@projectpac/source-llm
v0.6.0
Published
Part of PAC: @projectpac/source-llm.
Downloads
197
Readme
@projectpac/source-llm
The principal's model access: the right to spend their money at a provider, offered to a peer the way anything else they hold is.
{
"models": [
{
"name": "openrouter",
"host": "openrouter.ai",
"model": "anthropic/claude-sonnet-4.5",
"key": "openrouter-key"
}
]
}key names a file in this plugin's own folder (keys/openrouter-key). url
is optional -- a known host has one, anything else declares its own. note is
optional and composed from the host when absent.
Why it is its own plugin
This used to be three fields of a skill document -- provider, model, and a
key file its front matter named. Two consequences, both wrong for the same
reason:
- a credential was not something a peer could be offered, and
- only the skill's owner could ever pay for running it.
Who supplies the model is a term of the computation. A term belongs in the negotiation, not inside one party's private arrangement. So a design names a model access beside whatever else the program reads, and it may come from either principal.
What a peer sees, and what it does not
{
"name": "openrouter",
"note": "a model this principal pays for, at openrouter.ai",
"discloses": ["openrouter.ai"]
}The host, because that is the disclosure a peer consents to, and it is the same word the box session's declared egress speaks: one name carries from this config through the descriptor to the cage the program runs in. Not the model, which is what this principal chose to pay for; not the url; never the key.
No shape, because a credential is not read as data. A program spends it.
The two verbs
inventory() answers the rows whose key file is actually there. stake()
copies the key into the caller's folder and answers what a program needs to
make the call:
{ url, model, apiKey: { $line: "models/openrouter.key" } }The url and the model are literals -- neither is material. The key crosses as a file and comes back as a marker only a box resolves, so no flow on either side ever holds its value.
That the url is staked rather than written into the program is deliberate. What a reviewer approves is the host, bound into the box's approval message alongside the program hash; the path a provider uses is nobody's business. It also means two nodes no longer have to agree on an endpoint table before they can agree on bytes -- the program is the same program whoever is paying.
