Skip to content

feat(provider): add Y-API - #2393

Merged
zerob13 merged 1 commit into
ThinkInAIXYZ:devfrom
jiweiyeah:add-yapi-provider
Oct 3, 2026
Merged

zerob13 merged 1 commit into
ThinkInAIXYZ:devfrom
jiweiyeah:add-yapi-provider

Conversation

@jiweiyeah

@jiweiyeah jiweiyeah commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Add Y-API, an OpenAI-compatible LLM gateway, as a built-in provider.

This follows the two same-shape gateways already merged here: #2385 (FutureInfra) and #2314 (Cheaper Inference). Same six touch points, +69/-0, nothing deleted.

No new provider class is needed. The registry entry is ...OPENAI_BASE with credentialStrategy: 'api-key' and embeddingStrategy: 'none', so it resolves to the existing openai-compatible runtime (modelSource: 'openai', checkStrategy: 'fetch-models') exactly like the two precedents. I set embeddingStrategy: 'none' rather than inheriting openai because I have not verified an embeddings endpoint.

Live verification against the gateway on 2026-10-02, with a real API key — the parts this integration actually depends on:

  • GET /v1/models with key -> 200, object: "list", populated data[]. This is the call checkStrategy: 'fetch-models' makes, so model discovery works out of the box.
  • GET /v1/models without key -> 401, as expected.
  • POST /v1/chat/completions -> 200, returning a completion for deepseek/deepseek-v4-flash.

Model ids are vendor/model (e.g. deepseek/deepseek-v4-flash, anthropic/claude-sonnet-5, minimax/minimax-m3) and are pasted as-is into the model field.

The icon reuses our existing brand mark rather than a new drawing; it is a standalone SVG with no external references and no scripts.

Disclosure: I run Y-API, so this is a self-submitted listing.

Summary by CodeRabbit

  • New Features
    • Added Y-API as a built-in OpenAI-compatible provider, available with API-key authentication and links to its website, API keys, documentation, and model catalog. It is disabled by default.
    • Added a Y-API icon for models.

@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

🧰 Additional context used
📚 Code guidelines (1)
AGENTS.md — auto-discovered

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: e144675b-d3e1-4cfe-b4d2-32a4fef6747f

📥 Commits

Reviewing files that changed from the base of the PR and between d570e39 and 65f1cf3.

⛔ Files ignored due to path filters (1)
  • src/renderer/src/assets/llm-icons/yapi.svg is excluded by !**/*.svg
📒 Files selected for processing (5)
  • src/main/provider/defaults.ts
  • src/main/provider/providerRegistry.ts
  • src/renderer/src/components/icons/modelIconRegistry.ts
  • test/main/provider/basicApiKeyProviders.test.ts
  • test/main/provider/defaultProviders.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 7 remain after this review.


📝 Walkthrough

Walkthrough

Adds Y-API as a disabled OpenAI-compatible provider. The provider uses API-key credentials, has no embedding strategy, and is mapped to an icon. Tests cover its registry definition and default settings.

Changes

Y-API provider

Layer / File(s) Summary
Provider registration and icon mapping
src/main/provider/defaults.ts, src/main/provider/providerRegistry.ts, src/renderer/src/components/icons/modelIconRegistry.ts, test/main/provider/basicApiKeyProviders.test.ts, test/main/provider/defaultProviders.test.ts
Adds Y-API provider settings and registry metadata. Maps the yapi model key to the YAPI icon. Adds tests for its provider definition and default configuration.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Feature

Suggested reviewers: zerob13

Merge Risk: ⚪ Minimal · up to 65f1c

Y-API starts disabled and is registered for API-key-backed model discovery. Its embedding and icon behavior match the app’s contracts, with no concrete issue warranting a merge block.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 65f1c

Y-API is an optional external destination for configured credentials and conversation data. It starts disabled with no credential, and no introduced security defect was established. Some activation and failure-recovery behavior remains unverified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The supported exposure is the selected provider profile's configured credential and request content sent to its endpoint, with tool definitions potentially included under existing capability controls. The inspected client construction does not automatically borrow credentials from other provider profiles.

Trust Boundaries and Controls

  • observed — Disabled defaults prevent normal eager instance creation, but enablement is not a universal runtime guard: the pre-existing direct current-provider selection and instance lookup paths check existence without checking enable. Whether untrusted callers can reach those paths was not established. The new default carries no credential.

Resilience and Maintainability Implications

  • observed — Provider-list writes use a database transaction, limiting partially applied replacements. The existing settings wrapper catches write failures, while its caller subsequently publishes a provider-change event. Failure notification is therefore not proof of durable success; this behavior predates the new registration.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely identifies the main change: adding Y-API as a provider.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 5…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@zerob13 zerob13 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review: feat(provider): add Y-API

Verdict: Approve. A faithful application of the established gateway pattern — same six touch points and same shape as FutureInfra (#2385) and Cheaper Inference (#2314): 6 files, +69/−0, nothing else touched. Verified on this head: 52/52 across basicApiKeyProviders, defaultProviders, and providerRegistry suites.

Why this is correct

  • Right path, minimal diff: the registry entry spreads OPENAI_BASE (which already supplies runtimeKind: 'openai-compatible', modelSource: 'openai', and the fetch-models check strategy) and only overrides credentialStrategy: 'api-key' + embeddingStrategy: 'none'. Setting embedding to none rather than inheriting the OpenAI default is the honest call — the author states the embeddings endpoint wasn't verified, and a disabled capability beats a broken one.
  • Live verification documented: GET /v1/models → 401 without a key, POST /v1/chat/completions → 200 with one, vendor/model ids pasted as-is. The two contract tests pin the resolution shape (runtime kind, model source, check/credential/route/embedding strategies) and the defaults entry (id, base URL, disabled, websites) — the right durable coverage for a provider addition.
  • Disabled by default — purely additive, no migration, no breaking change. providerId.ts correctly untouched (no alias needed).
  • Icon: standalone SVG, no external references, role/aria-label present, wired through modelIconRegistry.

Note for maintainers

The PR body discloses that the author runs Y-API — this is a self-submitted listing of their own gateway. The integration itself is sound and follows the same bar as the previous gateway additions, but merge-owners should be aware of the self-interest when weighing the default-off placement.

Detailed references

  • src/main/provider/defaults.ts — PROVIDER_DEFAULTS entry.
  • src/main/provider/providerRegistry.ts — PROVIDER_ID_REGISTRY entry spreading OPENAI_BASE.
  • test/main/provider/{basicApiKeyProviders,defaultProviders}.test.ts — contract coverage.

@zerob13 zerob13 mentioned this pull request Oct 2, 2026
6 tasks done
@zerob13
zerob13 merged commit 90baed4 into ThinkInAIXYZ:dev Oct 3, 2026
12 checks passed
@jiweiyeah

Copy link
Copy Markdown
Contributor Author

Thanks for merging! One heads-up so this doesn't rot: the model catalog behind https://api.y-api.bestvirtualgoods.com/v1 is live and changes with the upstream — 20 models as of today (2026-10-04), up from 15 when the PR was authored. Nothing in the merged code pins model IDs (the catalog is fetched from GET /v1/models at runtime), so no code change is needed; I'm just noting it here so anyone testing the provider uses a current model ID. Also: happy to be pinged on future releases if that helps me keep the integration verified.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants