PageSourceSearch

https://docs-delta-gold.vercel.app/_next/static/chunks/pages/agent-network/providers-b95537ad29ca43e4.js

js docs-delta-gold.vercel.app collected 2026-10-03 05:48:14 UTC 11,939 bytes, 1 lines download raw bytes

1(self.webpackChunk_N_E=self.webpackChunk_N_E||[]).push([[4581],{11898:(e,t,n)=>{"use strict";n.r(t),n.d(t,{__N_SSG:()=>o,default:()=>a});var r=n(37876),s=n(91668);function i(e){let t=Object.assign({h1:"h1",p:"p",time:"time",strong:"strong",a:"a",h2:"h2",h3:"h3",ul:"ul",li:"li",ol:"ol",em:"em",code:"code"},(0,s.RP)(),e.components),{Warning:n}=t;return n||function(e,t){throw Error("Expected "+(t?"component":"object")+" `"+e+"` to be defined: you likely forgot to import, pass, or provide it.")}("Warning",!0),(0,r.jsxs)(r.Fragment,{children:[(0,r.jsx)(t.h1,{children:"Providers"}),(0,r.jsxs)(t.p,{className:"not-prose text-sm text-slate-400 dark:text-zinc-500 mt-0 mb-8 ml-2.5",children:["Updated ",(0,r.jsx)(t.time,{dateTime:"2026-09-04",children:"September 4, 2026"})]}),"\n",(0,r.jsxs)(t.p,{children:["A ",(0,r.jsx)(t.strong,{children:"provider"})," is an upstream LLM service that NetBird routes requests to. Connecting one\nstores its API key server-side and exposes it through your keyless, tunnel-only\n",(0,r.jsx)(t.a,{href:"/agent-network/how-it-works#llm-apis-and-ai-gateways",children:"agent network endpoint"}),", so agents\nnever hold a provider key."]}),"\n",(0,r.jsx)("p",{children:(0,r.jsx)("img",{src:"/docs-static/img/agent-network/providers/agent-network-providers-l
1ist.png",alt:"agent network providers list",className:"imagewrapper-big"})}),"\n",(0,r.jsx)(t.h2,{id:"supported-providers",children:"Supported Providers"}),"\n",(0,r.jsxs)(t.p,{children:["When you connect a provider, the picker groups the catalog into first-party ",(0,r.jsx)(t.strong,{children:"AI\nProviders"}),", multi-provider ",(0,r.jsx)(t.strong,{children:"AI Gateways"}),", and a ",(0,r.jsx)(t.strong,{children:"Custom"})," catch-all."]}),"\n",(0,r.jsx)(t.h3,{id:"ai-providers",children:"AI Providers"}),"\n",(0,r.jsx)(t.p,{children:"First-party vendor APIs:"}),"\n",(0,r.jsxs)(t.ul,{children:["\n",(0,r.jsx)(t.li,{children:"OpenAI"}),"\n",(0,r.jsx)(t.li,{children:"Anthropic"}),"\n",(0,r.jsx)(t.li,{children:"Azure OpenAI"}),"\n",(0,r.jsx)(t.li,{children:"AWS Bedrock"}),"\n",(0,r.jsx)(t.li,{children:"Google Vertex AI"}),"\n",(0,r.jsx)(t.li,{children:"Mistral"}),"\n",(0,r.jsx)(t.li,{children:"Kimi (Moonshot AI)"}),"\n"]}),"\n",(0,r.jsx)(t.h3,{id:"ai-gateways",children:"AI Gateways"}),"\n",(0,r.jsxs)(t.p,{children:["Routing and aggregation layers that sit in front of multiple providers. NetBird can also\nforward the calling agent's identity to these so the gateway can apply its own attribution\nand budgets (see ",(0,r.jsx)(t.a,{href:"/agent-network/how-it-works#llm-apis-and-ai-gateways",children:"How It Works"}),"):"]}),"\n",(0,r.jsxs)(t.ul,{children:["\n",(0,r.jsx)(t.li,{children:"LiteLLM Proxy"}),"\n",(0,r.jsx)(t.li,{children:"agentgateway"}),"\n",(0,r.jsx)(t.li,{children:"Portkey AI Gateway"}),"\n",(0,r.jsx)(t.li,{children:"Bifrost"}),"\n",(0,r.jsx)(t.li,{children:"Cloudflare AI Gateway"}),"\n",(0,r.jsx)(t.li,{children:"Vercel AI Gateway"}),"\n",(0,r.jsx)(t.li,{children:"OpenRouter"}),"\n"]}),"\n",(0,r.jsx)(t.h3,{id:"custom",children:"Custom"}),"\n",(0,r.jsxs)(t.ul,{children:["\n",(0,r.jsx)(t.li,{children:"Custom / Self-hosted: any OpenAI-compatible endpoint, including local models served by\nOllama, vLLM, or a private GPU host."}),"\n"]}),"\n",(0,r.jsx)(t.h2,{id:"connect-a-provider",children:"Connect a Provider"}),"\n",(0,r.jsxs)(t.ol,{children:["\n",(0,r.jsxs)(t.li,{children:["Go to ",(0,r.jsx)(t.strong,{children:"Agent Network → Providers"})," and click ",(0,r.jsx)(t.strong,{children:"Connect Provider"}),"."]}),"\n",(0,r.jsx)(t.li,{children:"Select the provider or gateway. NetBird pre-fills the upstream URL and the correct auth\nheader for that vendor."}),"\n",(0,r.jsxs)(t.li,{children:["Paste the provider's ",(0,r.jsx)(t.strong,{children:"API key"}),". It is stored encrypted server-side and never sent to\ncallers."]