Skip to content

feat(aimlapi): add guided top-up and key provisioning - #1886

Merged
kevincodex1 merged 8 commits into
Twigpine:mainfrom
aimlapi:feat/aimlapi-topup-and-attribution
Jul 8, 2026
Merged

kevincodex1 merged 8 commits into
Twigpine:mainfrom
aimlapi:feat/aimlapi-topup-and-attribution

Conversation

@Lookoff-AIMLAPI

@Lookoff-AIMLAPI Lookoff-AIMLAPI commented Jul 7, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Adds a guided AI/ML API top-up path to provider setup and the CLI.

Related to #1885.
Follow-up to #835 / #863.

This PR includes one prerequisite cleanup commit that updates the AI/ML API checkout/inference attribution partner id before adding the guided checkout flow.

What changed

Provider setup

  • Surfaces AI/ML API as the first recommended provider preset.
  • Updates the preset description to "1,000+ models OpenAI compatible endpoint".
  • Adds an AI/ML API-specific API key choice:
    • Top up and get API key
    • Enter existing API key
  • Adds guided top-up steps:
    • email
    • password
    • amount
    • card/crypto payment method
  • Saves the issued API key into the AI/ML API provider profile after checkout completes.

AI/ML API top-up

  • Adds a partner-checkout client.
  • Opens card or crypto checkout invoices.
  • Polls checkout status until payment completes.
  • Exchanges completed checkout sessions for an issued API key.
  • Uses AI/ML API endpoints with explicit URL overrides only.

CLI

  • Adds openclaude aimlapi topup.
  • Supports email/password, amount, method, model, partner id, and --no-open.

Why

AI/ML API is already available as a first-class provider, but first-run setup still assumes the user has an API key. This completes the onboarding path for users who need to top up and receive a key during setup.

Impact

User-facing

  • Users can configure AI/ML API from /provider without already having an API key.
  • Existing API key setup remains supported.
  • Users can choose card or crypto checkout.
  • Minimum top-up is $20.

Maintainer

  • Reuses the existing provider profile persistence path.
  • Keeps AI/ML API on the OpenAI-compatible provider route.
  • Does not add a new provider abstraction.

Verification

  • bun run typecheck
  • bun run build
  • bun run integrations:check
  • git diff --check

Known local test issue:

  • bun test src/components/ProviderManager.test.tsx currently fails before running tests with Cannot find package 'bundle' from src/state/AppState.tsx.

Summary by CodeRabbit

  • New Features
    • Added an aimlapi topup CLI command with guided payment and API key provisioning.
    • Extended the AI/ML API provider setup with a step-by-step top-up wizard (email/password, amount, payment method), progress screen, and improved back/cancel behavior.
    • Updated AI/ML API preset presentation (description/“Recommended” badge) for better discoverability.
  • Bug Fixes
    • Improved structured error reporting for top-up failures.
    • Updated AI/ML API partner identification headers used for discovery/routing.
  • Tests
    • Added and updated unit, snapshot, and end-to-end coverage for the full top-up flow.
  • Documentation
    • Updated AI/ML API setup documentation with the new wizard and CLI instructions.

@coderabbitai

coderabbitai Bot commented Jul 7, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 6639d1ac-7507-452f-a571-221617d7dfc4

📥 Commits

Reviewing files that changed from the base of the PR and between a76a127 and e6041b2.

📒 Files selected for processing (1)
  • docs/aimlapi-setup.md
📜 Recent review details
🧰 Additional context used
📓 Path-based instructions (4)
docs/**/*.{md,mdx}

📄 CodeRabbit inference engine (AGENTS.md)

Update documentation when setup, commands, provider behavior, or user-facing behavior changes.

Files:

  • docs/aimlapi-setup.md
**/*

📄 CodeRabbit inference engine (CONTRIBUTING.md)

In the files you touch, preserve the existing code style.

Files:

  • docs/aimlapi-setup.md

⚙️ CodeRabbit configuration file

**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.

Files:

  • docs/aimlapi-setup.md
**

⚙️ CodeRabbit configuration file

**: # AGENTS.md - AI Agent Coding Guide

This guide is for AI coding agents working in the OpenClaude repository. Read it before changing code, and also follow CONTRIBUTING.md for contributor policy, PR expectations, review follow-up, and project scope.

Project Snapshot

OpenClaude is a coding-agent CLI for cloud and local model providers. It supports OpenAI-compatible APIs, Anthropic, Gemini, DeepSeek, Ollama, MCP, local backends, slash commands, tools, agents, and a React/Ink terminal UI.

The installed CLI runs on Node.js >=22.0.0. Bun is used for source builds, scripts, dependency management, and tests.

Work Style

  • Keep changes focused on one problem.
  • Prefer existing patterns in the file or nearby module.
  • Avoid unrelated formatting, renames, dependency changes, or broad rewrites.
  • Add or update tests when behavior changes.
  • Update docs when setup, commands, provider behavior, or user-facing behavior changes.
  • For new features, larger refactors, dependencies, or runtime changes, follow the issue-first guidance in CONTRIBUTING.md.

Stack And Conventions

  • TypeScript with strict mode and ESM imports.
  • React + Ink for terminal UI.
  • Bun lockfile and Bun scripts for development workflows.
  • Node runtime for the built CLI.

Common libraries and patterns:

  • chalk for terminal color.
  • commander for CLI argument parsing.
  • execa for child processes.
  • Existing service, provider, settings, permission, and UI patterns over new abstractions.

Repository Map

  • src/commands/ - slash and CLI command implementations.
  • src/components/ - React/Ink UI components.
  • src/services/ - API, MCP, OAuth, wiki, voice, and other service integrations.
  • src/tools/ - tool implementations.
  • src/utils/ - shared utilities.
  • src/integrations/ - provider and model integration metadata.
  • src/entrypoints/ - CLI, MCP, SDK, and generated public types.
  • src/tasks/ - local, remote, workflow, and monitor tas...

Files:

  • docs/aimlapi-setup.md
{README.md,CONTRIBUTING.md,docs/**,.github/pull_request_template.md}

⚙️ CodeRabbit configuration file

{README.md,CONTRIBUTING.md,docs/**,.github/pull_request_template.md}: Review docs for accuracy against current code behavior. Flag security or provider claims that overpromise, stale install commands, missing setup caveats, and instructions that could push users toward unsafe credential handling. Keep purely wording-level suggestions non-blocking.

