feat(provider): add Y-API - #2393
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. 🧰 Additional context used📚 Code guidelines (1)No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (5)
Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 7 remain after this review. 📝 WalkthroughWalkthroughAdds Y-API as a disabled OpenAI-compatible provider. The provider uses API-key credentials, has no embedding strategy, and is mapped to an icon. Tests cover its registry definition and default settings. ChangesY-API provider
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Feature Suggested reviewers: Merge Risk: ⚪ Minimal · up to Y-API starts disabled and is registered for API-key-backed model discovery. Its embedding and icon behavior match the app’s contracts, with no concrete issue warranting a merge block. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to Y-API is an optional external destination for configured credentials and conversation data. It starts disabled with no credential, and no introduced security defect was established. Some activation and failure-recovery behavior remains unverified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
zerob13
left a comment
There was a problem hiding this comment.
Review: feat(provider): add Y-API
Verdict: Approve. A faithful application of the established gateway pattern — same six touch points and same shape as FutureInfra (#2385) and Cheaper Inference (#2314): 6 files, +69/−0, nothing else touched. Verified on this head: 52/52 across basicApiKeyProviders, defaultProviders, and providerRegistry suites.
Why this is correct
- Right path, minimal diff: the registry entry spreads
OPENAI_BASE(which already suppliesruntimeKind: 'openai-compatible',modelSource: 'openai', and thefetch-modelscheck strategy) and only overridescredentialStrategy: 'api-key'+embeddingStrategy: 'none'. Setting embedding tononerather than inheriting the OpenAI default is the honest call — the author states the embeddings endpoint wasn't verified, and a disabled capability beats a broken one. - Live verification documented:
GET /v1/models→ 401 without a key,POST /v1/chat/completions→ 200 with one,vendor/modelids pasted as-is. The two contract tests pin the resolution shape (runtime kind, model source, check/credential/route/embedding strategies) and the defaults entry (id, base URL, disabled, websites) — the right durable coverage for a provider addition. - Disabled by default — purely additive, no migration, no breaking change.
providerId.tscorrectly untouched (no alias needed). - Icon: standalone SVG, no external references,
role/aria-labelpresent, wired throughmodelIconRegistry.
Note for maintainers
The PR body discloses that the author runs Y-API — this is a self-submitted listing of their own gateway. The integration itself is sound and follows the same bar as the previous gateway additions, but merge-owners should be aware of the self-interest when weighing the default-off placement.
Detailed references
src/main/provider/defaults.ts—PROVIDER_DEFAULTSentry.src/main/provider/providerRegistry.ts—PROVIDER_ID_REGISTRYentry spreadingOPENAI_BASE.test/main/provider/{basicApiKeyProviders,defaultProviders}.test.ts— contract coverage.
|
Thanks for merging! One heads-up so this doesn't rot: the model catalog behind |
Add Y-API, an OpenAI-compatible LLM gateway, as a built-in provider.
This follows the two same-shape gateways already merged here: #2385 (FutureInfra) and #2314 (Cheaper Inference). Same six touch points,
+69/-0, nothing deleted.No new provider class is needed. The registry entry is
...OPENAI_BASEwithcredentialStrategy: 'api-key'andembeddingStrategy: 'none', so it resolves to the existingopenai-compatibleruntime (modelSource: 'openai',checkStrategy: 'fetch-models') exactly like the two precedents. I setembeddingStrategy: 'none'rather than inheritingopenaibecause I have not verified an embeddings endpoint.Live verification against the gateway on 2026-10-02, with a real API key — the parts this integration actually depends on:
GET /v1/modelswith key -> 200,object: "list", populateddata[]. This is the callcheckStrategy: 'fetch-models'makes, so model discovery works out of the box.GET /v1/modelswithout key -> 401, as expected.POST /v1/chat/completions-> 200, returning a completion fordeepseek/deepseek-v4-flash.Model ids are
vendor/model(e.g.deepseek/deepseek-v4-flash,anthropic/claude-sonnet-5,minimax/minimax-m3) and are pasted as-is into the model field.The icon reuses our existing brand mark rather than a new drawing; it is a standalone SVG with no external references and no scripts.
Disclosure: I run Y-API, so this is a self-submitted listing.
Summary by CodeRabbit