Something went wrong. Try again.
A local-first event pipeline for independent agents, built on Jazz.
Something went wrong. Try again.
7.0 kB · 172 lines
TypeScript
123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173import { z } from "zod";
export type ProviderKind = "tinker" | "openai-compatible";
export interface ProviderProfile { id: string; provider: ProviderKind; baseUrl: string; route: "/chat/completions"; apiKeyEnv: string; allowedModels: ReadonlySet<string>; imageInputModels: ReadonlySet<string>; jsonObjectResponseFormat: boolean; jsonSchemaResponseFormat: boolean; requestTimeoutMs: number; maxRequestBytes: number; maxResponseBytes: number;}
export interface ProviderProfileResolver { resolve(profileId: string, model: string): ProviderProfile;}
const profileIdSchema = z.string().min(1).max(100).regex(/^[a-z0-9][a-z0-9.-]*$/);const modelSchema = z.string().min(1).max(500);
export const BUILTIN_PROVIDER_PROFILE_IDS = ["tinker-default", "openai-json-default", "openai-compatible-default"] as const;export type BuiltinProviderProfileId = typeof BUILTIN_PROVIDER_PROFILE_IDS[number];
export function providerKindForProfile(profileId: string): ProviderKind { if (profileId === "tinker-default") return "tinker"; if (profileId === "openai-json-default") return "openai-compatible"; if (profileId === "openai-compatible-default") return "openai-compatible"; throw new Error(`Unknown trusted provider profile: ${profileId}`);}
export function createBuiltinProviderProfileResolver(environment: NodeJS.ProcessEnv = process.env): ProviderProfileResolver { return { resolve(profileId, model) { profileIdSchema.parse(profileId); modelSchema.parse(model); const profile = buildBuiltinProfile(profileId, environment); if (!profile.allowedModels.has(model)) { throw new Error(`Requested model is not allowlisted by provider profile ${profileId}`); } return profile; }, };}
export function staticProviderProfileResolver(profiles: ProviderProfile[]): ProviderProfileResolver { const byId = new Map(profiles.map((profile) => [profile.id, validateProfile(profile)])); return { resolve(profileId, model) { const profile = byId.get(profileId); if (!profile) throw new Error(`Unknown trusted provider profile: ${profileId}`); if (!profile.allowedModels.has(model)) { throw new Error(`Requested model is not allowlisted by provider profile ${profileId}`); } return profile; }, };}
function buildBuiltinProfile(profileId: string, environment: NodeJS.ProcessEnv): ProviderProfile { if (profileId === "tinker-default") { const configured = [ ...configuredTierModels(environment, "THOUGHTSTREAM_TINKER_"), ...configuredAllowedModels(environment.THOUGHTSTREAM_TINKER_ALLOWED_MODELS), ]; return validateProfile({ id: profileId, provider: "tinker", baseUrl: "https://tinker.thinkingmachines.dev/services/tinker-prod/oai/api/v1", route: "/chat/completions", apiKeyEnv: "TINKER_API_KEY", allowedModels: new Set([ "Qwen/Qwen3.5-4B", "Qwen/Qwen3.5-35B-A3B-Base", "Qwen/Qwen3.6-27B", "thinkingmachines/Inkling", "thinkingmachines/Inkling-Small", ...configured, ]), imageInputModels: new Set([ "thinkingmachines/Inkling", "thinkingmachines/Inkling-Small", ...configuredAllowedModels(environment.THOUGHTSTREAM_TINKER_IMAGE_MODELS), ]), // Tinker accepts response_format=json_object but does not enforce JSON // across its current model routes. Strictness remains a parent-side // complete-value validation contract, not a constrained-decoding claim. jsonObjectResponseFormat: false, jsonSchemaResponseFormat: false, requestTimeoutMs: 120_000, maxRequestBytes: 2 * 1024 * 1024, maxResponseBytes: 1_500_000, }); } if (profileId === "openai-compatible-default") { const baseUrl = environment.THOUGHTSTREAM_MODEL_BASE_URL; if (!baseUrl) throw new Error("Trusted provider profile openai-compatible-default requires THOUGHTSTREAM_MODEL_BASE_URL"); const allowedModels = new Set(configuredAllowedModels(environment.THOUGHTSTREAM_MODEL_ALLOWED_MODELS)); if (allowedModels.size === 0) { throw new Error("Trusted provider profile openai-compatible-default requires THOUGHTSTREAM_MODEL_ALLOWED_MODELS"); } return validateProfile({ id: profileId, provider: "openai-compatible", baseUrl, route: "/chat/completions", apiKeyEnv: "THOUGHTSTREAM_MODEL_API_KEY", allowedModels, imageInputModels: new Set(configuredAllowedModels(environment.THOUGHTSTREAM_MODEL_IMAGE_MODELS)), jsonObjectResponseFormat: false, jsonSchemaResponseFormat: false, requestTimeoutMs: 120_000, maxRequestBytes: 2 * 1024 * 1024, maxResponseBytes: 1_500_000, }); } if (profileId === "openai-json-default") { return validateProfile({ id: profileId, provider: "openai-compatible", baseUrl: "https://api.openai.com/v1", route: "/chat/completions", apiKeyEnv: "OPENAI_API_KEY", allowedModels: new Set(["gpt-4.1-mini"]), imageInputModels: new Set(), jsonObjectResponseFormat: false, jsonSchemaResponseFormat: true, requestTimeoutMs: 120_000, maxRequestBytes: 2 * 1024 * 1024, maxResponseBytes: 1_500_000, }); } throw new Error(`Unknown trusted provider profile: ${profileId}`);}
function configuredAllowedModels(value: string | undefined): string[] { return (value ?? "") .split(",") .map((model) => model.trim()) .filter(Boolean);}
function configuredTierModels(environment: NodeJS.ProcessEnv, prefix: string): string[] { return Object.entries(environment) .filter(([key, value]) => key.startsWith(prefix) && key.endsWith("_MODEL") && Boolean(value)) .map(([, value]) => value!) .filter((value, index, values) => values.indexOf(value) === index);}
function validateProfile(profile: ProviderProfile): ProviderProfile { profileIdSchema.parse(profile.id); const url = new URL(profile.baseUrl); if (url.protocol !== "https:" && !(url.protocol === "http:" && ["127.0.0.1", "::1", "localhost"].includes(url.hostname))) { throw new Error(`Provider profile ${profile.id} must use HTTPS or an explicit loopback fixture`); } if (url.username || url.password || url.hash || url.search) throw new Error(`Provider profile ${profile.id} has an unsafe base URL`); if (!/^[A-Z_][A-Z0-9_]*$/.test(profile.apiKeyEnv)) throw new Error(`Provider profile ${profile.id} has an invalid credential reference`); if (profile.allowedModels.size === 0) throw new Error(`Provider profile ${profile.id} has no allowed models`); for (const model of profile.allowedModels) modelSchema.parse(model); for (const model of profile.imageInputModels) { modelSchema.parse(model); if (!profile.allowedModels.has(model)) { throw new Error(`Provider profile ${profile.id} marks a non-allowlisted model as image-capable`); } } return { ...profile, baseUrl: profile.baseUrl.replace(/\/$/, "") };}