Files:

  • docs/aimlapi-setup.md
🔇 Additional comments (1)
docs/aimlapi-setup.md (1)

11-24: LGTM!

Also applies to: 25-40, 41-41


📝 Walkthrough

Walkthrough

This PR adds an AI/ML API top-up and provisioning flow: a new HTTP client and config module for checkout/auth/exchange, CLI prompt helpers, a runAimlapiTopup/provisionAimlapiKey orchestration module, a CLI aimlapi topup subcommand, ProviderManager UI screens for the top-up wizard, and preset/header metadata updates.

Changes

AI/ML API top-up feature

Layer / File(s) Summary
Aimlapi client, config, and prompts
src/integrations/aimlapi/client.ts, src/integrations/aimlapi/config.ts, src/integrations/aimlapi/prompt.ts
Adds AimlapiClient, AimlapiApiError, endpoint and amount helpers, and readline-based prompt helpers.
Top-up and provisioning orchestration
src/integrations/aimlapi/topup.ts, src/integrations/aimlapi/index.ts
Implements amount parsing, auth fallback, checkout polling, runAimlapiTopup, provisionAimlapiKey, and barrel re-exports.
CLI topup subcommand
src/cli/handlers/aimlapi.ts, src/main.tsx
Adds aimlapiTopup error handling and registers openclaude aimlapi topup with option mapping and amount-range help.
ProviderManager AIMLAPI top-up UI
src/components/ProviderManager.tsx, src/components/ProviderManager.test.tsx
Adds AIMLAPI wizard screens/state, navigation, provisioning flow wiring, and updated UI tests including an end-to-end top-up case.
Preset ordering and partner header updates
src/integrations/gateways/aimlapi.ts, src/integrations/gateways/gitlawb-opengateway.ts, src/integrations/discoveryService.test.ts, src/services/api/bootstrap.test.ts, src/services/api/client.test.ts
Updates the AIMLAPI partner header value, preset metadata, badge placement, and matching test expectations.

Estimated code review effort: 4 (Complex) | ~60 minutes

Possibly related issues

Possibly related PRs

  • Gitlawb/openclaude#863: Both PRs extend the AI/ML API provider surface; this one builds on the preset/gateway groundwork with top-up provisioning and CLI/UI wiring.

Suggested labels: new: provider/gateway

Suggested reviewers: jatmn, kevincodex1, Vasanthdev2004

🚥 Pre-merge checks | ✅ 6 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Risk Surface Disclosed ⚠️ Warning PR adds auth/network/browser checkout paths, but the review text never explicitly flags that risk surface or says whether it blocks merge. Add a review note naming the auth/network/browser-payment risk surface and stating clearly whether it is blocking or non-blocking.
✅ Passed checks (6 passed)
Check name Status Explanation
Title check ✅ Passed The title is concise, scoped, and accurately summarizes the guided AI/ML API top-up and provisioning changes.
Description check ✅ Passed The description covers summary, impact, and verification; it is mostly complete despite missing the template's exact Testing and Notes sections.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
No Hidden Policy Change ✅ Passed PASS: The attribution/routing defaults and CLI/network behavior are explicit in aimlapi config, gateway, topup, and docs; no extra policy change is hidden in cleanup.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 5

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@src/components/ProviderManager.test.tsx`:
- Around line 924-1000: This ProviderManager top-up test is relying on the
email/password prompts, but renderAimlapiApiKeyChoice will bypass them if
AIMLAPI_EMAIL and AIMLAPI_PASSWORD are already set. Update the test to save the
current env values, clear both before mounting ProviderManager and running the
flow, then restore them afterward so the prompts are rendered consistently and
the test cannot hang.

In `@src/integrations/aimlapi/client.ts`:
- Around line 184-194: Add a timeout to the shared fetch wrapper in AIMLAPI
client so stalled requests can’t hang indefinitely. Update the request path in
the fetch call used by `getSession`, `signup`, `pay`, and `exchange` to pass an
`AbortSignal.timeout(...)` signal, and make sure the existing `AimlapiApiError`
handling in the same block still reports timeout/network failures cleanly.

In `@src/integrations/aimlapi/topup.ts`:
- Around line 331-338: The retry logic in the polling loop is too narrow: in the
catch block it only retries AimlapiApiError responses with status >= 500, so
transient network failures surfaced by client.request as status 0 still abort
the in-progress payment wait. Update the retry condition in the polling code
around the catch block to also treat status 0 as transient, and keep the
existing sleep/continue behavior for those errors.
- Line 187: The console output in the session handling path is leaking a
sensitive capability token, so remove the use of session.sessionToken from the
log in topup.ts and replace it with a non-sensitive identifier or a generic
session message. Update the logging in the code that prints the session details
so it does not expose one-time tokens while still preserving any useful
operational context.

In `@src/main.tsx`:
- Line 4019: The CLI help text for the `--amount` option is hardcoded instead of
using the AIMLAPI limit constants, so it can drift from the validation rules.
Update the option definition in `main.tsx` to derive the displayed minimum and
maximum from the AIMLAPI bounds exported by `integrations/aimlapi/config.ts`,
keeping the help text aligned with the values enforced by the validation logic.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 872e4f18-a0bb-4e3d-93c3-3d9ff98fe1a8

📥 Commits

Reviewing files that changed from the base of the PR and between aac2d8c and 3a8671f.

⛔ Files ignored due to path filters (1)
  • src/integrations/generated/integrationManifest.generated.ts is excluded by !**/generated/**, !src/integrations/generated/**
📒 Files selected for processing (15)
  • src/cli/handlers/aimlapi.ts
  • src/components/ProviderManager.test.tsx
  • src/components/ProviderManager.tsx
  • src/integrations/aimlapi/client.ts
  • src/integrations/aimlapi/config.ts
  • src/integrations/aimlapi/index.ts
  • src/integrations/aimlapi/prompt.ts
  • src/integrations/aimlapi/topup.ts
  • src/integrations/artifactGenerator.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/gateways/aimlapi.ts
  • src/integrations/gateways/gitlawb-opengateway.ts
  • src/main.tsx
  • src/services/api/bootstrap.test.ts
  • src/services/api/client.test.ts
💤 Files with no reviewable changes (1)
  • src/integrations/gateways/gitlawb-opengateway.ts
📜 Review details
🧰 Additional context used
📓 Path-based instructions (8)
**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Use TypeScript with strict mode and ESM imports in source and test files.

