Skip to main content

Providers and host ownership

Rust LLM compat provider

Create a local provider with glxdev new --kind llm-provider --language rust. The generated V2 manifest uses a WASM component and the LLM compat world. Its configuration is account-scoped, the API key is a host-resolved secret, and http.client is scoped to the configured endpoint host. Permission declarations do not grant authority; the host and user grant remain part of admission.

glxdev new --kind llm-provider --language rust --package-id com.example.provider --name "Example Provider" --publisher example --base-url https://api.example.com/v1 --permission-host api.example.com
glxdev check --project ./example-provider
glxdev build --project ./example-provider
glxdev test --project ./example-provider
glxdev pack --project ./example-provider
glxdev verify --project ./example-provider

The local path has test-fixture evidence for package creation and host install/activation. The catalog API accepts authenticated publications from accounts with an active registered key and a valid Glixo-root-signed publisher certificate. See Publishing API for the HTTP contract, browser certificate import requirements, and the glxdev 0.1.0 local development preview. A Glixo publisher operator issues certificates out of band. Browser publishing also requires the deployment owner to provision matching raw base64 Ed25519 public keys as trusted build-time VITE_GLIXO_PUBLISHER_ROOT_PUBKEY and API GLIXO_PUBLISHER_ROOT_PUBKEY; this checkout does not wire the browser value into CI, so the browser flow remains disabled.

C# host-only provider

glxdev new --kind trusted-native-csharp --language csharp emits a source example only. It has no marketplace manifest or package. A trusted host build must compile and explicitly register it. Marketplace content cannot load native C# assemblies or arbitrary processes.

Anthropic, OpenAI, Gemini, Ollama, CLIProxy OAuth, OneDrive, and Dropbox implementations are host-owned. Provider metadata may show settings and supported credentials; it does not supply their implementation. OneDrive and Dropbox community descriptors are configure-only and carry no artifact links.

Migration references

CLIProxy and OmniRoute echo cards, GitNexus's old npx stdio configuration, client UI examples, and the Node/stdio adapter sample are not executable VNext examples. Fake/community cards are unlisted, examples are excluded from portal sync, and old archives are not re-signed as VNext.