Skip to main content
A provider is the service that runs the model: Anthropic, OpenAI, Google, a local Ollama server, and so on. o4 needs credentials for a provider before it can use that provider’s models. This page lists the built-in providers, the environment variable each one reads, and the ways to give o4 a key.

Built-in providers

These providers ship with o4 and have models in its catalog. The Provider ID is the name you use in model references such as anthropic:claude-opus-5, and the name o4 --list-models prints. When a provider lists two sources, o4 uses the first one that is set. Run o4 --list-models to see each provider’s models. See Choosing a model for how to pick one. You can add more providers yourself:

Add an API key

You have three ways to give o4 a key. Use whichever fits how you work.

In the setup wizard

When o4 starts and finds no key, it opens a setup wizard. Choose a provider under Choose Provider, paste your key under Enter API Key, then pick a model. The wizard offers Anthropic, OpenAI, Google Gemini, DeepSeek, Moonshot (Kimi), Meta (Muse), xAI (Grok), z.ai (GLM), z.ai Coding Plan (GLM) and Ollama (local). A provider whose environment variable is already set shows env set, and the wizard skips the key step for it. The wizard saves the key, the provider as your default provider, and the model as your default model. Run /onboard to open it again later. The wizard doesn’t cover subscriptions or Bedrock. For those, see Claude and ChatGPT subscriptions and Amazon Bedrock.

In settings

  1. Run /config providers to open the Providers tab of the settings.
  2. Select the Provider row and press Enter until it shows the provider you want. The row cycles through anthropic, openai, ollama, google, xai, deepseek, kimi-coding, meta, zai and zai-coding-plan, then any providers you added in ~/.o4/providers.toml and any other provider that has a key in settings.json. It starts at anthropic when you haven’t picked one. amazon-bedrock, claude-code and openai-codex aren’t in the list. They get their credentials elsewhere (see Amazon Bedrock and subscriptions).
  3. Select API key, press Enter, paste the key, and press Enter again.
The key applies right away: that provider’s models appear in Select Model without a restart. The Provider row is also your default provider, saved as default_provider in ~/.o4/settings.json. Its description reads API key's provider; Model tab sets model: the row picks whose key the API key row below edits. config.toml has no default_provider key. o4 uses the default provider only when it picks a model with no default model saved (see Choosing a model). Changing the row doesn’t switch the current session’s model. To change the default model, use the Model row of /config model. The API key row shows the stored key for the provider in the Provider row, with the middle masked, or (not set).

In environment variables

Export the variable from the table above in your shell profile, or set it for one run:
Environment variables suit CI jobs and print mode, where there is no interface to type a key into.

Where keys are stored

Keys you enter in o4 go into ~/.o4/settings.json, in the api_keys map keyed by provider ID:
~/.o4/settings.json
o4 writes this file with 0600 permissions, so only your user can read it. The keys are stored in plain text, so don’t commit the file or copy it into shared places. A key in settings.json takes precedence over the environment variable for the same provider. If you want an environment variable to win, clear the stored key. A project can also set api_keys in its own .o4/settings.json. o4 reads that file only in a trusted workspace, and its keys override yours for the same provider.
o4 removes provider keys from the environment of commands it runs for the model, such as the shell tool, formatters and language servers. The model can’t read your keys by running env. Variables that other tools also use, such as AWS_*, GITHUB_TOKEN and GOOGLE_APPLICATION_CREDENTIALS, are left in place so tools like aws, gh and gcloud keep working. See Sandbox.

Check or remove a key

In /config > Providers, the API key row shows whether the provider in the Provider row has a stored key. Pressing Enter on the row opens an empty input, so to remove the stored key, press Enter twice. Esc cancels without a change. Keys that come from environment variables aren’t stored by o4. Unset the variable to remove them. A wrong or expired key shows up as an authentication error (usually HTTP 401) on the first request to that provider. Store the right key or fix the variable, then send the message again.

Amazon Bedrock

The amazon-bedrock provider signs requests with AWS credentials. o4 looks for them in this order:
  1. A Bedrock API key in AWS_BEARER_TOKEN_BEDROCK, or BEDROCK_API_KEY.
  2. AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY, with AWS_SESSION_TOKEN for temporary credentials.
  3. The profile named in AWS_PROFILE, or the default profile in ~/.aws/credentials.
The region comes from AWS_REGION, then AWS_DEFAULT_REGION, then the profile’s region in ~/.aws/config, and falls back to us-east-1.
o4 sends the model ID exactly as it is in the catalog, to the Bedrock Runtime endpoint of your region. Your AWS account must have access to the model in that region. The built-in catalog lists base model IDs only. To use a cross-region inference profile such as us.anthropic.claude-sonnet-4-6, add it as a model entry in ~/.o4/models.toml first (see Add or change model entries). Copy the fields of the matching built-in model and keep api = "bedrock-converse-stream" and provider = "amazon-bedrock". o4 builds the Bedrock URL from the region, not from base_url. Without the entry, -m amazon-bedrock:us.anthropic.claude-sonnet-4-6 stops with Model ... not found.