Adds siliconflow and siliconflow-cn OpenAI-compatible providers
(api.siliconflow.com / api.siliconflow.cn), with the model list fetched
live from each region's /v1/models endpoint instead of a bundled
catalog (dynamicModelsAuthoritative, no models.dev mapping).
SiliconFlow's /v1/models serves every model type (chat, embedding,
reranker, image, audio, video) with no per-model type field, so
discovery filters non-chat ids out of the picker. The filter was
validated against the live catalog to match the server's own
type=text&sub_type=chat classification exactly (64/64, no false
drops, no false keeps).
Wires SILICONFLOW_API_KEY / SILICONFLOW_CN_API_KEY into env-key
discovery and registers API-key login providers so
`omp login siliconflow` / `omp login siliconflow-cn` stores a
credential validated against each region's /v1/models endpoint.
One ChatGPT email can hold several workspaces (a personal Plus/Pro plan
plus Team/Enterprise seats), each with its own workspace-scoped OAuth
token and independent limit pools. Codex credentials were deduped by
bare email, so logging into the second workspace silently replaced the
first, and usage reports from the two pools merged into one row.
- capture the workspace (chatgpt_account_id) as orgId at login, with
the plan type as its display label; token refreshes never rewrite it
- key openai-codex credential identity as email + org via the existing
org-scoped machinery; legacy email-keyed rows are claimed in place by
the first workspace-scoped login, and workspace-less credentials
never clobber workspace-scoped rows
- exclude the org-mirroring account base from same-org row claims so
two members of one workspace (shared chatgpt_account_id) keep
separate rows
- partition usage-report dedupe by workspace and require every shared
identity dimension to agree when reconciling codex usage blocks
Fixes the openai-codex half of #2966 (anthropic half shipped in #5170);
also covers the #633 scenario.
One Anthropic account email can hold multiple organizations (a Team seat
plus a personal Max plan), each with its own org-scoped OAuth token and
independent 5h/7d limit pools. Credentials were deduped by bare email, so
logging in with the second subscription silently replaced the first, and
usage reports from the two pools merged into one row with mixed numbers.
- capture organization uuid/name at login (token exchange response, with
a claude_cli/bootstrap fallback); token refreshes never rewrite it
- key anthropic credential identity as email + org; a legacy email-keyed
row is claimed in place by the first org-scoped login with the same
email, and org-less credentials never clobber org-scoped rows
- partition usage-report dedupe and the per-credential usage cache by
org so the two subscriptions' limit pools stay distinct for rotation
- show the organization in omp usage (redaction-safe) and name the
stored account/org in the login success message
This change introduces a new `openrouter` API type and extensively refactors OpenAI-family streaming providers, centralizing shared logic and improving robustness.
Key changes include:
- **Unified OpenAI-family Logic:** Consolidated core utilities, compat resolution, request shaping, and stream processing into `openai-shared.ts`, reducing duplication across `openai-completions`, `openai-responses`, and `openai-codex-responses`.
- **OpenRouter API Type:** Introduced a dedicated `openrouter` API type with dual-surface compatibility, allowing it to dispatch requests as either OpenAI Chat Completions or Responses.
- **Enhanced Provider Integration:**
- Improved Perplexity search to leverage shared OpenAI streaming transports, including API-key fallback to OpenRouter and support for Perplexity's Responses API.
- Integrated xAI-specific logic directly into the shared `stream.ts` dispatch, removing the dedicated `xai-responses` provider.
- Refined credential parsing for Google Gemini CLI and handling of Azure deployment names.
- **Robustness & Consistency:** Improved error handling for Codex, standardized output token parameter resolution, and ensured consistent application of reasoning suppression across all Chat Completions dialects.
- **New Documentation:** Added `provider-endpoint-constraints.md` to detail endpoint-specific behaviors and quirks for various providers.
- **Telemetry & Debugging:** Extended telemetry propagation to advisor calls and overflow compaction tasks. Improved debugging for Codex WebSocket failures and stream error messages.
- **Tooling & Security:** Updated browser stealth scripts to prevent detection and added a new `ts-no-inline-cast-access` TTSR rule.
- docs/models.md: retitled the '/model and --list-models' section and
updated the bullet to describe 'omp models' plus 'omp models canonical'.
- docs/providers.md: updated the troubleshooting note to validate
models.yml with 'omp models' (and 'omp models find <substr>').
- packages/coding-agent/CHANGELOG.md: noted the doc fix under Unreleased.
Fixes#2458