Choose a supported provider, authenticate, then select a model. Base Context does not choose a provider or model automatically. Accounts, usage limits, and billing belong to the provider you select.
- Start
base-context. - Open
/loginand select a provider. For a supported subscription, follow its browser authorization link. For API-key authentication, enter that provider's key. Bearer and cloud credentials use the provider-specific setup below. - Open
/modeland choose a supported model. The selected provider/model is saved for later sessions.
For command-line selection, list the supported models and name both parts:
base-context model list
base-context --provider openai --model gpt-5.4
# Equivalent:
base-context --model openai/gpt-5.4An API key alone does not select a model. A missing or unavailable saved model is not silently replaced with another provider. For models outside the built-in list, register the provider/model in models.json first.
Use /login for supported subscription OAuth or API-key authentication. The built-in subscription routes are OpenAI Codex (ChatGPT), Anthropic (Claude Pro/Max), and GitHub Copilot. Open the provider's browser link and complete its authorization steps. Access and usage limits depend on your provider account.
Credentials are stored in ~/.base-context/auth.json (BASE_CONTEXT_HOME can select another state root). Normal OAuth storage persists credentials and refreshes them when needed. Provider-specific bearer and cloud credentials are described below. Prime integrations are disabled; this does not disable other registered OAuth providers.
- Open
/loginand choose OpenAI Codex. - Open the displayed browser link and sign in with the ChatGPT account that has Codex access. Complete the callback or paste the requested authorization response when prompted.
- Open
/modeland explicitly choose anopenai-codexmodel available to your account.
An OpenAI API key belongs to the separate openai provider; it is not required for the Codex subscription route. Anthropic API-key authentication is likewise separate from Claude subscription login. Logging in does not automatically select or replace a model.
The SDK also offers an optional, explicitly injected read-only Codex backend for existing credentials. Only that mode disables login, refresh, credential writes, and API-key fallback. It does not restrict normal interactive subscription login. See SDK authentication.
Both gpt-6-sol and gpt-6-luna are listed under these separate providers:
| Provider | Authentication | Route | Catalog context capacity |
|---|---|---|---|
openai |
OpenAI API key | openai-responses, https://api.openai.com/v1/responses |
1,050,000 tokens |
openai-codex |
ChatGPT/Codex subscription OAuth | openai-codex-responses, https://chatgpt.com/backend-api/codex/responses |
872,000 tokens |
The official Codex catalog specifies a 272,000-token client default and an 872,000-token maximum configuration override for both models. Base Context uses that documented maximum as catalog capacity, without importing Codex's compaction percentages. The API model cards specify 1,050,000 context tokens, 922,000 maximum input tokens, and 128,000 maximum output tokens. All four catalog entries use the nominal 128,000 output ceiling; a separate Codex account/backend output limit has not been verified. Both accept text and images and produce text.
API reasoning levels are off (sent as none), low, medium, high, xhigh, and max. The Codex entries expose low through max, without off or minimal. Codex's Ultra option is client-side task delegation, not an additional Base Context reasoning level.
Catalog costs are flat Standard API-rate estimates. Long-context and service-tier premiums are not modeled by these entries. Codex costs are API-equivalent estimates, not subscription charges or invoices. Model availability depends on account, workspace, client, and rollout; live account access has not been verified.
Official sources: Sol model card, Luna model card, API pricing, Codex models, Codex catalog, and context-field definitions.
Use /login in interactive mode and select a provider to store an API key in auth.json, or set credentials via environment variable:
export ANTHROPIC_API_KEY=sk-ant-...
