Skip to main content

Auth overview

Upstream auth uses local CLI / OAuth credentials — not OpenAI sk- keys. The dummy key you put in Cursor or an SDK is only there so the client thinks it’s talking to OpenAI.

SurfaceCredentialSetup
Codex / ChatGPT~/.codex/auth.jsoncodex login
Gemini / Antigravity~/.gemini/antigravity_oauth_creds.json (preferred) or oauth_creds.jsonAntigravity sync
Claude Codeclaude CLI login / CLAUDE_CODE_OAUTH_TOKENClaude Code

Local / Docker

Compose mounts host auth directories (and reads Claude OAuth from .env). Finish logins on the host before docker compose up.

Kubernetes

Credentials land as Secret keys (CODEX_AUTH_JSON, GEMINI_OAUTH_JSON, CLAUDE_CODE_OAUTH_TOKEN) plus a shared GATEWAY_BEARER_TOKEN for inbound /v1 auth. See Install on Kubernetes.

Which providers are on

GATEWAY_PROVIDERS (default codex,gemini,claude) controls which surfaces get built and show up in /v1/models. Drop claude if you want Claude Code off entirely (common on some free-tier gateways).