Skip to content

Connect providers ​

Provider credentials stay in the proxy's private runtime directory. The website does not connect to your accounts. Use the management panel served by your local proxy.

Sign in with OAuth ​

  1. Open http://localhost:8317/management.html on the host and enter the management password.
  2. Start the sign-in flow for the provider you want to connect. Available flows depend on the pinned upstream proxy version and installed plugins.
  3. Open a private browser window signed in to only the intended provider account. Use Copy Link in the panel and open that link in the private window.
  4. Complete the provider's consent flow. If it ends at an unreachable localhost:…/callback?code=… page, copy the complete callback URL into the panel's Callback URL field and submit it once. A failed browser connection is expected when that callback listener is not exposed by the Docker stack.
  5. Run make ops accounts URL=http://localhost:8317 and confirm that the new account appears. Run make ops models URL=http://localhost:8317 to see its available models.

Callback URLs contain short-lived authorization codes. Do not share them or put them in docs, screenshots, logs you publish, or issues.

Repeat these steps for each authorized account. A browser already signed in to another account can connect the wrong subscription; check the resulting account in the panel.

Use provider API keys ​

Use the panel's provider or OpenAI-compatible configuration controls to add a key and endpoint supported by your upstream version. Keep the endpoint scheme, model names, and key format consistent with that provider's documentation.

Panel changes to the server configuration may update the rendered runtime config. make up replaces it from the checked-in template, so permanent settings belong in config.yaml with 1Password references, never literal keys. Follow the upstream configuration reference for the version you deploy.

Understand account routing ​

New sessions use round-robin routing among eligible accounts at the highest priority. Session affinity keeps later turns on the same account for up to one hour. Subagents follow their parent's account. A failover changes the upstream account and can rebuild the prompt cache.

The quota service checks Claude and Codex weekly capacity at startup and hourly. It raises priority when unused capacity will expire within 24 hours. This steers new sessions and failovers; a bound session still outranks priority.

Remove an account ​

Remove the credential through the panel and verify the account list. If a token might have been shared, also revoke the authorization at the provider. Deleting a local file does not revoke an upstream token or remove it from a private backup.

hara · built on CLIProxyAPI