diff --git a/litellm-api-keys.prose.md b/litellm-api-keys.prose.md index e94afc2..c42897d 100644 --- a/litellm-api-keys.prose.md +++ b/litellm-api-keys.prose.md @@ -257,9 +257,51 @@ reads use per-agent identities. This eliminates the single shared token risk. | Agent | .env Keys | |-------|-----------| | Mumuni | MUMUNI_LITELLM_API_KEY, MUMUNI_ZULIP_API_KEY | -| Tanko | TANKO_LITELLM_API_KEY, TANKO_ZULIP_API_KEY | -| Koby | (wrapper injects from vault — .env has Telegram token) | -| Koonimo | KOONIMO_LITELLM_API_KEY, KOONIMO_ZULIP_API_KEY | +|| Tanko | TANKO_LITELLM_API_KEY, TANKO_ZULIP_API_KEY | +|| Koby | (wrapper injects from vault — .env has Telegram token) | +|| Koonimo | KOONIMO_LITELLM_API_KEY, KOONIMO_ZULIP_API_KEY | +|| Agent Zero (kagentz .14) | OPENROUTER_API_KEY (direct OpenRouter access) | + +### Agent Zero (kagentz .14) — OpenRouter Integration (2026-09-01) + +Agent Zero runs in Docker on kagentz (CT105) and uses **direct OpenRouter API access**, +not via the LiteLLM proxy. This is because Agent Zero's workflow (self-update manager, +UI bootstrap, model selection) is built around OpenRouter's native authentication. + +**Key Storage:** +- **Container**: `/a0/usr/.env` (line ~72: `API_KEY_OPENROUTER=sk-or-v1-…`) +- **Vault**: Infisical secret `OPENROUTER_API_KEY` (project=agents, env=production) +- **Fallback**: The container's .env is the primary source; vault sync is optional + (unlike fleet agents which require vault injection) + +**Current Key (2026-09-01):** +- **Prefix**: `sk-or-v1-0af3f3…` +- **User**: `user_2rt9lCqcd5d7Vk1t18DHsvWdPTT` +- **Plan**: Paid (not free tier) +- **Usage**: 0 (as of 2026-09-01) + +**Model Configuration:** +- **Preset**: "Cost Efficient" (`/a0/usr/plugins/_model_config/presets.yaml`) +- **Model**: `openrouter/moonshotai/kimi-k3` +- **API Base**: (empty — uses OpenRouter default) + +**Why not LiteLLM proxy?** +Agent Zero's architecture was designed before the fleet adopted the LiteLLM proxy +standard. The container runs `/exe/self_update_manager.py` and `/a0/run_ui.py` which +directly call OpenRouter via Python's requests library. Converting would require: +1. Refactoring all LLM calls to use `litellm` library +2. Adding vault wrapper injection +3. Updating self_update_manager to use proxy-aware key handling + +**Rotation Procedure:** +1. Generate new key in OpenRouter UI +2. Update container: `sed -i 's/^API_KEY_OPENROUTER=.*/API_KEY_OPENROUTER=/' /a0/usr/.env` +3. Update vault: `infisical secrets set OPENROUTER_API_KEY= --projectId=agents --env=production` +4. Restart container: `sudo docker exec agent-zero supervisorctl restart run_ui` +5. Verify: `curl -s https://openrouter.ai/api/v1/auth/key -H "Authorization: Bearer "` + +**Related Contract:** +- `agent-zero-openrouter-key.prose.md` — Full agent-zero key management contract ## Key Rotation Log