Require user LLM credentials
All checks were successful
build / build (push) Successful in 17s

This commit is contained in:
robert
2026-06-06 12:21:31 -03:00
parent 00ad0b8790
commit 64fd7c26f2
6 changed files with 40 additions and 48 deletions

View File

@@ -30,9 +30,9 @@ class BuilderContext:
sandbox: Any | None = None
grant_token: str | None = None
# LLM creds forwarded by the orchestrator according to this agent's Card.
# The builder accepts caller-selected creds and falls back to platform
# grants. Hosted generated agents should usually use platform grants too.
# Falls back to settings for local development.
# The builder uses the caller's saved LLM credential, usually proxied
# through LiteLLM by the control plane. Falls back to settings only for
# local development.
llm_base_url: str | None = None
llm_api_key: str | None = None
llm_model: str | None = None
@@ -49,28 +49,26 @@ user's workspace at ``agents/<name>/`` and then deploy it through the
control plane.
The default starter is the current a2a-pack DeepAgents scaffold. It declares
``LLMProvisioning.PLATFORM``, reads the scoped LLM grant from ``ctx.llm``,
builds a ``ChatOpenAI`` model from those credentials, and wires a small
``LLMProvisioning.PLATFORM``, reads the caller's saved LLM credential from
``ctx.llm``, builds a ``ChatOpenAI`` model from those credentials, and wires a small
tool-calling DeepAgent with ``create_deep_agent`` plus ``wrap_model_call``
middleware. Do not recreate this from memory: call ``init_agent_template`` first
and modify the generated files.
Default hosted generated/user agents to ``LLMProvisioning.PLATFORM`` and
``caller_pays_llm=False`` so main-agent handoffs mint a scoped A2A LiteLLM grant
for the callee. The generated agent must still read ``ctx.llm`` and must never
``caller_pays_llm=True`` so main-agent handoffs forward the caller's saved LLM
credential for the callee. The generated agent must still read ``ctx.llm`` and must never
read ``A2A_LITELLM_KEY``, ``OPENAI_API_KEY``, LiteLLM master keys, or provider
keys directly. If the user explicitly asks for BYOK or caller-paid inference,
use ``LLMProvisioning.CALLER_PROVIDED`` with ``caller_pays_llm=True`` and make
missing ``ctx.llm.api_key`` a clear setup/config result before constructing
keys directly. ``LLMProvisioning.CALLER_PROVIDED`` is still acceptable for
explicit BYOK wording. Always make missing ``ctx.llm.api_key`` a clear setup/config result before constructing
``ChatOpenAI``.
``Pricing`` accepts only ``price_per_call_usd``, ``caller_pays_llm``, and
``notes``. Never set ``runtime.pricing.compute`` or
``runtime.pricing.total_usd`` in generated source; those are derived later by
the control plane/dashboard from declared ``Resources`` and billing policy.
``LLMProvisioning.PLATFORM_OR_CALLER_PROVIDED`` is reserved for trusted
platform/meta agents that should prefer caller-selected credentials and fall
back to a scoped platform grant; do not use it for ordinary generated agents
unless the user explicitly asks for that mixed billing mode.
``LLMProvisioning.PLATFORM_OR_CALLER_PROVIDED`` is retained only for backwards
compatibility; do not use it for ordinary generated agents unless the user
explicitly asks for that legacy mixed mode.
You have packaged DeepAgents skills loaded from ``/.agent-builder/skills/``.
Use ``deepagent-agent-design`` before designing generated agent internals,