{
  "$defs": {
    "RawEgress": {
      "additionalProperties": false,
      "description": "``egress:`` \u2014 extra runtime destinations a provider legitimately reaches.\n\n``allow`` hosts feed the shield's ``provider_allow`` tier (t30) \u2014 traffic\nthe agent makes *directly* at runtime, additional to the vault-relayed API\nhost (e.g. telemetry or a model-listing endpoint).  Build-time fetches do\n**not** belong here: image build runs before the shield attaches.",
      "properties": {
        "allow": {
          "description": "Hosts allowed directly at egress (t30)",
          "items": {
            "type": "string"
          },
          "title": "Allow",
          "type": "array"
        }
      },
      "title": "RawEgress",
      "type": "object"
    },
    "RawHelp": {
      "additionalProperties": false,
      "description": "``help:`` \u2014 one-line entry shown in the in-container help banner.",
      "properties": {
        "label": {
          "default": "",
          "title": "Label",
          "type": "string"
        },
        "section": {
          "default": "agent",
          "enum": [
            "agent",
            "dev_tool"
          ],
          "title": "Section",
          "type": "string"
        }
      },
      "title": "RawHelp",
      "type": "object"
    },
    "RawInstall": {
      "additionalProperties": false,
      "description": "``install:`` \u2014 Dockerfile fragments emitted into the L1 image.",
      "properties": {
        "depends_on": {
          "items": {
            "type": "string"
          },
          "title": "Depends On",
          "type": "array"
        },
        "run_as_root": {
          "default": "",
          "title": "Run As Root",
          "type": "string"
        },
        "run_as_dev": {
          "default": "",
          "title": "Run As Dev",
          "type": "string"
        }
      },
      "title": "RawInstall",
      "type": "object"
    },
    "RawOAuthRefresh": {
      "additionalProperties": false,
      "description": "``vault.oauth_refresh:`` \u2014 token-refresh endpoint and client config.",
      "properties": {
        "token_url": {
          "title": "Token Url",
          "type": "string"
        },
        "client_id": {
          "title": "Client Id",
          "type": "string"
        },
        "scope": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ],
          "default": null,
          "title": "Scope"
        }
      },
      "required": [
        "token_url",
        "client_id"
      ],
      "title": "RawOAuthRefresh",
      "type": "object"
    },
    "RawOpenCode": {
      "additionalProperties": false,
      "description": "``opencode:`` \u2014 OpenAI-compatible provider config for OpenCode-based agents.",
      "properties": {
        "display_name": {
          "title": "Display Name",
          "type": "string"
        },
        "base_url": {
          "title": "Base Url",
          "type": "string"
        },
        "preferred_model": {
          "title": "Preferred Model",
          "type": "string"
        },
        "fallback_model": {
          "title": "Fallback Model",
          "type": "string"
        },
        "env_var_prefix": {
          "title": "Env Var Prefix",
          "type": "string"
        },
        "config_dir": {
          "title": "Config Dir",
          "type": "string"
        },
        "auth_key_url": {
          "title": "Auth Key Url",
          "type": "string"
        },
        "api_key_hint": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ],
          "default": null,
          "description": "Override for the auto-derived auth provider's API-key hint",
          "title": "Api Key Hint"
        }
      },
      "required": [
        "display_name",
        "base_url",
        "preferred_model",
        "fallback_model",
        "env_var_prefix",
        "config_dir",
        "auth_key_url"
      ],
      "title": "RawOpenCode",
      "type": "object"
    },
    "RawProviderAuth": {
      "additionalProperties": false,
      "description": "``auth:`` \u2014 at least one of ``api_key`` / ``oauth`` must be present.\n\nDeclaring both with *different* headers is how a provider expresses the\nOAuth-or-API-key header switch (Anthropic); the projection collapses that\nto the ``auth_header: dynamic`` wire sentinel\n(see [`Provider.wire_auth`][terok_executor.roster.types.Provider.wire_auth]).",
      "properties": {
        "api_key": {
          "anyOf": [
            {
              "$ref": "#/$defs/RawProviderAuthMode"
            },
            {
              "type": "null"
            }
          ],
          "default": null
        },
        "oauth": {
          "anyOf": [
            {
              "$ref": "#/$defs/RawProviderAuthMode"
            },
            {
              "type": "null"
            }
          ],
          "default": null
        }
      },
      "title": "RawProviderAuth",
      "type": "object"
    },
    "RawProviderAuthMode": {
      "additionalProperties": false,
      "description": "Define wire authentication for an ``auth.api_key`` or ``auth.oauth`` block.",
      "properties": {
        "header": {
          "default": "",
          "description": "HTTP header that contains the credential. For an empty block, the default is ``Authorization``. For a block that is not empty, this field is required.",
