Model developers
Cloud platforms
Inference providers
Routers and gateways
Self-hosted
Custom endpoints
The type in the second column is the provider’s id. It is what policies see in
input.provider and what traces record, whatever API the runtime uses to reach the provider.
Credentials
Provider credentials are encrypted when saved, are never returned by the API or shown again in the console, and reach the runtime only when it calls the provider.- API key. Most providers. Sent the way the provider expects (
Authorization: Bearer,x-api-keyorapi-key). - Amazon Bedrock.
- Access keys: an IAM user’s access key ID and secret access key.
- IAM role: Xenovia assumes a role in your account. You give the role ARN, plus the keys of an IAM user that may only call
sts:AssumeRoleon that role. The role’s trust policy must require the external ID shown in the console. That ID is your organization’s ID, set by Xenovia and never by the person adding the provider, so no other organization can use your role. - Bedrock API key: a long-term or short-term Bedrock API key.
- Azure OpenAI and Microsoft Foundry. An API key, or a Microsoft Entra ID service principal (tenant ID, client ID and client secret) with access to the resource.
- Google Vertex AI. A service account key (the JSON file) for a service account with the Vertex AI User role, plus the project ID and region.
- Databricks. A personal access token, or an OAuth service principal (client ID and secret).
Microsoft Foundry and Claude
Microsoft Foundry deployments, including Claude, use the Microsoft Foundry type with your resource’s endpoint (https://<resource>.services.ai.azure.com). Claude deployments are called through Foundry’s Anthropic Messages API, every other model through its OpenAI-compatible API. The runtime tells them apart from the model name. If a deployment’s name does not show the model (a Claude deployment called prod-chat, for example), set Model family to Claude.
Claude is also available from Anthropic directly, from Amazon Bedrock and from Google Vertex AI. Use input.model_family in a policy to treat Claude the same way whichever of these an agent uses.
Self-hosted and custom endpoints
vLLM, Ollama, SGLang and LM Studio servers, and any other server or gateway that speaks the OpenAI Chat Completions API (Custom OpenAI-compatible endpoint) or the Anthropic Messages API (Custom Anthropic-compatible endpoint), take a base URL and an optional key.- An OpenAI-compatible endpoint receives
{base URL}/chat/completions. If it also serves the Responses API, say so under Advanced; otherwise Responses requests are sent to it as chat completions. - An Anthropic-compatible endpoint receives
{base URL}/v1/messageswith anx-api-keyheader. - OpenAI, Anthropic, Gemini, Groq, xAI, OpenRouter, NVIDIA NIM and Scaleway also accept a custom base URL, for example a company gateway in front of the provider. The provider keeps its type.
- Private network addresses work only on installations that allow private provider endpoints. Hosted agents can reach public endpoints only.
Models
The model is set on the provider (and can be overridden per agent). The model in your application’s request is replaced with it. The console lists the provider’s models where the provider publishes a model list, and suggests common models otherwise; you can always type a model ID.Policy fields
Besidesinput.provider and input.model, request and response policies receive:
The Approved provider allowlist template matches on
input.provider.