Provider Authentication

Provider Authentication

#

Most hosted providers support one or both of these authentication methods:

  • Sign in through a browser or device flow backed by OAuth.
  • Provide an API key.

Use /login [provider] to see the methods supported by a provider. Amazon Bedrock and Google Vertex AI can also use ambient cloud credentials.

Authenticate interactively

#

Run /login and select a provider. pig guides you through its OAuth or API-key flow and saves the resulting credential in auth.json: pi's ~/.pi/agent/auth.json when pi already has one, so the two tools share rotating tokens, and ~/.pig/agent/auth.json otherwise.

On a remote or headless machine, an OAuth callback may not reach the local process. When prompted, paste the final redirect URL or authorization code back into pig.

Run /logout and select a provider to remove its stored credential. This does not unset environment variables, remove authentication from models.json, or revoke the credential at the provider.

auth.json can contain API keys and OAuth tokens. Keep it private and do not commit it.

Sign in with a subscription

#

Three providers take a subscription or account sign-in instead of an API key, each the way pi 1.0.3 does it:

ProviderHowNotes
Anthropic (Claude Pro/Max)/login asks which way in first. Browser (default): pig listens on http://localhost:53692/callback, opens claude.ai, and the code comes back by itself; a paste box stays open beside it — if the browser is on another machine, paste the final redirect URL there. Copy code (headless): the browser lands on Anthropic's own page showing code#state; paste that.The token goes out as Claude Code's (claude-cli user agent, both betas, tool names spelled Read/Bash/Edit/Write) because that is the identity Anthropic issued it to. Port 53692 is registered with Anthropic and cannot be changed.
GitHub CopilotDevice flow: pig shows a code, you type it at github.com/login/device, pig polls until it is accepted. Blank at the Enterprise prompt means github.com.Claude's and Grok's models are switched on for the account after signing in.
AntigravityBrowser callback on localhost:51121/oauth-callback.Needs ANTIGRAVITY_CLIENT_ID / ANTIGRAVITY_CLIENT_SECRET in the environment or antigravity.clientId / antigravity.clientSecret in settings.json; pig does not ship them.

Tokens are renewed automatically when they expire. On a machine with no terminal UI use pig-ai login <provider>; on a pipe the browser callback cannot be raced against a paste, so pick "copy code" for Anthropic.

Radius has no sign-in in pig: set RADIUS_API_KEY or store the key through /login. Its models come from the bundled catalog, generated from the public gateway https://radius.pi.dev; pig does not fetch or cache a gateway catalog at runtime. A different gateway can be configured as a provider in models.json with its own models.

Use an API key from the environment

#

Environment variables are useful in CI and anywhere pig should not store the key. Set the variable before starting pig:

export ANTHROPIC_API_KEY=sk-ant-...
pig

This table covers providers with a single primary API-key variable. Providers that need additional configuration or support ambient credentials are covered under Cloud providers.

ProviderEnvironment variable
AnthropicANTHROPIC_API_KEY
Ant LingANT_LING_API_KEY
OpenAIOPENAI_API_KEY
DeepSeekDEEPSEEK_API_KEY
NVIDIA NIMNVIDIA_API_KEY
Google GeminiGEMINI_API_KEY
GitHub CopilotCOPILOT_GITHUB_TOKEN, then GH_TOKEN, then GITHUB_TOKEN
MistralMISTRAL_API_KEY
GroqGROQ_API_KEY
CerebrasCEREBRAS_API_KEY
xAIXAI_API_KEY
OpenRouterOPENROUTER_API_KEY
Vercel AI GatewayAI_GATEWAY_API_KEY
ZAI Coding Plan (Global)ZAI_API_KEY
ZAI Coding Plan (China)ZAI_CODING_CN_API_KEY
OpenCode Zen and GoOPENCODE_API_KEY
RadiusRADIUS_API_KEY
TypeSafe (classifier models)TYPESAFE_API_KEY
Hugging FaceHF_TOKEN
FireworksFIREWORKS_API_KEY
Together AITOGETHER_API_KEY
BasetenBASETEN_API_KEY
Kimi For CodingKIMI_API_KEY
MetaMETA_API_KEY
MiniMaxMINIMAX_API_KEY
MiniMax (China)MINIMAX_CN_API_KEY
Moonshot AI (Global and China)MOONSHOT_API_KEY
Qwen Token Plan and IndividualQWEN_TOKEN_PLAN_API_KEY
Qwen Token Plan (China)QWEN_TOKEN_PLAN_CN_API_KEY
Xiaomi MiMoXIAOMI_API_KEY
Xiaomi MiMo Token Plan (China)XIAOMI_TOKEN_PLAN_CN_API_KEY
Xiaomi MiMo Token Plan (Amsterdam)XIAOMI_TOKEN_PLAN_AMS_API_KEY
Xiaomi MiMo Token Plan (Singapore)XIAOMI_TOKEN_PLAN_SGP_API_KEY

