Add Command Code backend and caller-supplied endpoints; release 0.8.0 - #20
Merged
Merged
Conversation
The same Jev decisions protocol is served by more hosts than the two registry names. `backend` now also accepts a validated BackendEndpoint object everywhere a backend name is accepted, resolved through the new resolveBackend() and backendHost() exports, and the registry gains a `commandcode` entry that sends to api.commandcode.ai with the model typesafe/jev and the key from COMMANDCODE_API_KEY. Key isolation is the invariant: a registry backend other than typesafe, and every endpoint object, reads only its own keyEnv variable and never TYPESAFE_API_KEY or the login store, so a TypeSafe key can no longer travel to another host. A public model list (commandcode, OpenRouter, or an endpoint without modelsVerifyKey: true) never records verification.
DevMortimer
marked this pull request as ready for review
September 28, 2026 03:28
Both resolve the backend they are given, so an unknown name or an endpoint object that fails validation throws the same configuration error as resolveBackend instead of producing a status. The docs said they never throw; they now say that holds for a valid backend and point callers at resolveBackend for user-supplied endpoints.
DevMortimer
marked this pull request as draft
September 28, 2026 03:35
DevMortimer
marked this pull request as ready for review
September 28, 2026 03:38
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
commandcodebackend: judgments go toapi.commandcode.aiunder/provider/v1/systemonewith the modeltypesafe/jevand the key fromCOMMANDCODE_API_KEY; its public model list does not verify a key.backendnow accepts a caller-supplied endpoint object (BackendEndpoint) wherever a backend name is accepted (createTypeSafe,keySituation,resolveApiKey,authState,ensureApiKey,safeError). An endpoint names its ownlabel,host,keyEnv, and optionallypath,defaultModel, and model-list fields; it is validated on every call and never added to the registry.resolveBackend(nameOrEndpoint)andbackendHost(nameOrEndpoint), plus theBackendEndpoint,BackendSpec, andResolvedBackendtypes.TypeSafeBackendgains"commandcode", which a consumer with an exhaustiveswitchwill see as a new member.Why
DevMortimer/pi-warden#134 needs to pass a user-configured endpoint to this package and name the real destination host in its consent text. The same Jev decisions protocol is served by more hosts than the two hardcoded ones. This is about which host serves Jev; it is not a different model or protocol.
Key isolation
A registry backend other than
typesafe, and every endpoint object, reads only its ownkeyEnvenvironment variable. It never readsTYPESAFE_API_KEYor the login store, and akeyEnvofTYPESAFE_API_KEYis refused — a TypeSafe key can no longer travel to another host. The auth record is still one file shared by every backend.How it was verified
npm run checkon the base commit: build and typecheck pass, tests 104 pass / 0 fail. On this branch: build and typecheck pass, tests 133 pass / 0 fail.http:case, every validation refusal, key isolation, non-verifying model lists, malformed replies, 401 advice, and the new helpers.npm run test:livewas not run: it needs a paid key.