/** * omp auth-gateway router and HTTP server. * * Accepts any provider-format request (OpenAI chat-completions, Anthropic * messages, OpenAI Responses) and dispatches through pi-ai's `streamSimple()` * — which handles credential injection, anthropic-beta headers, codex * websocket transport, and all the per-provider intricacies. The gateway is * pure protocol translation: foreign wire → omp Context → pi-ai stream() → * omp events → foreign wire. * * Endpoints: * GET /healthz → unauth; ok + version * GET /v1/usage → aggregated provider usage (5-min per-credential cache via AuthStorage) * GET /v1/credentials/check → per-credential auth probe (diagnose 401s in a multi-account pool) * GET /v1/models → list known models from the registry * POST /v1/chat/completions → OpenAI chat-completions in/out * POST /v1/messages → Anthropic messages in/out * POST /v1/responses → OpenAI Responses in/out * POST /v1/pi/stream → native pi-ai stream in/out * POST /v1/systemone | /alpha/decisions → TypeSafe System One judgments (routes/systemone) * POST /v1/images[/generations|/edits] → image generation, OpenAI/OpenRouter wire (routes/images) * POST /v1/audio/speech → text-to-speech, raw audio out (routes/speech) * POST /v1/audio/transcriptions → speech-to-text, multipart or JSON base64 in (routes/transcriptions) * * Chat routes live in this file; every other modality is a `routes/*` module * built on the shared plumbing in `dispatch.ts`. {@link createAuthGatewayRouter} * answers the `/v1/*` routes for any transport: {@link startAuthGateway} * serves them over HTTP behind bearer auth, `stdio.ts` over JSON lines. */ import { type AuthGatewayBootOptions, type AuthGatewayRouteOptions } from "./dispatch.js"; import type { AuthGatewayServerHandle } from "./types.js"; /** The gateway's `/v1/*` routes, for a transport that has already admitted the caller. */ export interface AuthGatewayRouter { /** Answers one request; `peer` names the caller in logs. Never rejects: a crashed route answers 500. */ route(req: Request, peer: string): Promise; /** * Closes the retained provider session state (Codex WebSockets, GitLab Duo * workflows), whose sockets and timers would otherwise keep the process alive. */ close(): void; } /** * The gateway's routes over `opts`, owning their per-session provider state: * two routers in one process never share (or tear down) each other's. */ export declare function createAuthGatewayRouter(opts: AuthGatewayRouteOptions): AuthGatewayRouter; export declare function startAuthGateway(opts: AuthGatewayBootOptions): AuthGatewayServerHandle;