> ## Documentation Index
> Fetch the complete documentation index at: https://docs.open4rena.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Providers and API keys

> The model providers o4 supports, and how to add API keys.

A provider is the service that runs the model: Anthropic, OpenAI, Google, a local Ollama server, and so on. o4 needs credentials for a provider before it can use that provider's models. This page lists the built-in providers, the environment variable each one reads, and the ways to give o4 a key.

## Built-in providers

These providers ship with o4 and have models in its catalog. The **Provider ID** is the name you use in model references such as `anthropic:claude-opus-5`, and the name `o4 --list-models` prints.

| Provider | Provider ID | Environment variables | Notes |
| - | - | - | - |
| Anthropic | `anthropic` | `ANTHROPIC_API_KEY` | Anthropic API key. |
| Claude Code subscription | `claude-code` | `CLAUDE_CODE_OAUTH_TOKEN` | Same models as `anthropic`, billed to your Claude plan. See [subscriptions](/models/subscriptions). |
| OpenAI | `openai` | `OPENAI_API_KEY` | OpenAI API key. |
| ChatGPT/Codex subscription | `openai-codex` | `OPENAI_CODEX_ACCESS_TOKEN`, or `~/.codex/auth.json` | Billed to your ChatGPT plan. See [subscriptions](/models/subscriptions). |
| Google Gemini | `google` | `GOOGLE_API_KEY`, then `GEMINI_API_KEY` | Gemini Developer API key. |
| DeepSeek | `deepseek` | `DEEPSEEK_API_KEY` | |
| Kimi Code | `kimi-coding` | `KIMI_API_KEY` | Kimi Code membership models on the Kimi Code endpoint (`https://api.kimi.com/coding/v1`). The setup wizard calls it Moonshot (Kimi). |
| Meta | `meta` | `META_API_KEY`, then `MODEL_API_KEY` | Meta Model API (Muse Spark models). |
| Z.AI | `zai` | `ZAI_API_KEY` | Pay-as-you-go GLM API. |
| Z.AI GLM Coding Plan | `zai-coding-plan` | `ZAI_CODING_API_KEY` | Separate subscription with its own key. The two Z.AI keys aren't interchangeable. |
| xAI | `xai` | `XAI_API_KEY` | |
| Ollama | `ollama` | `OLLAMA_API_KEY` | Built-in models run on Ollama Cloud and need the key. A local Ollama server needs no key. See [Local models](/models/local-models). |
| Amazon Bedrock | `amazon-bedrock` | See [Amazon Bedrock](#amazon-bedrock) | Uses AWS credentials. |

When a provider lists two sources, o4 uses the first one that is set.

Run `o4 --list-models` to see each provider's models. See [Choosing a model](/models/overview) for how to pick one.

You can add more providers yourself:

* Any server that speaks the OpenAI Chat Completions API, hosted or local: [OpenAI-compatible endpoints](/models/openai-compatible).
* Local runtimes such as Ollama, LM Studio and llama.cpp: [Local models](/models/local-models).

## Add an API key

You have three ways to give o4 a key. Use whichever fits how you work.

### In the setup wizard

When o4 starts and finds no key, it opens a setup wizard. Choose a provider under **Choose Provider**, paste your key under **Enter API Key**, then pick a model. The wizard offers Anthropic, OpenAI, Google Gemini, DeepSeek, Moonshot (Kimi), Meta (Muse), xAI (Grok), z.ai (GLM), z.ai Coding Plan (GLM) and Ollama (local). A provider whose environment variable is already set shows `env set`, and the wizard skips the key step for it.

The wizard saves the key, the provider as your default provider, and the model as your default model. Run `/onboard` to open it again later.

The wizard doesn't cover subscriptions or Bedrock. For those, see [Claude and ChatGPT subscriptions](/models/subscriptions) and [Amazon Bedrock](#amazon-bedrock).

### In settings

1. Run `/config providers` to open the **Providers** tab of the settings.
2. Select the **Provider** row and press `Enter` until it shows the provider you want. The row cycles through `anthropic`, `openai`, `ollama`, `google`, `xai`, `deepseek`, `kimi-coding`, `meta`, `zai` and `zai-coding-plan`, then any providers you added in `~/.o4/providers.toml` and any other provider that has a key in `settings.json`. It starts at `anthropic` when you haven't picked one. `amazon-bedrock`, `claude-code` and `openai-codex` aren't in the list. They get their credentials elsewhere (see [Amazon Bedrock](#amazon-bedrock) and [subscriptions](/models/subscriptions)).
3. Select **API key**, press `Enter`, paste the key, and press `Enter` again.