base-context| Provider | Environment Variable | auth.json key |
|---|---|---|
| Anthropic | ANTHROPIC_API_KEY |
anthropic |
| Azure OpenAI Responses | AZURE_OPENAI_API_KEY |
azure-openai-responses |
| OpenAI | OPENAI_API_KEY |
openai |
| DeepSeek | DEEPSEEK_API_KEY |
deepseek |
| Google Gemini | GEMINI_API_KEY |
google |
| Mistral | MISTRAL_API_KEY |
mistral |
| Groq | GROQ_API_KEY |
groq |
| Cerebras | CEREBRAS_API_KEY |
cerebras |
| Cloudflare AI Gateway | CLOUDFLARE_API_KEY (+ CLOUDFLARE_ACCOUNT_ID, CLOUDFLARE_GATEWAY_ID) |
cloudflare-ai-gateway |
| Cloudflare Workers AI | CLOUDFLARE_API_KEY (+ CLOUDFLARE_ACCOUNT_ID) |
cloudflare-workers-ai |
| xAI | XAI_API_KEY |
xai |
| OpenRouter | OPENROUTER_API_KEY |
openrouter |
| Vercel AI Gateway | AI_GATEWAY_API_KEY |
vercel-ai-gateway |
| ZAI | ZAI_API_KEY |
zai |
| OpenCode Zen | OPENCODE_API_KEY |
opencode |
| OpenCode Go | OPENCODE_API_KEY |
opencode-go |
| Hugging Face | HF_TOKEN |
huggingface |
| Fireworks | FIREWORKS_API_KEY |
fireworks |
| Kimi For Coding | KIMI_API_KEY |
kimi-coding |
| MiniMax | MINIMAX_API_KEY |
minimax |
| MiniMax (China) | MINIMAX_CN_API_KEY |
minimax-cn |
| Xiaomi MiMo | XIAOMI_API_KEY |
xiaomi |
| Xiaomi MiMo Token Plan (China) | XIAOMI_TOKEN_PLAN_CN_API_KEY |
xiaomi-token-plan-cn |
| Xiaomi MiMo Token Plan (Amsterdam) | XIAOMI_TOKEN_PLAN_AMS_API_KEY |
xiaomi-token-plan-ams |
| Xiaomi MiMo Token Plan (Singapore) | XIAOMI_TOKEN_PLAN_SGP_API_KEY |
xiaomi-token-plan-sgp |
Reference for environment variables and auth.json keys: env-api-keys.ts.
Store credentials in the owned ~/.base-context/auth.json (BASE_CONTEXT_HOME selects another product root):
{
"anthropic": { "type": "api_key", "key": "sk-ant-..." },
"openai": { "type": "api_key", "key": "sk-..." },
"deepseek": { "type": "api_key", "key": "sk-..." },
"google": { "type": "api_key", "key": "..." },
"opencode": { "type": "api_key", "key": "..." },
"opencode-go": { "type": "api_key", "key": "..." },
"xiaomi": { "type": "api_key", "key": "..." },
"xiaomi-token-plan-cn": { "type": "api_key", "key": "..." },
"xiaomi-token-plan-ams": { "type": "api_key", "key": "..." },
"xiaomi-token-plan-sgp": { "type": "api_key", "key": "..." }
}The file is created with 0600 permissions (user read/write only). Auth file credentials take priority over environment variables.
The key field supports three formats:
- Shell command:
"!command"executes and uses stdout (cached for process lifetime){ "type": "api_key", "key": "!security find-generic-password -ws 'anthropic'" } { "type": "api_key", "key": "!op read 'op://vault/item/credential'" } - Environment variable: Uses the value of the named variable
{ "type": "api_key", "key": "MY_ANTHROPIC_KEY" } - Literal value: Used directly
{ "type": "api_key", "key": "sk-ant-..." }
Writable OAuth storage is used only when the configured route permits it. The read-only existing-Codex subscription mode does not write this file or refresh credentials. Shell-backed API-key entries execute commands; use only trusted local configuration, never unreviewed imported instructions.
export AZURE_OPENAI_API_KEY=...
export AZURE_OPENAI_BASE_URL=https://your-resource.openai.azure.com
# also supported: https://your-resource.cognitiveservices.azure.com
# root endpoints are auto-normalized to /openai/v1
# or use resource name instead of base URL
export AZURE_OPENAI_RESOURCE_NAME=your-resource
# Optional
export AZURE_OPENAI_API_VERSION=2024-02-01
export AZURE_OPENAI_DEPLOYMENT_NAME_MAP=gpt-4=my-gpt4,gpt-4o=my-gpt4o# Option 1: AWS Profile
export AWS_PROFILE=your-profile
# Option 2: IAM Keys
export AWS_ACCESS_KEY_ID=AKIA...
export AWS_SECRET_ACCESS_KEY=...