          "title": "Header",
          "type": "string"
        },
        "prefix": {
          "default": "",
          "description": "Text before the credential. For an empty block, the default is ``Bearer ``. If a block contains only ``header``, the prefix stays empty. This behavior supports legacy files.",
          "title": "Prefix",
          "type": "string"
        },
        "extra_headers": {
          "additionalProperties": {
            "type": "string"
          },
          "description": "Additional headers for this authentication mode.",
          "title": "Extra Headers",
          "type": "object"
        }
      },
      "title": "RawProviderAuthMode",
      "type": "object"
    },
    "RawProviderModel": {
      "additionalProperties": false,
      "description": "Define the name and limits for one model in ``models.<id>``.",
      "properties": {
        "name": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ],
          "default": null,
          "description": "Model name that users see",
          "title": "Name"
        },
        "limit": {
          "$ref": "#/$defs/RawProviderModelLimit"
        }
      },
      "title": "RawProviderModel",
      "type": "object"
    },
    "RawProviderModelLimit": {
      "additionalProperties": false,
      "description": "Define optional token limits in ``models.<id>.limit``.",
      "properties": {
        "context": {
          "anyOf": [
            {
              "exclusiveMinimum": 0,
              "type": "integer"
            },
            {
              "type": "null"
            }
          ],
          "default": null,
          "description": "Maximum number of tokens in the context window",
          "title": "Context"
        },
        "output": {
          "anyOf": [
            {
              "exclusiveMinimum": 0,
              "type": "integer"
            },
            {
              "type": "null"
            }
          ],
          "default": null,
          "description": "Maximum number of tokens in generated output",
          "title": "Output"
        }
      },
      "title": "RawProviderModelLimit",
      "type": "object"
    }
  },
  "additionalProperties": false,
  "description": "Full schema for one ``resources/providers/*.yaml`` file.\n\nThe file's stem (``anthropic.yaml`` \u2192 ``\"anthropic\"``) supplies the provider\nname; the YAML never repeats it.  Strict keys reject typos\n(``upstreams:``, ``oath:``) the same way the agent schema does.",
  "properties": {
    "label": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ],
      "default": null,
      "description": "Provider name that users see",
      "title": "Label"
    },
    "upstream": {
      "description": "Upstream API base URL",
      "title": "Upstream",
      "type": "string"
    },
    "auth": {
      "$ref": "#/$defs/RawProviderAuth"
    },
    "path_upstreams": {
      "additionalProperties": {
        "type": "string"
      },
      "title": "Path Upstreams",
      "type": "object"
    },
    "oauth_credential_headers": {
      "additionalProperties": {
        "type": "string"
      },
      "title": "Oauth Credential Headers",
      "type": "object"
    },
    "oauth_refresh": {
      "anyOf": [
        {
          "$ref": "#/$defs/RawOAuthRefresh"
        },
        {
          "type": "null"
        }
      ],
      "default": null
    },
    "shared_domain": {
      "default": false,
      "title": "Shared Domain",
      "type": "boolean"
    },
    "egress": {
      "anyOf": [
        {
          "$ref": "#/$defs/RawEgress"
        },
        {
          "type": "null"
        }
      ],
      "default": null,
      "description": "Extra runtime egress hosts allowed at t30"
    },
    "serves": {
      "additionalProperties": {
        "type": "string"
      },
      "description": "Wire protocol \u2192 container-facing base path (LLM providers only)",
      "title": "Serves",
      "type": "object"
    },
    "default_model": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ],
      "default": null,
      "description": "Default model ID for OpenCode and Pi",
      "title": "Default Model"
    },
    "models": {
      "additionalProperties": {
        "$ref": "#/$defs/RawProviderModel"
      },
      "description": "Model data. Each key is a model ID.",
      "title": "Models",
      "type": "object"
    },
    "opencode": {
      "anyOf": [
        {
          "$ref": "#/$defs/RawOpenCode"
        },
        {
          "type": "null"
        }
      ],
      "default": null,
      "description": "OpenCode wrapper config for a harness-driven provider (Blablador, \u2026)"
    },
    "install": {
      "anyOf": [
        {
          "$ref": "#/$defs/RawInstall"
        },
        {
          "type": "null"
        }
      ],
      "default": null,
      "description": "Pinned-alias install fragment for a harness-driven provider"
    },
    "help": {
      "anyOf": [
        {
          "$ref": "#/$defs/RawHelp"
        },
        {
          "type": "null"
        }
      ],
      "default": null,
      "description": "Help-listing entry for the command"
    }
  },
  "required": [
    "upstream",
    "auth"
  ],
  "title": "terok-executor provider YAML",
  "type": "object",
  "$schema": "https://json-schema.org/draft/2020-12/schema"
}
