Built-in providers
These providers ship with o4 and have models in its catalog. The Provider ID is the name you use in model references such asanthropic:claude-opus-5, and the name o4 --list-models prints.
When a provider lists two sources, o4 uses the first one that is set.
Run
o4 --list-models to see each provider’s models. See Choosing a model for how to pick one.
You can add more providers yourself:
- Any server that speaks the OpenAI Chat Completions API, hosted or local: OpenAI-compatible endpoints.
- Local runtimes such as Ollama, LM Studio and llama.cpp: Local models.
Add an API key
You have three ways to give o4 a key. Use whichever fits how you work.In the setup wizard
When o4 starts and finds no key, it opens a setup wizard. Choose a provider under Choose Provider, paste your key under Enter API Key, then pick a model. The wizard offers Anthropic, OpenAI, Google Gemini, DeepSeek, Moonshot (Kimi), Meta (Muse), xAI (Grok), z.ai (GLM), z.ai Coding Plan (GLM) and Ollama (local). A provider whose environment variable is already set showsenv set, and the wizard skips the key step for it.
The wizard saves the key, the provider as your default provider, and the model as your default model. Run /onboard to open it again later.
The wizard doesn’t cover subscriptions or Bedrock. For those, see Claude and ChatGPT subscriptions and Amazon Bedrock.
In settings
- Run
/config providersto open the Providers tab of the settings. - Select the Provider row and press
Enteruntil it shows the provider you want. The row cycles throughanthropic,openai,ollama,google,xai,deepseek,kimi-coding,meta,zaiandzai-coding-plan, then any providers you added in~/.o4/providers.tomland any other provider that has a key insettings.json. It starts atanthropicwhen you haven’t picked one.amazon-bedrock,claude-codeandopenai-codexaren’t in the list. They get their credentials elsewhere (see Amazon Bedrock and subscriptions). - Select API key, press
Enter, paste the key, and pressEnteragain.
default_provider in ~/.o4/settings.json. Its description reads API key's provider; Model tab sets model: the row picks whose key the API key row below edits. config.toml has no default_provider key. o4 uses the default provider only when it picks a model with no default model saved (see Choosing a model). Changing the row doesn’t switch the current session’s model. To change the default model, use the Model row of /config model.
The API key row shows the stored key for the provider in the Provider row, with the middle masked, or (not set).
In environment variables
Export the variable from the table above in your shell profile, or set it for one run:Where keys are stored
Keys you enter in o4 go into~/.o4/settings.json, in the api_keys map keyed by provider ID:
~/.o4/settings.json
0600 permissions, so only your user can read it. The keys are stored in plain text, so don’t commit the file or copy it into shared places.
A key in settings.json takes precedence over the environment variable for the same provider. If you want an environment variable to win, clear the stored key.
A project can also set api_keys in its own .o4/settings.json. o4 reads that file only in a trusted workspace, and its keys override yours for the same provider.
o4 removes provider keys from the environment of commands it runs for the model, such as the shell tool, formatters and language servers. The model can’t read your keys by running
env. Variables that other tools also use, such as AWS_*, GITHUB_TOKEN and GOOGLE_APPLICATION_CREDENTIALS, are left in place so tools like aws, gh and gcloud keep working. See Sandbox.Check or remove a key
In/config > Providers, the API key row shows whether the provider in the Provider row has a stored key. Pressing Enter on the row opens an empty input, so to remove the stored key, press Enter twice. Esc cancels without a change.
Keys that come from environment variables aren’t stored by o4. Unset the variable to remove them.
A wrong or expired key shows up as an authentication error (usually HTTP 401) on the first request to that provider. Store the right key or fix the variable, then send the message again.
Amazon Bedrock
Theamazon-bedrock provider signs requests with AWS credentials. o4 looks for them in this order:
- A Bedrock API key in
AWS_BEARER_TOKEN_BEDROCK, orBEDROCK_API_KEY. AWS_ACCESS_KEY_IDandAWS_SECRET_ACCESS_KEY, withAWS_SESSION_TOKENfor temporary credentials.- The profile named in
AWS_PROFILE, or thedefaultprofile in~/.aws/credentials.
AWS_REGION, then AWS_DEFAULT_REGION, then the profile’s region in ~/.aws/config, and falls back to us-east-1.
us.anthropic.claude-sonnet-4-6, add it as a model entry in ~/.o4/models.toml first (see Add or change model entries). Copy the fields of the matching built-in model and keep api = "bedrock-converse-stream" and provider = "amazon-bedrock". o4 builds the Bedrock URL from the region, not from base_url. Without the entry, -m amazon-bedrock:us.anthropic.claude-sonnet-4-6 stops with Model ... not found.
Related
- Claude and ChatGPT subscriptions: use a Claude Code or ChatGPT plan instead of an API key.
- Choosing a model: pick a model and set the default.
- Environment variables: every variable o4 reads.
- Troubleshooting: what to do when a provider rejects a request.