Files:

  • src/cli/handlers/aimlapi.ts
  • src/integrations/aimlapi/index.ts
  • src/integrations/gateways/aimlapi.ts
  • src/main.tsx
  • src/integrations/aimlapi/prompt.ts
  • src/integrations/artifactGenerator.ts
  • src/services/api/client.test.ts
  • src/services/api/bootstrap.test.ts
  • src/integrations/aimlapi/client.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/aimlapi/config.ts
  • src/integrations/aimlapi/topup.ts
  • src/components/ProviderManager.test.tsx
  • src/components/ProviderManager.tsx
**/*

📄 CodeRabbit inference engine (CONTRIBUTING.md)

In the files you touch, preserve the existing code style.

Files:

  • src/cli/handlers/aimlapi.ts
  • src/integrations/aimlapi/index.ts
  • src/integrations/gateways/aimlapi.ts
  • src/main.tsx
  • src/integrations/aimlapi/prompt.ts
  • src/integrations/artifactGenerator.ts
  • src/services/api/client.test.ts
  • src/services/api/bootstrap.test.ts
  • src/integrations/aimlapi/client.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/aimlapi/config.ts
  • src/integrations/aimlapi/topup.ts
  • src/components/ProviderManager.test.tsx
  • src/components/ProviderManager.tsx

⚙️ CodeRabbit configuration file

**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.

Files:

  • src/cli/handlers/aimlapi.ts
  • src/integrations/aimlapi/index.ts
  • src/integrations/gateways/aimlapi.ts
  • src/main.tsx
  • src/integrations/aimlapi/prompt.ts
  • src/integrations/artifactGenerator.ts
  • src/services/api/client.test.ts
  • src/services/api/bootstrap.test.ts
  • src/integrations/aimlapi/client.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/aimlapi/config.ts
  • src/integrations/aimlapi/topup.ts
  • src/components/ProviderManager.test.tsx
  • src/components/ProviderManager.tsx
**

⚙️ CodeRabbit configuration file

**: # AGENTS.md - AI Agent Coding Guide

This guide is for AI coding agents working in the OpenClaude repository. Read it before changing code, and also follow CONTRIBUTING.md for contributor policy, PR expectations, review follow-up, and project scope.

Project Snapshot

OpenClaude is a coding-agent CLI for cloud and local model providers. It supports OpenAI-compatible APIs, Anthropic, Gemini, DeepSeek, Ollama, MCP, local backends, slash commands, tools, agents, and a React/Ink terminal UI.

The installed CLI runs on Node.js >=22.0.0. Bun is used for source builds, scripts, dependency management, and tests.

Work Style

  • Keep changes focused on one problem.
  • Prefer existing patterns in the file or nearby module.
  • Avoid unrelated formatting, renames, dependency changes, or broad rewrites.
  • Add or update tests when behavior changes.
  • Update docs when setup, commands, provider behavior, or user-facing behavior changes.
  • For new features, larger refactors, dependencies, or runtime changes, follow the issue-first guidance in CONTRIBUTING.md.

Stack And Conventions

  • TypeScript with strict mode and ESM imports.
  • React + Ink for terminal UI.
  • Bun lockfile and Bun scripts for development workflows.
  • Node runtime for the built CLI.

Common libraries and patterns:

  • chalk for terminal color.
  • commander for CLI argument parsing.
  • execa for child processes.
  • Existing service, provider, settings, permission, and UI patterns over new abstractions.

Repository Map

  • src/commands/ - slash and CLI command implementations.
  • src/components/ - React/Ink UI components.
  • src/services/ - API, MCP, OAuth, wiki, voice, and other service integrations.
  • src/tools/ - tool implementations.
  • src/utils/ - shared utilities.
  • src/integrations/ - provider and model integration metadata.
  • src/entrypoints/ - CLI, MCP, SDK, and generated public types.
  • src/tasks/ - local, remote, workflow, and monitor tas...

Files:

  • src/cli/handlers/aimlapi.ts
  • src/integrations/aimlapi/index.ts
  • src/integrations/gateways/aimlapi.ts
  • src/main.tsx
  • src/integrations/aimlapi/prompt.ts
  • src/integrations/artifactGenerator.ts
  • src/services/api/client.test.ts
  • src/services/api/bootstrap.test.ts
  • src/integrations/aimlapi/client.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/aimlapi/config.ts
  • src/integrations/aimlapi/topup.ts
  • src/components/ProviderManager.test.tsx
  • src/components/ProviderManager.tsx
src/{commands,components,services,tools,utils,integrations,entrypoints,tasks}/**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Prefer the existing service, provider, settings, permission, and UI patterns over introducing new abstractions.

Files:

  • src/integrations/aimlapi/index.ts
  • src/integrations/gateways/aimlapi.ts
  • src/integrations/aimlapi/prompt.ts
  • src/integrations/artifactGenerator.ts
  • src/services/api/client.test.ts
  • src/services/api/bootstrap.test.ts
  • src/integrations/aimlapi/client.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/aimlapi/config.ts
  • src/integrations/aimlapi/topup.ts
  • src/components/ProviderManager.test.tsx
  • src/components/ProviderManager.tsx
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}

⚙️ CodeRabbit configuration file

{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}: Review provider routing, model selection, env precedence, auth/token handling, OpenAI-compatible shims, retries, proxy behavior, and outbound HTTP behavior with high scrutiny. Block on silent default changes, hidden fallback expansion, credential reuse mistakes, hardcoded provider assumptions, or new network reach that is not intentional and documented.

Files:

  • src/integrations/aimlapi/index.ts
  • src/integrations/gateways/aimlapi.ts
  • src/integrations/aimlapi/prompt.ts
  • src/integrations/artifactGenerator.ts
  • src/services/api/client.test.ts
  • src/services/api/bootstrap.test.ts
  • src/integrations/aimlapi/client.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/aimlapi/config.ts
  • src/integrations/aimlapi/topup.ts
{bin/**,scripts/**,package.json,src/setup.ts,src/main.tsx,src/entrypoints/**}

⚙️ CodeRabbit configuration file

{bin/**,scripts/**,package.json,src/setup.ts,src/main.tsx,src/entrypoints/**}: Review install, launcher, build, packaging, startup, and entrypoint changes for cross-platform compatibility, tracked-source rewrites, env/config precedence, and release safety. Block on changes that can break Windows/macOS/Linux startup or publish unexpected artifacts.