The key applies right away: that provider's models appear in **Select Model** without a restart.

The **Provider** row is also your default provider, saved as `default_provider` in `~/.o4/settings.json`. Its description reads `API key's provider; Model tab sets model`: the row picks whose key the **API key** row below edits. `config.toml` has no `default_provider` key. o4 uses the default provider only when it picks a model with no default model saved (see [Choosing a model](/models/overview#when-no-default-is-saved)). Changing the row doesn't switch the current session's model. To change the default model, use the **Model** row of `/config model`.

The **API key** row shows the stored key for the provider in the **Provider** row, with the middle masked, or `(not set)`.

### In environment variables

Export the variable from the [table above](#built-in-providers) in your shell profile, or set it for one run:

```bash theme={null}
export ANTHROPIC_API_KEY="sk-ant-..."
o4
```

Environment variables suit CI jobs and [print mode](/guides/print-mode), where there is no interface to type a key into.

## Where keys are stored

Keys you enter in o4 go into `~/.o4/settings.json`, in the `api_keys` map keyed by provider ID:

```json ~/.o4/settings.json theme={null}
{
  "api_keys": {
    "anthropic": "sk-ant-...",
    "deepseek": "sk-..."
  }
}
```

o4 writes this file with `0600` permissions, so only your user can read it. The keys are stored in plain text, so don't commit the file or copy it into shared places.

A key in `settings.json` takes precedence over the environment variable for the same provider. If you want an environment variable to win, clear the stored key.

A project can also set `api_keys` in its own `.o4/settings.json`. o4 reads that file only in a [trusted workspace](/safety/workspace-trust), and its keys override yours for the same provider.

<Note>
  o4 removes provider keys from the environment of commands it runs for the model, such as the shell tool, formatters and language servers. The model can't read your keys by running `env`. Variables that other tools also use, such as `AWS_*`, `GITHUB_TOKEN` and `GOOGLE_APPLICATION_CREDENTIALS`, are left in place so tools like `aws`, `gh` and `gcloud` keep working. See [Sandbox](/safety/sandbox).
</Note>

## Check or remove a key

In `/config` > **Providers**, the **API key** row shows whether the provider in the **Provider** row has a stored key. Pressing `Enter` on the row opens an empty input, so to remove the stored key, press `Enter` twice. `Esc` cancels without a change.

Keys that come from environment variables aren't stored by o4. Unset the variable to remove them.

A wrong or expired key shows up as an authentication error (usually HTTP 401) on the first request to that provider. Store the right key or fix the variable, then send the message again.

## Amazon Bedrock

The `amazon-bedrock` provider signs requests with AWS credentials. o4 looks for them in this order:

1. A Bedrock API key in `AWS_BEARER_TOKEN_BEDROCK`, or `BEDROCK_API_KEY`.
2. `AWS_ACCESS_KEY_ID` and `AWS_SECRET_ACCESS_KEY`, with `AWS_SESSION_TOKEN` for temporary credentials.
3. The profile named in `AWS_PROFILE`, or the `default` profile in `~/.aws/credentials`.

The region comes from `AWS_REGION`, then `AWS_DEFAULT_REGION`, then the profile's region in `~/.aws/config`, and falls back to `us-east-1`.

```bash theme={null}
export AWS_PROFILE=bedrock-dev
export AWS_REGION=us-west-2
o4 -m amazon-bedrock:anthropic.claude-sonnet-4-6
```

o4 sends the model ID exactly as it is in the catalog, to the Bedrock Runtime endpoint of your region. Your AWS account must have access to the model in that region.

The built-in catalog lists base model IDs only. To use a cross-region inference profile such as `us.anthropic.claude-sonnet-4-6`, add it as a model entry in `~/.o4/models.toml` first (see [Add or change model entries](/models/overview#add-or-change-model-entries)). Copy the fields of the matching built-in model and keep `api = "bedrock-converse-stream"` and `provider = "amazon-bedrock"`. o4 builds the Bedrock URL from the region, not from `base_url`. Without the entry, `-m amazon-bedrock:us.anthropic.claude-sonnet-4-6` stops with `Model ... not found`.

## Related

* [Claude and ChatGPT subscriptions](/models/subscriptions): use a Claude Code or ChatGPT plan instead of an API key.
* [Choosing a model](/models/overview): pick a model and set the default.
* [Environment variables](/reference/environment-variables): every variable o4 reads.
* [Troubleshooting](/help/troubleshooting): what to do when a provider rejects a request.
