Problem
A provider's credential is a static value today — options.apiKey or an env var — resolved once when the provider loads and baked into the cached SDK client. So it can't be used for a custom endpoint whose auth is a short-lived token minted by a local command (e.g. a token CLI that returns a ~1h bearer and must be re-run to refresh). Whatever token is captured at launch goes stale mid-session and every request 401s until restart. There is no way to configure this from openscience.json.
Suggested fix
Add a generic provider option options.tokenCommand: a shell command whose stdout is an auth token. It runs on the per-request path and is sent as Authorization: Bearer <token>. If the token is a JWT it is cached until just before its exp and only re-minted when near expiry, so long sessions do not go stale.
- Config-only, no new dependency; reuses the existing per-request
fetch hook and the token-refresh pattern already in the provider layer.
- Works for any OpenAI-compatible or Anthropic-style endpoint.
- Runs a shell command (same trust as custom commands/plugins), so best kept in global config. Header defaults to Bearer; a
tokenHeader override could come later.
I can send a narrow PR with tests and a docs note if this direction looks acceptable. Would this fit under "support for new providers"?
Problem
A provider's credential is a static value today —
options.apiKeyor an env var — resolved once when the provider loads and baked into the cached SDK client. So it can't be used for a custom endpoint whose auth is a short-lived token minted by a local command (e.g. a token CLI that returns a ~1h bearer and must be re-run to refresh). Whatever token is captured at launch goes stale mid-session and every request 401s until restart. There is no way to configure this fromopenscience.json.Suggested fix
Add a generic provider option
options.tokenCommand: a shell command whose stdout is an auth token. It runs on the per-request path and is sent asAuthorization: Bearer <token>. If the token is a JWT it is cached until just before itsexpand only re-minted when near expiry, so long sessions do not go stale.{ "provider": { "my-endpoint": { "npm": "@ai-sdk/openai-compatible", "options": { "baseURL": "https://api.example.com/v1", "tokenCommand": "get-token" }, "models": { "some-model": { "name": "Some Model" } } } } }fetchhook and the token-refresh pattern already in the provider layer.tokenHeaderoverride could come later.I can send a narrow PR with tests and a docs note if this direction looks acceptable. Would this fit under "support for new providers"?