Files:

  • src/main.tsx
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}

⚙️ CodeRabbit configuration file

{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}: Review tests for meaningful coverage of the changed behavior, isolation of global/env/config state, async cleanup, fake timers, provider profile leaks, and Windows-compatible assumptions. Block when risky runtime changes lack focused regression coverage or tests assert implementation details while missing the user-visible behavior.

Files:

  • src/services/api/client.test.ts
  • src/services/api/bootstrap.test.ts
  • src/integrations/discoveryService.test.ts
  • src/components/ProviderManager.test.tsx
src/components/**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Use React + Ink patterns for terminal UI components under src/components/.

Files:

  • src/components/ProviderManager.test.tsx
  • src/components/ProviderManager.tsx
🪛 ast-grep (0.44.1)
src/integrations/aimlapi/topup.ts

[warning] 186-186: Avoid logging sensitive data
Context: console.log(chalk.dim( -> Session ${session.sessionToken}))
Note: [CWE-532] Insertion of Sensitive Information into Log File.

(log-sensitive-data-typescript)


[warning] 238-238: Avoid logging sensitive data
Context: console.log( key ${chalk.dim(maskKey(apiKey))} (id ${apiKeyId}))
Note: [CWE-532] Insertion of Sensitive Information into Log File.

(log-sensitive-data-typescript)

🔇 Additional comments (19)
src/integrations/artifactGenerator.ts (1)

226-278: LGTM!

src/integrations/gateways/aimlapi.ts (1)

77-77: LGTM!

Partner ID value matches DEFAULT_PARTNER_ID in src/integrations/aimlapi/config.ts, and the description/badge changes align with the PR's intent to surface aimlapi as the recommended preset.

Also applies to: 90-91

src/integrations/discoveryService.test.ts (1)

463-467: LGTM!

src/services/api/bootstrap.test.ts (1)

220-220: LGTM!

src/services/api/client.test.ts (1)

642-642: LGTM!

src/integrations/aimlapi/client.ts (1)

15-166: LGTM!

src/integrations/aimlapi/config.ts (1)

13-75: LGTM!

src/integrations/aimlapi/prompt.ts (1)

9-63: LGTM!

src/integrations/aimlapi/topup.ts (2)

92-153: LGTM!

Also applies to: 155-320


238-238: LGTM!

src/integrations/aimlapi/index.ts (1)

1-12: LGTM!

src/main.tsx (2)

4020-4020: --method has no .choices() guard.

An invalid value (e.g. a typo) silently falls back to 'card' with no error, since the action handler does opts.method === 'crypto' ? 'crypto' : 'card'. Low-impact since the fallback is safe, but a one-line .choices(['card', 'crypto']) would surface user typos instead of masking them.

Also applies to: 4038-4038


4012-4044: LGTM on the subcommand wiring (dynamic import, --no-open negation via opts.open === false, option → AimlapiTopupOptions mapping) — no cross-platform/startup-path concerns for this new subcommand registration.

src/components/ProviderManager.tsx (4)

2374-2446: Amount validation duplicated between here and renderAimlapiTopupAmount.

The finite/min/max checks in startAimlapiTopup re-implement the same logic already enforced when the user submits the amount screen (lines 2551-2599). It's harmless (defensive re-check before firing the network call) but the two copies can drift over time.


48-57: LGTM!

Also applies to: 125-130, 827-837, 1578-1584


1972-2048: LGTM! Verified the full bidirectional screen graph: aimlapi-api-key-choice → email → password → amount → method → progress. Every handleBackFrom* mirrors its corresponding forward transition (cursor offsets included), and cancel is correctly blocked while isAimlapiTopupRunning is true.

Also applies to: 2288-2292


2448-2717: LGTM! Status-label map is a Record<AimlapiTopupStatus, string>, so TypeScript guarantees exhaustive coverage of all eight statuses from topup.ts, and the render switch wiring is correct.

Also applies to: 3145-3162

src/cli/handlers/aimlapi.ts (1)

1-26: LGTM!

src/components/ProviderManager.test.tsx (1)

111-121: LGTM!

Also applies to: 328-328, 443-450, 890-901

Comment on lines +924 to +1000
test('ProviderManager can top up AI/ML API and save the issued key', async () => {
const addProviderProfile = mock((payload: any) => ({
id: 'aimlapi_profile',
...payload,
}))
const provisionAimlapiKey = mock(async (options: any) => {
options.onStatus?.('creating-session')
options.onStatus?.('opening-checkout', 'https://app.aimlapi.com/checkout/test')
options.onStatus?.('waiting-payment')
options.onStatus?.('provisioning-key')
return {
apiKey: 'aimlapi-issued-key',
apiKeyId: 'key_test',
baseUrl: 'https://api.aimlapi.com/v1',
model: 'gpt-4o',
}
})

mockProviderManagerDependencies(() => undefined, async () => undefined, {
addProviderProfile,
provisionAimlapiKey,
})

const nonce = `${Date.now()}-${Math.random()}`
const { ProviderManager } = await import(`./ProviderManager.js?ts=${nonce}`)
const mounted = await mountProviderManager(ProviderManager)

try {
await waitForFrameOutput(mounted.getOutput, frame =>
frame.includes('Provider manager'),
)

mounted.stdin.write('\r')
await waitForFrameOutput(mounted.getOutput, frame =>
frame.includes('Choose provider preset'),
)

await navigateToPreset(mounted.stdin, 'AI/ML API')
mounted.stdin.write('\r')
await waitForFrameOutput(mounted.getOutput, frame =>
frame.includes('Step 1 of 2: Default model'),
)

mounted.stdin.write('\r')
await waitForFrameOutput(mounted.getOutput, frame =>
frame.includes('Top up and get API key'),
)

mounted.stdin.write('\r')
await waitForFrameOutput(mounted.getOutput, frame =>
frame.includes('Enter your AI/ML API account email'),
)
mounted.stdin.write('user@example.com')
await Bun.sleep(25)
mounted.stdin.write('\r')

await waitForFrameOutput(mounted.getOutput, frame =>
frame.includes('Enter your AI/ML API password'),
)
mounted.stdin.write('secret-password')
await Bun.sleep(25)
mounted.stdin.write('\r')

await waitForFrameOutput(mounted.getOutput, frame =>
frame.includes('Choose a top-up amount in USD') &&
frame.includes('25'),
)
mounted.stdin.write('\r')

await waitForFrameOutput(mounted.getOutput, frame =>
frame.includes('Payment method') &&
frame.includes('Card') &&
frame.includes('Crypto'),
)
mounted.stdin.write('j')
await Bun.sleep(25)
mounted.stdin.write('\r')

