026
Merged

jerelvelarde merged 2 commits into
mainfrom
jerel/bring-your-own-keys

Conversation

@jerelvelarde

@jerelvelarde jerelvelarde commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

Visitors can now use their own OpenAI and Jev API keys instead of depending on the deployment's shared credentials. The chat header includes an API keys dialog with a real connection test, save, and clear actions. The agent also starts without shared keys for BYOK-only hosting.

Keys stay in browser memory until refresh or clear and are forwarded through the application server in request headers. Saving or clearing starts a new conversation; New chat retains the current keys. The backend scopes credentials across the full streaming request, isolates checkpoint IDs by credential pair, disables hosted LangSmith tracing for BYOK, and sanitizes provider errors. BYOK uses chat-latest and jev-latest, including internal agent model calls, without inheriting the host's OpenAI organization, project, or proxy settings.

Validation:

  • 157 JavaScript tests and 111 Python tests passed.
  • Workspace type checks, lint, frozen-lockfile validation, and production build passed; lint retains an existing font warning.
  • Real OpenAI/Jev connection validation, streaming answer, and A2UI table generation passed locally.
  • Browser-tested saving, clearing, New chat, and the mobile dialog in the production build.

The application server receives visitor keys, so deployment operators must be trusted and credential headers must not be logged. This change is not deployed yet.

Security review fixes: streaming agent requests reject redirects to avoid forwarding credential headers; BYOK validation and Jev transports ignore environment proxy/CA settings; OpenAI clients discard inherited custom headers so server Authorization cannot override visitor keys. Regression tests exercise an actual cross-origin redirect and inspect synchronous/asynchronous OpenAI requests under poisoned host settings.

@jerelvelarde
jerelvelarde marked this pull request as ready for review October 9, 2026 15:41
@jerelvelarde
jerelvelarde merged commit e173161 into main Oct 9, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant