Integration request from aimlapi.com - #424
Closed
hugoaimlapi wants to merge 2 commits into
Closed
hugoaimlapi wants to merge 2 commits into
hugoaimlapi wants to merge 2 commits into
Conversation
PentAGI already advertises an aggregator tier next to its per-vendor providers, but reaching aimlapi.com meant configuring the generic `custom` provider by hand: one endpoint, one key, no model catalog, no per-agent defaults and no entry in the settings UI. Since the gateway is OpenAI-compatible it fits the existing openaicompat base exactly, so making it first-class costs a registry entry and a config rather than a new client. The default roster spreads the 13 agent roles over four model families and deliberately skips the OpenAI/Anthropic/Google models the gateway also carries: this product runs offensive-security workloads and those vendors' guardrails false-positive on legitimate exploit-development content. That is the same reasoning already recorded in examples/configs/openrouter.provider.yml, and the role/model mapping mirrors it so a reviewer can compare them directly. The enricher is the one place the mapping diverges. Through this gateway minimax/minimax-m3 ignores both reasoning_effort:"none" and extra_body.thinking.type:"disabled" and still thinks, returning the chain inline in `content` wrapped in <think> tags instead of in reasoning_content; the enricher is the role that explicitly wants thinking off, so it stays on deepseek-v4-flash, which honours it. Requests to api.aimlapi.com carry HTTP-Referer, X-Title, X-AIMLAPI-Source and X-AIMLAPI-Partner-ID identifying PentAGI as the calling application. They are attached by a RoundTripper that wraps a copy of the shared HTTP client, so the process-wide client is never mutated, a caller's own header always wins, and the host is re-checked per request — pointing AIMLAPI_SERVER_URL at a LiteLLM proxy or a self-hosted gateway disables attribution rather than tagging another operator's traffic through a redirect. Two regression tests exist because the failures they catch are invisible otherwise: a malformed partner id is accepted by the gateway and silently earns nothing, and the gateway rejects `null` for temperature, top_p, seed, tools and most other optional fields with a 400 while accepting them absent — so a client that serialises cleared tools as null passes turn one of an agent loop and fails every turn two.
Signed-off-by: Hugo <hugo@aimlapi.com>
Collaborator
|
Thanks for the work. We are not taking this: the provider duplicates what the custom OpenAI-compatible endpoint already covers, and we cannot carry vendor attribution headers in the product. Closing this PR. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Hi! I'm Hugo from aimlapi.com — an AI aggregator that gives access to 1000+ models in one API, trusted by 400k+ users.
We'd love to be available as a verified provider option inside PentAGI — so we went ahead and did all the technical work on our side, in our fork: https://github.com/aimlapi/pentagi-aimlapi
To build our partnership, we offer a 50/50 revenue share on all traffic from this integration.
My contacts: hugo@aimlapi.com (email / Slack), Telegram: @hug0the
Description of the Change
Problem
aimlapi.com is an OpenAI-compatible gateway in front of many vendors' chat models. Today the only way to use it is the generic
customprovider (LLM_SERVER_URL/LLM_SERVER_KEYplus a hand-writtenLLM_SERVER_CONFIG_PATHfor per-role models): no built-in role defaults, no model catalog in Settings, no installer screen, and it takes the single custom slot. Details in #417.Solution
A first-class
aimlapiprovider on the existingopenaicompatbase. No new client code, no new dependencies.backend/pkg/providers/aimlapi/:aimlapi.go(fallback modeldeepseek/deepseek-v4-flash), embeddedconfig.ymlwith defaults for all 13 agent roles, andmodels.ymlwith a 6-model catalog and prices.effort: max(generator, refiner), MiniMax M3 (adviser), Kimi K2.7 Code (coder, installer).examples/configs/openrouter.provider.yml.config.go,.env.exampleanddocker-compose.yml:AIMLAPI_API_KEY,AIMLAPI_SERVER_URL(defaulthttps://api.aimlapi.com/v1),AIMLAPI_PROVIDER(LiteLLM prefix). The key is added toGetSecretPatterns().ProviderAIMLAPIinprovider.go(includingAllProviderTypes), an entry inregistry.go,ProviderTypeAimlapiindatabase/models.go.20260903_120000_add_aimlapi_provider.sqladdsaimlapitoPROVIDER_TYPE, same pattern as the MiniMax one. Down deletesaimlapirows before restoring the enum.aimlapiinProviderType,ProvidersModelsList,ProvidersReadinessStatusandDefaultProvidersConfig, wired inSettingsProviders. Frontend types regenerated; new icon, label and e2e cassette entries.llm_provider_form§aimlapiscreen (base URL, key, provider name) with help text; the key is masked.ctester -type aimlapiandftester -provider aimlapi.Attribution:
attribution.gowraps a copy of the shared HTTP client (the global one isn't modified) and adds these headers to requests going to aimlapi.com:They tell aimlapi.com the traffic comes from PentAGI; the partner ID is what the revenue share is counted on. No user data in them.
AIMLAPI_SERVER_URLhost isaimlapi.comor a subdomain, re-checked on every request, so they don't follow a redirect to another host.AIMLAPI_SERVER_URLat a proxy or self-hosted gateway turns them off. Otherwise removing them means dropping thewithAttribution(...)wrapper inaimlapi.New.Closes #417
Type of Change
Areas Affected
Testing and Verification
Test Configuration
Test Steps
cd backend && go test ./pkg/providers/aimlapi/ ./pkg/providers/ ./pkg/config/ ./pkg/server/models/AIMLAPI_API_KEYset:go run cmd/ctester/*.go -type aimlapi -report ../examples/tests/aimlapi-report.mdTest Results
New unit tests in
backend/pkg/providers/aimlapi/aimlapi_test.go: role models present inmodels.yml, partner-id format, headers only for the aimlapi.com host and never over caller headers, shared client not mutated, unsettop_p/seedand clearedtoolsomitted from the JSON body instead of sent asnull(the gateway answers 400 tonull). The aimlapi rows were added to the existing tables inproviders_test.go,config_test.goandserver/models/providers_test.go.ctester against the live API (2026-09-03) is committed as
examples/tests/aimlapi-report.md: 292/299 (97.66%). The 7 failures:generate_reportnot called in "Penetration Testing Memory with Tool Call": simple, searcher, enricher (deepseek-v4-flash).All role models are in the live catalog.
Security Considerations
AIMLAPI_API_KEYis masked in the installer and added toGetSecretPatterns().Performance Impact
None for existing providers. The aimlapi transport adds four headers to requests going to aimlapi.com.
Documentation Updates
backend/docs/config.md,backend/docs/database.md, installer help textDeployment Notes
AIMLAPI_API_KEY,AIMLAPI_SERVER_URL,AIMLAPI_PROVIDER. Nothing changes unlessAIMLAPI_API_KEYis set.aimlapitoPROVIDER_TYPE. Rolling back deletesaimlapiproviders, flows and assistants.Checklist
Code Quality
go fmtandgo vet(for Go code)pnpm run lint(for TypeScript/JavaScript code)Security
Compatibility
Documentation
Additional Notes
Other aggregators here ship as
examples/configs/*.provider.ymlfor thecustomprovider. This one is first-class so it gets its own Settings/installer entry and per-role defaults, and can run next to a separate custom endpoint. If you'd rather have just an example config, I can cut it down to that.