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Map the relevant files and locate the AI/ML API top-up path.
git ls-files 'src/components/ProviderManager.test.tsx' 'src/components/ProviderManager.tsx' 'src/**/aimlapi*' 'src/**/ProviderManager*' | sort

echo '--- outline ProviderManager.test.tsx ---'
ast-grep outline src/components/ProviderManager.test.tsx --view expanded || true

echo '--- outline ProviderManager.tsx ---'
ast-grep outline src/components/ProviderManager.tsx --view expanded || true

echo '--- search for AIMLAPI env usage ---'
rg -n "AIMLAPI_EMAIL|AIMLAPI_PASSWORD|renderAimlapiApiKeyChoice|topup" src/components src/services src/utils src/commands src/integrations | sed -n '1,240p'

Repository: Gitlawb/openclaude

Length of output: 7084


🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Read the implementation around the top-up branch.
file=src/components/ProviderManager.tsx
line=$(rg -n "renderAimlapiApiKeyChoice|AIMLAPI_EMAIL|AIMLAPI_PASSWORD" "$file" | head -n 1 | cut -d: -f1 || true)
if [ -n "${line:-}" ]; then
  start=$((line-80)); [ "$start" -lt 1 ] && start=1
  end=$((line+180))
  sed -n "${start},${end}p" "$file" | cat -n
fi

echo '--- relevant test section ---'
sed -n '924,1000p' src/components/ProviderManager.test.tsx | cat -n

echo '--- existing env isolation patterns in tests ---'
rg -n "delete process\.env\.AIMLAPI_|originalAimlapi|process\.env\.[A-Z_]+ =|delete process\.env\." src/components/ProviderManager.test.tsx src/**/*.test.tsx src/**/*.test.ts | sed -n '1,240p'

Repository: Gitlawb/openclaude

Length of output: 34052


🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Check whether the test suite or nearby tests rely on these vars being present.
rg -n "AIMLAPI_EMAIL|AIMLAPI_PASSWORD" . --glob '!**/node_modules/**' --glob '!**/dist/**' --glob '!**/build/**' | sed -n '1,240p'

Repository: Gitlawb/openclaude

Length of output: 1244


🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Probe the exact branch logic with a read-only script snippet extracted from the file.
python3 - <<'PY'
from pathlib import Path
import re
text = Path('src/components/ProviderManager.tsx').read_text()
for pat in ['AIMLAPI_EMAIL', 'AIMLAPI_PASSWORD', 'topup', 'renderAimlapiApiKeyChoice']:
    print(f'--- {pat} ---')
    for m in re.finditer(pat, text):
        s = max(0, m.start()-260)
        e = min(len(text), m.end()+520)
        print(text[s:e])
        print('====')
        break
PY

Repository: Gitlawb/openclaude

Length of output: 3454


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo '--- ProviderManager env-branch implementation ---'
rg -n -A40 -B40 "AIMLAPI_EMAIL|AIMLAPI_PASSWORD|renderAimlapiApiKeyChoice|topup" src/components/ProviderManager.tsx | sed -n '1,240p'

echo '--- targeted test snippet ---'
sed -n '924,1000p' src/components/ProviderManager.test.tsx | cat -n

echo '--- all repo env references ---'
rg -n "AIMLAPI_EMAIL|AIMLAPI_PASSWORD" src tests . --glob '!**/node_modules/**' --glob '!**/dist/**' --glob '!**/build/**' | sed -n '1,240p'

Repository: Gitlawb/openclaude

Length of output: 13508


🏁 Script executed:

#!/bin/bash
set -euo pipefail

python3 - <<'PY'
from pathlib import Path
text = Path('src/components/ProviderManager.tsx').read_text()
needles = ['AIMLAPI_EMAIL', 'AIMLAPI_PASSWORD', 'renderAimlapiApiKeyChoice', 'topup']
for needle in needles:
    idx = text.find(needle)
    print(f'=== {needle} @ {idx} ===')
    if idx != -1:
        start = max(0, idx - 900)
        end = min(len(text), idx + 1600)
        print(text[start:end])
        print()
PY

Repository: Gitlawb/openclaude

Length of output: 10290


🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Try a narrow search around the topup branch in the component file.
file='src/components/ProviderManager.tsx'
match_line=$(rg -n "AIMLAPI_EMAIL|AIMLAPI_PASSWORD|topup" "$file" | head -n 1 | cut -d: -f1)
echo "match_line=${match_line:-none}"
if [ -n "${match_line:-}" ]; then
  start=$((match_line-120)); [ "$start" -lt 1 ] && start=1
  end=$((match_line+240))
  sed -n "${start},${end}p" "$file" | cat -n
fi

Repository: Gitlawb/openclaude

Length of output: 13544


Clear AIMLAPI_EMAIL/AIMLAPI_PASSWORD in this test.
renderAimlapiApiKeyChoice skips the email/password prompts when both are set, so this case can hang waiting for a screen that never renders. Save and restore both env vars around the test.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/components/ProviderManager.test.tsx` around lines 924 - 1000, This
ProviderManager top-up test is relying on the email/password prompts, but
renderAimlapiApiKeyChoice will bypass them if AIMLAPI_EMAIL and AIMLAPI_PASSWORD
are already set. Update the test to save the current env values, clear both
before mounting ProviderManager and running the flow, then restore them
afterward so the prompts are rendered consistently and the test cannot hang.

Source: Path instructions

Comment thread src/integrations/aimlapi/client.ts
Comment thread src/integrations/aimlapi/topup.ts Outdated
Comment thread src/integrations/aimlapi/topup.ts
Comment thread src/main.tsx Outdated
@jatmn jatmn linked an issue Jul 7, 2026 that may be closed by this pull request

@jatmn jatmn left a comment •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please do not change preset order.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
src/integrations/aimlapi/client.ts (1)

186-206: 🩺 Stability & Availability | 🟠 Major | ⚡ Quick win

Wrap response.text() in the timeout guard

AbortSignal.timeout(...) can also fire while the body is being consumed. If headers arrive but the body stalls, response.text() rejects outside this try/catch, so the error escapes as a raw abort instead of AimlapiApiError(status=0). That bypasses the retry in pollUntilPaid() and can abort an in-progress top-up.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/integrations/aimlapi/client.ts` around lines 186 - 206, The timeout
handling around the fetch in Aimlapi client is incomplete because
response.text() can still be aborted after headers arrive, escaping as a raw
abort instead of AimlapiApiError. Update the request flow in client.ts around
the fetch/response handling so the body read is covered by the same try/catch
used for the network call, and convert any abort or body-consumption failure
into AimlapiApiError with status 0. Keep the existing error path in the
AimlapiApiError construction and the request logic in the fetch/response.text
sequence.

Source: Path instructions

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@src/main.tsx`:
- Line 4021: The `--method` option currently accepts any string and later falls
back to `card`, which hides typos instead of failing fast. Update the command
definitions in `main.tsx` (and the matching option in `topup.ts`) to use
`.choices()` for the payment method so only valid values like `card` and
`crypto` are accepted. Make sure the parsing logic in the `method` handling path
no longer performs a silent default for invalid input.

---

Outside diff comments:
In `@src/integrations/aimlapi/client.ts`:
- Around line 186-206: The timeout handling around the fetch in Aimlapi client
is incomplete because response.text() can still be aborted after headers arrive,
escaping as a raw abort instead of AimlapiApiError. Update the request flow in
client.ts around the fetch/response handling so the body read is covered by the
same try/catch used for the network call, and convert any abort or
body-consumption failure into AimlapiApiError with status 0. Keep the existing
error path in the AimlapiApiError construction and the request logic in the
fetch/response.text sequence.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 0f21f2b9-a542-4b0e-916b-7ca236f97f8b

📥 Commits

Reviewing files that changed from the base of the PR and between abb6d4f and 04d67e6.

⛔ Files ignored due to path filters (1)
  • src/integrations/generated/integrationManifest.generated.ts is excluded by !**/generated/**, !src/integrations/generated/**
📒 Files selected for processing (4)
  • src/components/ProviderManager.test.tsx
  • src/integrations/aimlapi/client.ts
  • src/integrations/aimlapi/topup.ts
  • src/main.tsx
📜 Review details
🧰 Additional context used
📓 Path-based instructions (8)
**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Use TypeScript with strict mode and ESM imports in source and test files.

Files:

  • src/main.tsx
  • src/integrations/aimlapi/client.ts
  • src/components/ProviderManager.test.tsx
  • src/integrations/aimlapi/topup.ts
**/*

📄 CodeRabbit inference engine (CONTRIBUTING.md)

In the files you touch, preserve the existing code style.

Files:

  • src/main.tsx
  • src/integrations/aimlapi/client.ts
  • src/components/ProviderManager.test.tsx
  • src/integrations/aimlapi/topup.ts

⚙️ CodeRabbit configuration file

**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.

Files:

  • src/main.tsx
  • src/integrations/aimlapi/client.ts
  • src/components/ProviderManager.test.tsx
  • src/integrations/aimlapi/topup.ts
**

⚙️ CodeRabbit configuration file

**: # AGENTS.md - AI Agent Coding Guide

This guide is for AI coding agents working in the OpenClaude repository. Read it before changing code, and also follow CONTRIBUTING.md for contributor policy, PR expectations, review follow-up, and project scope.

Project Snapshot

OpenClaude is a coding-agent CLI for cloud and local model providers. It supports OpenAI-compatible APIs, Anthropic, Gemini, DeepSeek, Ollama, MCP, local backends, slash commands, tools, agents, and a React/Ink terminal UI.

The installed CLI runs on Node.js >=22.0.0. Bun is used for source builds, scripts, dependency management, and tests.

Work Style

  • Keep changes focused on one problem.
  • Prefer existing patterns in the file or nearby module.
  • Avoid unrelated formatting, renames, dependency changes, or broad rewrites.
  • Add or update tests when behavior changes.
  • Update docs when setup, commands, provider behavior, or user-facing behavior changes.
  • For new features, larger refactors, dependencies, or runtime changes, follow the issue-first guidance in CONTRIBUTING.md.

Stack And Conventions

  • TypeScript with strict mode and ESM imports.
  • React + Ink for terminal UI.
  • Bun lockfile and Bun scripts for development workflows.
  • Node runtime for the built CLI.

Common libraries and patterns:

  • chalk for terminal color.
  • commander for CLI argument parsing.
  • execa for child processes.
  • Existing service, provider, settings, permission, and UI patterns over new abstractions.

Repository Map

  • src/commands/ - slash and CLI command implementations.
  • src/components/ - React/Ink UI components.
  • src/services/ - API, MCP, OAuth, wiki, voice, and other service integrations.
  • src/tools/ - tool implementations.
  • src/utils/ - shared utilities.
  • src/integrations/ - provider and model integration metadata.
  • src/entrypoints/ - CLI, MCP, SDK, and generated public types.
  • src/tasks/ - local, remote, workflow, and monitor tas...

Files:

  • src/main.tsx
  • src/integrations/aimlapi/client.ts
  • src/components/ProviderManager.test.tsx
  • src/integrations/aimlapi/topup.ts
{bin/**,scripts/**,package.json,src/setup.ts,src/main.tsx,src/entrypoints/**}

⚙️ CodeRabbit configuration file

{bin/**,scripts/**,package.json,src/setup.ts,src/main.tsx,src/entrypoints/**}: Review install, launcher, build, packaging, startup, and entrypoint changes for cross-platform compatibility, tracked-source rewrites, env/config precedence, and release safety. Block on changes that can break Windows/macOS/Linux startup or publish unexpected artifacts.

Files:

  • src/main.tsx
src/{commands,components,services,tools,utils,integrations,entrypoints,tasks}/**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Prefer the existing service, provider, settings, permission, and UI patterns over introducing new abstractions.

Files:

  • src/integrations/aimlapi/client.ts
  • src/components/ProviderManager.test.tsx
  • src/integrations/aimlapi/topup.ts
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}

⚙️ CodeRabbit configuration file

{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}: Review provider routing, model selection, env precedence, auth/token handling, OpenAI-compatible shims, retries, proxy behavior, and outbound HTTP behavior with high scrutiny. Block on silent default changes, hidden fallback expansion, credential reuse mistakes, hardcoded provider assumptions, or new network reach that is not intentional and documented.

Files:

  • src/integrations/aimlapi/client.ts
  • src/integrations/aimlapi/topup.ts
src/components/**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Use React + Ink patterns for terminal UI components under src/components/.

Files:

  • src/components/ProviderManager.test.tsx
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}

⚙️ CodeRabbit configuration file

{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}: Review tests for meaningful coverage of the changed behavior, isolation of global/env/config state, async cleanup, fake timers, provider profile leaks, and Windows-compatible assumptions. Block when risky runtime changes lack focused regression coverage or tests assert implementation details while missing the user-visible behavior.

Files:

  • src/components/ProviderManager.test.tsx
🔇 Additional comments (4)
src/main.tsx (1)

39-39: LGTM!

Resolves the earlier feedback to source --amount bounds from MIN_AMOUNT_USD_MINOR/MAX_AMOUNT_USD_MINOR instead of hardcoding $20/$10000.

Also applies to: 4020-4020

src/components/ProviderManager.test.tsx (1)

29-30: LGTM! This resolves the previously flagged hang risk — AIMLAPI_EMAIL/AIMLAPI_PASSWORD are now cleared before the top-up test runs and captured in the env snapshot for restore, so the email/password prompt screens are reliably exercised. As per path instructions, tests touching env state should isolate it, and this now does.

Also applies to: 927-929

src/integrations/aimlapi/client.ts (1)

55-55: LGTM!

Also applies to: 191-191

src/integrations/aimlapi/topup.ts (1)

187-187: LGTM!

Also applies to: 333-334

Comment thread src/main.tsx Outdated
@Lookoff-AIMLAPI

Copy link
Copy Markdown
Contributor Author

Fixed — reverted the "pin AI/ML API first" rule in artifactGenerator.ts and regenerated the manifest. Preset order is back to gitlawb-opengateway → anthropic → aimlapi → ..., same as main. Also addressed all 5 CodeRabbit findings (fetch timeout, no longer logging the session token, retry on network errors during poll, cleared env vars in the new test, --amount help text sourced from config bounds).

@jatmn could you please re-review?

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@src/main.tsx`:
- Line 4019: The password CLI option on the command definition exposes
credentials in shell history and process listings, so remove the value-accepting
`--password <password>` flag from `src/main.tsx` and rely on `AIMLAPI_PASSWORD`
plus the existing hidden prompt flow. Update the related command setup and any
password-handling logic to use the `promptHidden` helper from `prompt.ts` for
interactive entry instead of accepting the password as a CLI argument.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 4c11b41b-99a3-4dca-9da7-bad87573bf5a

📥 Commits

Reviewing files that changed from the base of the PR and between 04d67e6 and 5148f40.

📒 Files selected for processing (1)
  • src/main.tsx
📜 Review details
🧰 Additional context used
📓 Path-based instructions (4)
**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Use TypeScript with strict mode and ESM imports in source and test files.

Files:

  • src/main.tsx
**/*

📄 CodeRabbit inference engine (CONTRIBUTING.md)

In the files you touch, preserve the existing code style.

Files:

  • src/main.tsx

⚙️ CodeRabbit configuration file

**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.

Files:

  • src/main.tsx
**

⚙️ CodeRabbit configuration file

**: # AGENTS.md - AI Agent Coding Guide

This guide is for AI coding agents working in the OpenClaude repository. Read it before changing code, and also follow CONTRIBUTING.md for contributor policy, PR expectations, review follow-up, and project scope.

Project Snapshot

OpenClaude is a coding-agent CLI for cloud and local model providers. It supports OpenAI-compatible APIs, Anthropic, Gemini, DeepSeek, Ollama, MCP, local backends, slash commands, tools, agents, and a React/Ink terminal UI.

The installed CLI runs on Node.js >=22.0.0. Bun is used for source builds, scripts, dependency management, and tests.

Work Style

  • Keep changes focused on one problem.
  • Prefer existing patterns in the file or nearby module.
  • Avoid unrelated formatting, renames, dependency changes, or broad rewrites.
  • Add or update tests when behavior changes.
  • Update docs when setup, commands, provider behavior, or user-facing behavior changes.
  • For new features, larger refactors, dependencies, or runtime changes, follow the issue-first guidance in CONTRIBUTING.md.

Stack And Conventions

  • TypeScript with strict mode and ESM imports.
  • React + Ink for terminal UI.
  • Bun lockfile and Bun scripts for development workflows.
  • Node runtime for the built CLI.

Common libraries and patterns:

  • chalk for terminal color.
  • commander for CLI argument parsing.
  • execa for child processes.
  • Existing service, provider, settings, permission, and UI patterns over new abstractions.

Repository Map

  • src/commands/ - slash and CLI command implementations.
  • src/components/ - React/Ink UI components.
  • src/services/ - API, MCP, OAuth, wiki, voice, and other service integrations.
  • src/tools/ - tool implementations.
  • src/utils/ - shared utilities.
  • src/integrations/ - provider and model integration metadata.
  • src/entrypoints/ - CLI, MCP, SDK, and generated public types.
  • src/tasks/ - local, remote, workflow, and monitor tas...

Files:

  • src/main.tsx
{bin/**,scripts/**,package.json,src/setup.ts,src/main.tsx,src/entrypoints/**}

⚙️ CodeRabbit configuration file

{bin/**,scripts/**,package.json,src/setup.ts,src/main.tsx,src/entrypoints/**}: Review install, launcher, build, packaging, startup, and entrypoint changes for cross-platform compatibility, tracked-source rewrites, env/config precedence, and release safety. Block on changes that can break Windows/macOS/Linux startup or publish unexpected artifacts.