}),"\n",(0,r.jsxs)(t.li,{children:[(0,r.jsx)(t.em,{children:"(Optional)"})," Restrict the ",(0,r.jsx)(t.strong,{children:"allowed models"})," and set ",(0,r.jsx)(t.strong,{children:"per-model pricing"})," used for cost\nestimates in usage and logs."]}),"\n",(0,r.jsxs)(t.li,{children:[(0,r.jsx)(t.em,{children:"(Optional, gateways)"})," Fill any gateway-specific fields (for example a Portkey config\nID) and the identity headers used for attribution."]}),"\n",(0,r.jsx)(t.li,{children:"Save the provider."}),"\n"]}),"\n",(0,r.jsx)("p",{children:(0,r.jsx)("img",{src:"/docs-static/img/agent-network/providers/agent-network-create-provider.png",alt:"agent network connect provider modal",className:"imagewrapper"})}),"\n",(0,r.jsx)(t.h2,{id:"custom-and-self-hosted-providers",children:"Custom & Self-hosted Providers"}),"\n",(0,r.jsxs)(t.p,{children:["Pick ",(0,r.jsx)(t.strong,{children:"Custom / Self-hosted"})," for any OpenAI-compatible endpoint that isn't a first-party\nvendor or a named gateway, a private inference server, an on-prem deployment, or a local\nmodel runtime like Ollama or vLLM (vLLM also has its own named entry). NetBird talks to it\nthe same way it talks to OpenAI: you provide the ",(0,r.jsx)(t.strong,{children:"Upstream URL"})," where requests are\nforwarded and, if the endpoint requires one, an ",(0,r.jsx)(t.strong,{children:"API key"})," sent as a bearer token."]}),"\n",(0,r.jsx)("p",{children:(0,r.jsx)("img",{src:"/docs-static/img/agent-network/providers/agent-network-custom-provider.png",alt:"custom provider settings with the Skip TLS Verification switch",className:"imagewrapper"})}),"\n",(0,r.jsx)(t.h3,{id:"skip-tls-verification",children:"Skip TLS Verification"}),"\n",(0,r.jsxs)(t.p,{children:["Self-hosted endpoints often serve HTTPS with a self-signed or otherwise untrusted\ncertificate, which makes the proxy reject the connection with an unknown-certificate error.\nEnable ",(0,r.jsx)(t.strong,{children:"Skip TLS Verification"})," on a custom provider to disable upstream TLS certificate\nvalidation so requests go through anyway."]}),"\n",(0,r.jsx)(n,{children:(0,r.jsx)(t.p,{children:"This turns off certificate checks for that provider's upstream traffic, which removes\nprotection against man-in-the-middle attacks. Use it only for quick testing. For anything\nbeyond that, mount your CA / trusted certificates on your proxy instances instead of\nskipping verification."})}),"\n",(0,r.jsxs)(t.p,{children:["The switch appears only for custom (self-hosted) providers and is ",(0,r.jsx)(t.strong,{children:"off by default"}),"."]}),"\n",(0,r.jsx)(t.h3,{id:"identity-metadata",children:"Identity Metadata"}),"\n",(0,r.jsxs)(t.p,{children:["By default NetBird stamps the caller's ",(0,r.jsx)(t.strong,{children:"user"})," and the ",(0,r.jsx)(t.strong,{children:"group that authorized the request"}),"\nonto each upstream request, so the provider or gateway can attribute usage to the real caller\ninstead of the shared API key. The exact header or field is provider-specific. See the\nprovider's ",(0,r.jsx)(t.a,{href:"/agent-network/integrations",children:"integration guide"})," for details (for example, AWS\nBedrock carries it in a header used for ",(0,r.jsx)(t.a,{href:"/agent-network/integrations/bedrock#cost-allocation",children:"cost-allocation tags"}),",\nand AI gateways receive their own attribution headers)."]}),"\n",(0,r.jsxs)(t.p,{children:["This is controlled by the ",(0,r.jsx)(t.strong,{children:"Forward identity metadata"})," toggle on the provider, which is ",(0,r.jsx)(t.strong,{children:"on by\ndefault"})," and shown only for providers that support it (first-party APIs such as OpenAI or\nAnthropic have no such metadata channel, so the toggle doesn't appear for them). Tur
1n it off\nto keep the caller's identity out of the upstream request."]}),"\n",(0,r.jsx)("p",{children:(0,r.jsx)("img",{src:"/docs-static/img/agent-network/providers/agent-network-provider-metadata.png",alt:"Connect Provider modal with the Disable identity metadata toggle",className:"imagewrapper"})}),"\n",(0,r.jsx)(t.h2,{id:"models-and-pricing",children:"Models and Pricing"}),"\n",(0,r.jsxs)(t.p,{children:["Each provider carries a list of models it serves. Leaving the list empty makes the\nprovider a catch-all that accepts any model (typical for gateways); listing specific models\nrestricts routing to them. Per-model prices drive the cost figures shown in\n",(0,r.jsx)(t.a,{href:"/agent-network/usage-and-logs",children:"Usage & Logs"}),"; adjust them if your negotiated rates differ\nfrom the catalog defaults."]}),"\n",(0,r.jsxs)(t.p,{children:["Each model has an ",(0,r.jsx)(t.strong,{children:"input"})," and ",(0,r.jsx)(t.strong,{children:"output"})," price per 1k tokens, plus optional\n",(0,r.jsx)(t.strong,{children:"cache"})," rates that match how the provider bills prompt caching. Which cache\nfields apply depends on the provider's pricing surface: OpenAI-shape providers\nuse a single ",(0,r.jsx)(t.strong,{children:"cached input"})," rate (cached tokens are a subset of the prompt),\nwhile Anthropic-shape providers, including Claude on Amazon Bedrock and Google\nVertex AI, use separate ",(0,r.jsx)(t.strong,{children:"cache read"})," and ",(0,r.jsx)(t.strong,{children:"cache creation"})," rates (additive\nbuckets on top of input). Gateways and custom providers expose all cache fields,\nsince NetBird can't know the upstream shape ahead of time."]}),"\n",(0,r.jsxs)(t.p,{children:["Leave a cache rate ",(0,r.jsx)(t.strong,{children:"blank"})," to inherit NetBird's default for that model when one\nexists; set it to ",(0,r.jsx)(t.strong,{children:"0"})," to bill that cache bucket at the plain input rate (no\ndiscount). See ",(0,r.jsx)(t.a,{href:"/agent-network/usage-and-logs/access-logs",children:"how caching is metered"}),"\nfor how these buckets appear in the cost breakdown."]}),"\n",(0,r.jsxs)(t.p,{children:["Self-hosters can seed the catalog defaults these fields prefill from with a\npricing file. See\n",(0,r.jsx)(t.a,{href:"/selfhosted/maintenance/configuration-files#agent-network-settings",children:(0,r.jsx)(t.code,{children:"server.agentNetwork.pricingDefaultsFile"})}),"."]}),"\n",(0,r.jsx)(t.h3,{id:"adding-a-model-not-in-the-catalog",children:"Adding a Model Not in the Catalog"}),"\n",(0,r.jsxs)(t.p,{children:["If the model you need isn't in the picker, type its model ID directly into the ",(0,r.jsx)(t.strong,{children:"Model"})," field\ninstead of selecting from the list, for example ",(0,r.jsx)(t.code,{children:"eu.anthropic.claude-sonnet-5"}),". A model NetBird\ndoesn't know has no catalog defaults, so set its ",(0,r.jsx)(t.strong,{children:"input"})," and ",(0,r.jsx)(t.strong,{children:"output"})," prices (and cache\nrates, if applicable) yourself for usage and logs to report accurate costs."]}),"\n",(0,r.jsx)("p",{children:(0,r.jsx)("img",{src:"/docs-static/img/agent-network/providers/agent-network-custom-model.png",alt:"Models tab with a custom model ID and manually entered input/output pricing",className:"imagewrapper"})}),"\n",(0,r.jsx)(t.h2,{id:"the-keyless-endpoint",children:"The Keyless Endpoint"}),"\n",(0,r.jsx)(t.p,{children:"All connected providers share a single account endpoint, generated when you connect your\nfirst provider and reachable only over the NetBird overlay."}),"\n",(0,r.jsx)("p",{children:(0,r.jsx)("img",{src:"/docs-static/img/agent-network/quickstart/agent-network-endpoint.png",alt:"agent network endpoint on the Providers page",className:"imagewrapper"})}),"\n",(0,r.jsxs)(t.p,{children:["Agents send normal provider requests to the endpoint without an API key; which identities\nmay reach which providers is governed by ",(0,r.jsx)(t.a,{href:"/agent-network/policies",children:"Policies"}),"."]})]})}var o=!0;let a=function(e={}){let{wrapper:t}=Object.assign({},(0,s.RP)(),e.components);return t?(0,r.jsx)(t,Object.assign({},e,{children:(0,r.jsx)(i,e)})):i(e)}},86592:(e,t,n)=>{(window.__NEXT_P=window.__NEXT_P||[]).push(["/agent-network/providers",function(){return n(11898)}])}},e=>{e.O(0,[636,6593,8792],()=>e(e.s=86592)),_N_E=e.O()}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.