Anthropic also recognizes ANTHROPIC_AUTH_TOKEN, sent as Authorization: Bearer <token> and checked first, and ANTHROPIC_OAUTH_TOKEN, which is checked before ANTHROPIC_API_KEY.

Load an API key from a command

#

To use a secret manager without writing the resolved key to disk, set a provider's key in auth.json to a command prefixed with !:

{
  "anthropic": {
    "type": "api_key",
    "key": "!security find-generic-password -ws 'anthropic'"
  }
}

$NAME and ${NAME} are read from the entry's env and then the process environment; a bare name such as MY_KEY is a literal key. pig runs the command when the key is first needed and caches its standard output for the process lifetime. Empty output, a timeout, or a nonzero exit leaves the key unresolved until pig restarts.

Cloud Providers

#

The providers below need additional settings or can use credentials supplied by their cloud platform.

A stored API-key credential can include an env object. Its values take priority over the process environment for that provider:

{
  "cloudflare-workers-ai": {
    "type": "api_key",
    "key": "...",
    "env": {
      "CLOUDFLARE_ACCOUNT_ID": "account-id"
    }
  }
}

Azure OpenAI

#

Set an API key plus either a base URL or resource name:

export AZURE_OPENAI_API_KEY=...
export AZURE_OPENAI_BASE_URL=https://your-resource.ai.azure.com
# Or:
export AZURE_OPENAI_RESOURCE_NAME=your-resource

Resource root URLs under ai.azure.com, cognitiveservices.azure.com, and openai.azure.com are normalized to the OpenAI API path.

Amazon Bedrock

#

Bedrock can use a bearer token or an ambient AWS credential source:

# Named profile
export AWS_PROFILE=your-profile

# IAM keys
export AWS_ACCESS_KEY_ID=AKIA...
export AWS_SECRET_ACCESS_KEY=...
# Required for temporary credentials
export AWS_SESSION_TOKEN=...

# Bedrock bearer token
export AWS_BEARER_TOKEN_BEDROCK=...

# Region, when not supplied by the profile or AWS SDK configuration
export AWS_REGION=us-west-2
# AWS_DEFAULT_REGION is also supported

pig also supports ECS task credentials and IRSA through the standard AWS_CONTAINER_CREDENTIALS_* and AWS_WEB_IDENTITY_TOKEN_FILE variables.

Cloudflare AI Gateway

#

The gateway requires a token, account ID, and gateway ID:

export CLOUDFLARE_API_KEY=...
export CLOUDFLARE_ACCOUNT_ID=...
export CLOUDFLARE_GATEWAY_ID=...

The account and gateway IDs can come from the process environment or the credential's env object in auth.json.

CLOUDFLARE_API_KEY authenticates pig to the gateway. Upstream access can use Cloudflare unified billing, credentials stored in the gateway, or an Authorization header configured for the provider in models.json.

Cloudflare Workers AI

#

Workers AI requires a token and account ID:

export CLOUDFLARE_API_KEY=...
export CLOUDFLARE_ACCOUNT_ID=...

The account ID can also be stored in the credential's env object.

Google Vertex AI

#

Use a Google Cloud API key:

export GOOGLE_CLOUD_API_KEY=...

To use Application Default Credentials, configure a project and location:

export GOOGLE_CLOUD_PROJECT=your-project
# GCLOUD_PROJECT is also supported
export GOOGLE_CLOUD_LOCATION=us-central1

Then authenticate:

gcloud auth application-default login

To use a service-account key file instead, set GOOGLE_APPLICATION_CREDENTIALS along with the project and location.