DocslothModels
checking session

Models

Models displays real server state with a next action, not placeholder statistics.

Served by the core studio

Software records (sources, programs, runs, releases, components, environments, media, verification and exports) live in the core engine and are edited in its studio. When a connected engine answers through this workspace, the panels above render its own records as returned; without a connection the shell states that and shows nothing rather than an invented row. The surface contract below names each action and the setup it needs.

Surface contract

Primary object: the workspace’s BYOK model credential: provider, base URL, model ids, key fingerprint and the engine’s own capability-test answer.

Actions

  • BindSet or replace the workspace BYOK credential through PUT /v1/engine/models/credential: provider, base URL, model ids and API key. The engine encrypts the key at rest and never returns it; this page reads only the masked view (provider, base URL, model ids, fingerprint, updated-at).
  • Capability testPOST /v1/engine/models/credential/probe sends one fixed two-token completion through the stored credential and reports the provider’s own answer: ok with the model and latency, or the typed failure (code, detail, model, latency). Nothing is inferred from a model name.
  • Set limitsOpens the real budgets surface: PUT /v1/budgets/{id} sets the cap in micro-USD, owner/admin only. Model usage is metered per request by the control plane.
Required states and how this surface reaches them
loading
the session probe and each list show Loading… until the control plane answers.
ready
the server’s own records render as returned; the primary object is named before its details.
empty
no model credential is stored for this workspace: the surface says so and offers the form; an unconfigured provider is never shown as answering.
error
the control plane’s status and detail are shown; no placeholder row replaces them.
offline
no control plane is reachable; nothing is rendered rather than invented.
permission_denied
a 401 returns to sign-in with this path; a 403 states that the role cannot read this surface.
not_configured
a deployment whose engine lacks the credential secret answers 503 not_configured and stores nothing; the page names that instead of a fake credential.
budget_paused
model calls stop at the workspace budget cap (402 quota_exceeded); the overview’s budget row shows cap and consumption.
requires_approval
mutations the server reserves for an explicit human owner/admin are refused with its own detail and never auto-approved here.

Scope: workspace membership. Engine records are read and written through the core engine’s own routes (proxied by the control plane); the hosted shell binds only to named contracts, shows a record only when the server returned it, and never calculates permissions in the browser.

Model credential (BYOK)

One credential per workspace, owned by the engine. The key is sent once to PUT /v1/engine/models/credential, encrypted at rest and never displayed again; this page and the control plane read only the masked view (provider, base URL, model ids, fingerprint and updated-at).

Loading…

Set a credential

The engine stores the key AES-256-GCM encrypted under the deployment’s credential secret and never returns it. A deployment without that secret refuses the write with 503 not_configured and stores nothing.

For example openai-compatible; the label your provider uses.
https, or http only for a loopback runtime such as Ollama.
One or more ids, comma or newline separated; the first serves the probe.
Sent once to the engine and cleared from this form afterwards; encrypted at rest, never displayed.

Delete model credential

DELETE /v1/engine/models/credential removes the workspace's stored credential from the engine. Chat and the editor fall back to the deployment key afterwards; the key itself is not recoverable.