Skip to content

feat(provider): custom endpoint auth via a refreshing shell-command token #146

Description

Problem

A provider's credential is a static value today — options.apiKey or an env var — resolved once when the provider loads and baked into the cached SDK client. So it can't be used for a custom endpoint whose auth is a short-lived token minted by a local command (e.g. a token CLI that returns a ~1h bearer and must be re-run to refresh). Whatever token is captured at launch goes stale mid-session and every request 401s until restart. There is no way to configure this from openscience.json.

Suggested fix

Add a generic provider option options.tokenCommand: a shell command whose stdout is an auth token. It runs on the per-request path and is sent as Authorization: Bearer <token>. If the token is a JWT it is cached until just before its exp and only re-minted when near expiry, so long sessions do not go stale.

{
  "provider": {
    "my-endpoint": {
      "npm": "@ai-sdk/openai-compatible",
      "options": { "baseURL": "https://api.example.com/v1", "tokenCommand": "get-token" },
      "models": { "some-model": { "name": "Some Model" } }
    }
  }
}
  • Config-only, no new dependency; reuses the existing per-request fetch hook and the token-refresh pattern already in the provider layer.
  • Works for any OpenAI-compatible or Anthropic-style endpoint.
  • Runs a shell command (same trust as custom commands/plugins), so best kept in global config. Header defaults to Bearer; a tokenHeader override could come later.

I can send a narrow PR with tests and a docs note if this direction looks acceptable. Would this fit under "support for new providers"?

Activity

  1. ishaan1124 commented on Jul 11, 2026

    @ishaan1124
    Member

    Shipped in v1.3.4 — the provider option 'tokenCommand' runs a shell command for a bearer token and re-mints it before the JWT exp. Docs: set it under a provider's options and drop the static apiKey.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions