Repository navigation
feat: add OrcaRouter as a first-class provider (API key + OAuth 2.0 PKCE) - #266
Open
hodeswildsmith455-boop wants to merge 1 commit into
Open
hodeswildsmith455-boop wants to merge 1 commit into
hodeswildsmith455-boop wants to merge 1 commit into
Conversation
…KCE) Signed-off-by: hodeswildsmith455-boop <hodeswildsmith455-boop@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds OrcaRouter as a first-class provider in
internal/providers/orcarouter(registered ininternal/providers/registry.go) together with a real console surface, so an operator can either paste an existingsk-orca-…key or connect an OrcaRouter account through OAuth 2.0 + PKCE. The model selector is driven by the live OrcaRouter model catalog with per-entry capability filtering, replacing free-text model entry for this provider.https://api.orcarouter.ai/v1(OpenAI-compatible)https://www.orcarouter.ai— consent at/auth, code exchange at/api/v1/auth/keyshttps://api.orcarouter.ai/v1/auth/keysis a 404 and is asserted against in tests).Two authentication entries, one credential seam
orcaroutersk-orca-…keyorcarouter-oauthBoth entries run through a single credential interface (
internal/providers/orcarouter/credential.go); the format discriminator records which entry minted the key, and nothing downstream — provider requests or model discovery — branches on it. The key is stored with the project's existing account-secret mechanism and is masked/clearable from the console.Connect flow: OAuth 2.0 + PKCE, Flow A (loopback redirect)
Flow A is used because this host is self-hosted software that can bind a loopback listener and therefore needs no pre-registered redirect URI; the consent screen redirects straight back to
http://127.0.0.1:<port>/cb. Flow B (out-of-band code) remains reachable as the fallback path (CompleteLoginaccepts a pasted callback URL or a bare code) for hosts that cannot receive a redirect.stateare generated fresh per attempt fromcrypto/rand; only the unpaddedbase64url(sha256(verifier))challenge travels on the authorize URL, withcode_challenge_method=S256.stateechoed on the redirect is compared in constant time before the code is used.statemismatch, expiry/reuse,403,400and429all terminate the attempt safely with an actionable message; the response body is passed through the redactor so no credential or verifier can reach a log or an error string.scopeis read back and recorded as-is; a narrower grant than requested is surfaced rather than assumed away.401marks only the exact account and credential generation that issued the rejected request as needing reauthentication, so a late failure cannot contaminate a freshly reauthorized credential.pagehide.Model catalog and capability filtering
The selector is populated from the configured origin's
GET /v1/models, fetched through the provider's own client (the console backend holds the key; the browser only ever receives minimal model metadata). The vendor/model namespace is preserved verbatim.Per-entry filtering is applied on declared metadata, never on the model name:
?capability=chat, requiring a speakable endpoint type and excluding image-generation/video/rerank-only models;A small verified cold-start seed remains for catalog outages (live success is authoritative and no seed is mixed in); a persisted model id is re-validated against the live compatible list before it is restored.
Test plan
Run on this commit (
b92caa2→6b5f310), orchestrator binary built from a bootstrapped Go 1.27 toolchain:make test(Go + worker) — all packages okmake vet— cleanmake test-architecture— okmake changelog— bilingual fragment validatesnpm --prefix frontend run build— oknpm --prefix frontend run lint— 0 errors (18 pre-existing warnings)make test-live—TestLiveCatalogThroughProviderandTestLiveChatThroughProviderPASS against the real gatewaymake orca-evidence— Playwright captures produced,passed: trueFocused counts:
internal/providers/orcarouter41/41 pass (0 skip with a key present), plusTestFilterModelsByCapability/TestProviderModelEntry*ininternal/control12/12. The dual-auth seam is asserted directly: both adapters must yield the same credential result, and auth requests must only reach the auth origin while inference/catalog only reach the API origin.Verification (independent, from the base commit)
The delivery verifier re-applied the patch to
b92caa2in a clean checkout and re-ran every check; each command below is a real test-runner invocation and covers provider, dual auth, catalog, capabilities, errors, regression and the live path. All checks exited 0, including the live provider run and the GUI evidence run. The GUI checks regenerateorca-evidence/from the tree under test (gitignored):auth-methods.pngshows the API-key field and the Connect-with-OrcaRouter entry side by side with the pasted secret masked, andtext-model-dropdown.png/multimodal-model-dropdown.pngshow the catalog-backed dropdown before and after the image attachment re-queries the vision capability (16 chat models, 2 vision).Personal verification of the round trip
A real login still requires human consent, so it is not automated here. The automated PKCE tests drive the project's own connect adapter against a local fake auth server — authorize → callback/OOB → exchange → persist → reuse — covering denial,
statemismatch, expired/reused code, scope downgrade,403/400/429and network failure. Nothing was bypassed.OrcaRouter is the gateway this provider targets. OrcaRouter is an OpenAI-compatible AI gateway that routes many providers behind one endpoint. I'm an engineer on the OrcaRouter team.
Primary sources for this integration, verified 2026-10-03: inference and catalog at
https://api.orcarouter.ai/v1; OAuth 2.0 + PKCE authorization athttps://www.orcarouter.ai/authwith the exchange documented atPOST https://www.orcarouter.ai/api/v1/auth/keys; discovery athttps://www.orcarouter.ai/.well-known/openid-configuration; credential revocation athttps://www.orcarouter.ai/console/authorized-apps; terms of service and the operating legal entity published athttps://www.orcarouter.ai. Maintenance owner for this provider: the OrcaRouter contributor who opened this PR.