# Option 3: Bearer Token
export AWS_BEARER_TOKEN_BEDROCK=...
# Optional region (defaults to us-east-1)
export AWS_REGION=us-west-2Also supports ECS task roles (AWS_CONTAINER_CREDENTIALS_*) and IRSA (AWS_WEB_IDENTITY_TOKEN_FILE).
base-context --provider amazon-bedrock --model us.anthropic.claude-sonnet-4-20250514-v1:0Register custom application inference profile IDs in models.json before selecting them. Prompt caching is enabled automatically for Claude models whose ID contains a recognizable model name (base models and system-defined inference profiles). For application inference profiles (whose ARNs don't contain the model name), set AWS_BEDROCK_FORCE_CACHE=1 to enable cache points:
export AWS_BEDROCK_FORCE_CACHE=1
base-context --provider amazon-bedrock --model arn:aws:bedrock:us-east-1:123456789012:application-inference-profile/abc123If you are connecting to a Bedrock API proxy, the following environment variables can be used:
# Set the URL for the Bedrock proxy (standard AWS SDK env var)
export AWS_ENDPOINT_URL_BEDROCK_RUNTIME=https://my.corp.proxy/bedrock
# Set if your proxy does not require authentication
export AWS_BEDROCK_SKIP_AUTH=1
# Set if your proxy only supports HTTP/1.1
export AWS_BEDROCK_FORCE_HTTP1=1CLOUDFLARE_API_KEY can be set via /login. The account ID and gateway slug must be set as environment variables.
export CLOUDFLARE_API_KEY=... # or use /login
export CLOUDFLARE_ACCOUNT_ID=...
export CLOUDFLARE_GATEWAY_ID=... # create at dash.cloudflare.com → AI → AI Gateway
base-context --provider cloudflare-ai-gateway --model "claude-sonnet-4-5"Routes to OpenAI and Anthropic through Cloudflare AI Gateway. OpenAI uses the OpenAI passthrough route (/openai) with native OpenAI model IDs such as gpt-5.1. Anthropic uses the Anthropic passthrough route (/anthropic) with native Anthropic model IDs such as claude-sonnet-4-5. Cloudflare-hosted @cf/... models are available through the separate cloudflare-workers-ai provider.
AI Gateway authentication uses CLOUDFLARE_API_KEY as cf-aig-authorization. Upstream authentication can be one of:
| Mode | Request auth | Upstream auth |
|---|---|---|
| Workers AI | Cloudflare token only | Cloudflare-native |
| Unified billing | Cloudflare token only | Cloudflare handles upstream auth and deducts credits |
| Stored BYOK | Cloudflare token only | Cloudflare injects provider keys stored in the AI Gateway dashboard |
| Inline BYOK | Cloudflare token plus upstream Authorization header |
The request supplies the upstream provider key |
For normal Base Context usage, prefer unified billing or stored BYOK. Inline BYOK requires configuring an additional upstream Authorization header for the Cloudflare AI Gateway provider, for example via a models.json provider/model override.
CLOUDFLARE_API_KEY can be set via /login. CLOUDFLARE_ACCOUNT_ID must be set as an environment variable.
export CLOUDFLARE_API_KEY=... # or use /login
export CLOUDFLARE_ACCOUNT_ID=...
base-context --provider cloudflare-workers-ai --model "@cf/moonshotai/kimi-k2.6"Base Context automatically sets x-session-affinity for prefix caching discounts.
Uses Application Default Credentials:
gcloud auth application-default login
export GOOGLE_CLOUD_PROJECT=your-project
export GOOGLE_CLOUD_LOCATION=us-central1Or set GOOGLE_APPLICATION_CREDENTIALS to a service account key file.
Via models.json: Add Ollama, LM Studio, vLLM, or any provider that speaks a supported API (OpenAI Completions, OpenAI Responses, Anthropic Messages, Google Generative AI). See models.md.
Via extensions: For providers that need custom API implementations or OAuth flows, create an extension. See custom-provider.md and examples/extensions/custom-provider-gitlab-duo.
When resolving credentials for a provider:
- CLI
--api-keyflag auth.jsonentry (API key or OAuth token)- Environment variable
- Custom provider keys from
models.json