Documentation
¶
Overview ¶
Package upstream is the one place that knows where a provider lives and how a call proves it may reach one. It is a leaf on purpose: it depends on object and the standard library and nothing else, so a second caller — hanzoai/egress, which exists so that callers never hold a vendor key — reaches the same addresses and the same credential scheme by importing them rather than restating them.
A copy would not stay a copy. Provider addresses and auth schemes are facts about vendors, and two files holding them drift in the direction that is hardest to notice: the copy that is wrong sends a credential to the wrong host.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func Authorize ¶
Authorize applies a provider's credential to an outbound request and returns nothing. It is the one place on the relay that reads a provider secret, and the header it writes is the only form that secret takes: there is no value for a caller to log, echo into an error, or forward somewhere it does not belong.
The scheme belongs to the provider, not to the surface calling it. Azure names its key in the Authorization value, Anthropic sends it in a header of its own, and everything else carries a bearer token — so any caller that reaches an Anthropic upstream sends x-api-key without having to remember to.
A nil provider means the call carries no credential (a session already opened with one), which is a fact about the call, not a mistake to guard against.
func Endpoint ¶
Endpoint returns the upstream URL for a provider and an OpenAI-style API path ("chat/completions", "embeddings", "rerank"). It is the single place that knows each provider's address, so every OpenAI-compatible surface is built by varying path alone and no per-endpoint copy of provider routing exists.
A provider whose address is unknown yields "": the relay refuses rather than guessing a host, and every caller checks for it before sending anything.
ProviderUrl is honoured for OpenAI, Azure, Local/Ollama/DigitalOcean and any other type; it is deliberately IGNORED for Fireworks, Grok, OpenRouter, Moonshot, Gemini, Jina and Cohere, whose single public address is stated here rather than taken from a row. Changing that would move traffic — and a credential — to a different host, so it stays as it is.
Types ¶
This section is empty.