Files:

  • src/main.tsx
🔇 Additional comments (1)
src/main.tsx (1)

4013-4018: LGTM!

Also applies to: 4020-4020, 4022-4045

Comment thread src/main.tsx Outdated

@jatmn jatmn left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I found a few issues that need to be addressed before this is ready.

Findings

  • [P1] Fix the failing AI/ML API ProviderManager tests
    src/components/ProviderManager.test.tsx:120
    The new AI/ML API tests now fail in a fresh checkout because PRESET_ORDER still pins AI/ML API first, but the current manifest restored Gitlawb Opengateway as the first preset after the maintainer request. As a result, navigateToPreset(mounted.stdin, 'AI/ML API') selects the wrong mocked preset, ProviderManager saves AI/ML API preset... sees Mock provider instead of AI/ML API, and ProviderManager can top up AI/ML API... times out before the top-up screen. Please realign the test helper with the actual preset order or make it derive the target from rendered labels so the changed tests exercise the AI/ML API path again.

  • [P2] Complete CodeRabbit's request to normalize body-read aborts
    src/integrations/aimlapi/client.ts:199
    CodeRabbit's timeout follow-up is still valid: the fetch() call is inside the try/catch, but response.text() is awaited after that block. If headers arrive and the body stalls or the timeout fires while consuming the body, the abort escapes as a raw error instead of AimlapiApiError(status=0), so pollUntilPaid() cannot use its transient retry path and an in-progress checkout wait can abort. Please keep the body read inside the same normalized error handling.

  • [P2] Complete CodeRabbit's request to avoid argv password exposure
    src/main.tsx:4019
    The CLI still accepts --password <password> and forwards it into the top-up flow. That puts the AI/ML API account password in shell history and process listings while the command runs, even though this PR already has AIMLAPI_PASSWORD and the hidden promptHidden() path for non-echoed interactive entry. Please remove the value-taking password flag and rely on env/hidden prompt instead.

@Lookoff-AIMLAPI

Copy link
Copy Markdown
Contributor Author

Fixed all three:

PRESET_ORDER in the test helper now matches the restored order (Gitlawb Opengateway, Anthropic, AI/ML API, ...) — verified against ORDERED_PROVIDER_PRESETS directly.

Body read (response.text()) is now inside the same try/catch as fetch(), so a timeout/abort mid-body normalizes to AimlapiApiError(status=0) and pollUntilPaid can retry it.

Removed the value-taking --password CLI flag; only AIMLAPI_PASSWORD env / hidden prompt remain.

@jatmn ready for re-review, please

@jatmn jatmn left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the update. I rechecked the current branch and found issues that still need to be addressed.

Findings

  • [P1] Fix the failing smoke-and-tests check
    src/integrations/aimlapi/client.ts:192
    The current GitHub smoke-and-tests (22) job fails in bun run check because scripts/no-raw-abort-signal-timeout.test.ts rejects this new AbortSignal.timeout(REQUEST_TIMEOUT_MS) call. The repository has a guard for this because raw AbortSignal.timeout() leaks native memory under Bun; timeout fetches should use the cleanup-safe helper pattern, such as createCombinedAbortSignal(..., { timeoutMs }), and call cleanup() after the fetch/body read completes. Please replace the raw timeout signal so the smoke job can pass again.

  • [P3] Remove the stale --password guidance from non-interactive top-up errors
    src/integrations/aimlapi/prompt.ts:12
    The CLI correctly no longer registers a value-taking --password option, but the non-TTY guard still tells users to provide credentials via --email/--password. Running openclaude aimlapi topup --help confirms there is no password flag, while a non-interactive run without AIMLAPI_PASSWORD prints this impossible instruction. Please update this message to point users at AIMLAPI_PASSWORD or an interactive hidden prompt instead of the removed flag.

@Lookoff-AIMLAPI

Copy link
Copy Markdown
Contributor Author

Fixed both — smoke check should pass now (AbortSignal.timeout replaced with createCombinedAbortSignal + cleanup()), and the non-interactive error message no longer mentions the removed --password flag.

@jatmn could you please re-review?

@jatmn jatmn left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the update. I rechecked the current branch and found one issue that still needs to be addressed.

Findings

  • [P2] Update the AI/ML API setup guide for guided top-up
    docs/aimlapi-setup.md:11
    The README still links this file as the AI/ML API setup guide, but the guide now drifts from the feature added in this PR: it says users must already have an AI/ML API account and API key from the dashboard, and the /provider instructions only tell them to paste an existing key. The linked issue and this implementation specifically remove that blocker by adding “Top up and get API key” plus openclaude aimlapi topup, so users following the documented setup path will still think they need to leave OpenClaude and manually create a key. Please update the setup guide to describe both supported paths: guided top-up/key provisioning and entering an existing key.

@Lookoff-AIMLAPI

Copy link
Copy Markdown
Contributor Author

Fixed — updated the setup guide to document both paths (guided top-up via /provider or openclaude aimlapi topup, plus entering an existing key), so it no longer implies users must create a key manually on the dashboard first.

Ready for re-review, please. (@jatmn )

@jatmn jatmn left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the update. I rechecked the previously discussed paths and do not see any remaining actionable issues from my side.

@kevincodex1 LGTM

@Lookoff-AIMLAPI

Copy link
Copy Markdown
Contributor Author

Thanks a lot for the thorough review and all the feedback throughout this process. I really appreciate the time and effort you put into it—it was a great learning experience for me. Glad we got everything sorted out!

@jatmn

jatmn commented Jul 7, 2026

Copy link
Copy Markdown
Collaborator

Thanks for the contribution :)

baseUrlEnvVars: ['OPENGATEWAY_BASE_URL', 'OPENAI_BASE_URL'],
fallbackBaseUrl: 'https://opengateway.gitlawb.com/v1',
fallbackModel: 'mimo-v2.5-pro',
badge: { text: 'Recommended', color: 'success' },

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

please dont remove this . OpenGateway is our own gateway so it will be always on top and AIML will be below it but still recommended

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

was format change, its still there :)

@kevincodex1
kevincodex1 merged commit 9a53290 into Twigpine:main Jul 8, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Guided AI/ML API top-up and API key provisioning

4 participants