You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Prove each provider runs the bot's saved model on the intended account #415
The model saved on a bot must control every turn for that bot, through the subscription or credential the user picked. CLI detection or a saved OAuth login does not prove that execution works. If a provider cannot honor the selected model, it must fail with an honest unsupported state, never quietly run a different model or credential.
Routing is implemented and covered by unit tests. What remains is real-turn evidence for each provider and credential path.
Providers on main (checked 2026-10-06)
Provider
Driver kind
Runtime
Real-turn evidence
Codex (ChatGPT)
codex
Mastra AgentController
Missing
Claude
claudeAgent
Mastra
Missing
Grok
grok
Mastra
Missing
Kimi For Coding
kimi
Mastra
Missing. See AKR-66.
OpenCode Go
opencodeGo
Mastra
Missing
Custom API
customOpenai
Mastra
Missing
Standard OpenCode
opencode
Legacy adapter bridge
Missing
The original list also named Cursor, Gemini, Amp, and later ACP CLIs:
Cursor is retired (RETIRED_PROVIDER_DRIVERS). It used cursor-agent ACP compatibility, not a direct subscription transport.
Gemini and Amp are not Akeru providers. They are reachable only as models inside standard OpenCode, for example google/gemini-3-pro and sourcegraph/amp.
ACP CLIs have no driver.
Goal
For every provider in the table, one real turn proves three things: it used the bot's saved model, it used the intended subscription or credential path, and its runtime (Mastra or legacy adapter) is recorded. A turn whose UI claims subscription support but executes on another credential or model counts as a failure.
Already done
Codex, Claude, Grok, and OpenCode adapters reject a saved provider instance that does not match the active adapter. Cursor did too while it existed.
The command reactor forwards the saved provider instance and model on session start and on every turn.
A saved Claude model that the provider refuses now emits a provider error, fails the turn, and closes the query. A saved Codex model that gets rerouted emits a provider error and interrupts the turn, or closes the runtime if the interrupt fails.
Kimi keeps a saved k3-256k as kimi-for-coding/k3-256k, never asks a legacy adapter for capabilities, and fails closed without valid access.
Tests in AgentController.models*.test.ts include:
"fails closed when the saved model is not in the instance snapshot"
"fails closed for a disabled saved provider instead of rerouting"
"routes two bots on the same Codex instance to different models"
"sends the saved OpenCode model to the legacy bridge"
"runs the saved Kimi model through Mastra without provider fallback"
OpenCode tests cover the real model IDs kimi/k2.5, google/gemini-3-pro, and sourcegraph/amp.
Each provider in the table has a recorded real turn with the saved model, the credential path, and the runtime, posted as a comment on this issue
A selected model that a provider cannot serve fails visibly in chat on every provider
No provider falls back to another model or credential except through a documented, user-visible rule (see open questions)
Adapter-level tests exist for every provider in the table
How to verify
vp test run apps/server/src/provider/Layers/AgentController.models.routing.test.ts apps/server/src/provider/Layers/AgentController.models.failures.test.ts apps/server/src/provider/Layers/AgentController.models.resume.test.ts
Then, in an isolated dev environment, connect each provider, set a non-default model on a bot, send one turn, and confirm the provider's request log or usage shows that model and account.
Out of scope
Adding Cursor, Gemini, Amp, or ACP CLIs as providers
Kimi feature parity beyond model routing, tracked in AKR-66
Grok's default grok-build is a product slug that means "the session's current model", and it reaches Mastra as Grok 4.7. Should a slug that resolves to a specific model count as honoring the saved model?
History
2026-08-30: implementation evidence. Focused provider, reactor, workspace, browser, redaction, Settings, and contract checks passed (18 files, 418 tests), and server typecheck passed. The Grok review accepted the fail-closed fixes but did not approve Done.
2026-08-31: ChatGPT, Claude, Grok, and Kimi had full custom-harness routing locally. Grok review passed. Live subscription testing was skipped on purpose. OpenCode stayed on its adapter path.
2026-09-22 roadmap audit: saved-model routing has tests and Kimi fails closed. Real-turn evidence for every claimed provider and credential path is missing.
Original roles: GPT-6.1 Sol implements, Grok reviews.
Problem
The model saved on a bot must control every turn for that bot, through the subscription or credential the user picked. CLI detection or a saved OAuth login does not prove that execution works. If a provider cannot honor the selected model, it must fail with an honest unsupported state, never quietly run a different model or credential.
Routing is implemented and covered by unit tests. What remains is real-turn evidence for each provider and credential path.
Providers on
main(checked 2026-10-06)codexAgentControllerclaudeAgentgrokkimiopencodeGocustomOpenaiopencodeThe original list also named Cursor, Gemini, Amp, and later ACP CLIs:
RETIRED_PROVIDER_DRIVERS). It usedcursor-agentACP compatibility, not a direct subscription transport.google/gemini-3-proandsourcegraph/amp.Goal
For every provider in the table, one real turn proves three things: it used the bot's saved model, it used the intended subscription or credential path, and its runtime (Mastra or legacy adapter) is recorded. A turn whose UI claims subscription support but executes on another credential or model counts as a failure.
Already done
k3-256kaskimi-for-coding/k3-256k, never asks a legacy adapter for capabilities, and fails closed without valid access.AgentController.models*.test.tsinclude:kimi/k2.5,google/gemini-3-pro, andsourcegraph/amp.Acceptance criteria
How to verify
vp test run apps/server/src/provider/Layers/AgentController.models.routing.test.ts apps/server/src/provider/Layers/AgentController.models.failures.test.ts apps/server/src/provider/Layers/AgentController.models.resume.test.tsThen, in an isolated dev environment, connect each provider, set a non-default model on a bot, send one turn, and confirm the provider's request log or usage shows that model and account.
Out of scope
Open questions
grok-buildis a product slug that means "the session's current model", and it reaches Mastra as Grok 4.7. Should a slug that resolves to a specific model count as honoring the saved model?History
Context
Blocks AKR-81. Related: AKR-66, AKR-67, AKR-72, AKR-123, LEO-294, LEO-331, LEO-344. Routing overview:
docs/internals/providers.md.Created with Claude Opus 5.5 in Claude Code.