Skip to content

Support native Anthropic BYOK endpoints - #63

Merged
morgaesis merged 11 commits into
mainfrom
codex/anthropic-byok
Jul 13, 2026
Merged

morgaesis merged 11 commits into
mainfrom
codex/anthropic-byok

Conversation

@morgaesis

@morgaesis morgaesis commented Jul 13, 2026 •

Copy link
Copy Markdown
Contributor

Adds native Anthropic Messages support, sealed custom endpoint authentication, and the updated hosted model roster. Provider connections reject private targets, pin validated DNS results, and never follow redirects; native Anthropic scoring uses only compatible explicit scorer configuration. Review and reply receipts attribute per-model usage and conservatively flag incomplete provider accounting across retries and fallbacks. The release version is 0.5.0.

@postil-dev postil-dev Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gate: failed

  • error Model provider unavailable · severity: error · confidence 1.00 · kind: uncertainty
Review metadata
  • Model: deepseek/deepseek-v4-pro -> mistralai/mistral-small-3.2-24b-instruct -> google/gemma-3-27b-it -> qwen/qwen3-32b
  • Review duration: 419.12 s
  • Commit: 7ed6235
  • Dashboard run: View in Postil
  • Tokens: 0 prompt, 0 completion

@postil-dev postil-dev Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gate: failed

The diff introduces a usage receipt feature for postil respond and refactors the answer method to return structured data. A potential issue exists where failed model attempts with zero token usage are silently excluded from the receipt, which may be intentional but could mask cost-relevant failures. The receipt file is created with create_new(true), which will fail if the path already exists, potentially breaking idempotent retries.

  • warn Usage receipt creation fails if path already exists · severity: warn · confidence 0.70 · kind: humanEscalation
  • warn Failed model attempts with zero token usage are excluded from receipt · severity: warn · confidence 0.60 · kind: humanEscalation

1 finding(s) suppressed by policy (confidence/severity/ignore).

Review metadata
  • Model: deepseek/deepseek-v4-pro
  • Review duration: 27.89 s
  • Commit: b129ccf
  • Dashboard run: View in Postil
  • Tokens: 11879 prompt, 1962 completion
  • Scorer: openai/gpt-5-mini (2 disagreement(s))

Comment thread src/respond.rs
);
let file = OpenOptions::new()
.write(true)
.create_new(true)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

warn Usage receipt creation fails if path already exists
warn · confidence 0.70 · kind: humanEscalation

OpenOptions::new().create_new(true) will return an error if the file at POSTIL_USAGE_RECEIPT_PATH already exists. This breaks idempotent retries: if postil respond is re-run with the same receipt path (e.g., after a transient network error before the receipt is written), it will fail immediately instead of overwriting or appending. Consider using .create(true).truncate(true) to allow overwriting, or document that the caller must delete the file before retrying.

Comment thread src/llm.rs
Comment on lines +539 to +545
if model_usage.prompt_tokens > 0 || model_usage.completion_tokens > 0 {
add_usage(&mut usage, model_usage);
models.push(ModelUsage {
model: model.clone(),
usage: model_usage,
});
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

warn Failed model attempts with zero token usage are excluded from receipt
warn · confidence 0.60 · kind: humanEscalation

When a model in the cascade fails and its model_usage has zero prompt_tokens and zero completion_tokens, the attempt is silently omitted from the models array in the Answer struct. This means the usage receipt will not record that the model was tried at all. If the provider charges for failed attempts (e.g., rate-limit or authentication errors that still consume tokens), this data is lost. Verify with the Anthropic and OpenAI billing models whether zero-token failures can incur costs, and if so, always push a ModelUsage entry for every attempt regardless of token counts.

@morgaesis

Copy link
Copy Markdown
Contributor Author

@postil approve bb5c6049e18ea1a54bec04eeafcfb6a3e7d5ea986833a80000a7e4cc71316262 -- Sequential retries exclusively borrow stack-local state; no concurrent mutation exists.

@morgaesis

Copy link
Copy Markdown
Contributor Author

@postil approve 33435f21cf9f06bdf3979d64276772e4dd705d65f42981fa475621b64c87ec21 -- Sequential retries exclusively borrow stack-local state; no concurrent mutation exists.

@morgaesis

Copy link
Copy Markdown
Contributor Author

@postil approve 414724469941df86ae6072c0a74b1e22767e83ce3e86478c9c80af82cdd9ca05 -- Sequential retries exclusively borrow stack-local state; no concurrent mutation exists.

@postil-dev

postil-dev Bot commented Jul 13, 2026

Copy link
Copy Markdown

Approval rejected: that finding is absent, already approved, revoked, or no longer kind-blocking.

@morgaesis

Copy link
Copy Markdown
Contributor Author

@postil approve 88ff043473956711a683ecf5be71c9ccd8c6737e882bb6db2baf6bb8551c1c41 -- Sequential retries exclusively borrow stack-local state; no concurrent mutation exists.

@postil-dev

postil-dev Bot commented Jul 13, 2026

Copy link
Copy Markdown

Approval rejected: that finding is absent, already approved, revoked, or no longer kind-blocking.

@morgaesis

Copy link
Copy Markdown
Contributor Author

@postil approve d2a87b0289dc688320b9b76798bbc1bafe12cae5cb86426a35a5bc50eedb8a8e -- The temporary file is created with explicit mode 0600 and create_new fails closed.

@postil-dev

postil-dev Bot commented Jul 13, 2026

Copy link
Copy Markdown

Approval rejected: that finding is absent, already approved, revoked, or no longer kind-blocking.

@morgaesis

Copy link
Copy Markdown
Contributor Author

@postil approve 8d914169bfba7ae8f465626fb4d51b321fb8fe38a71f0d543a66ffa8cb4c2617 -- Receipt contents are sync_all committed, atomically renamed, and the parent directory is synced before output or delivery.

@postil-dev

postil-dev Bot commented Jul 13, 2026

Copy link
Copy Markdown

Approval rejected: that finding is absent, already approved, revoked, or no longer kind-blocking.

@morgaesis

Copy link
Copy Markdown
Contributor Author

@postil approve 561a0bba4cf6c8b6ea5dc20791ee2648afea243f72e3953edce023edd4da1545 -- Receipt contents are sync_all committed, atomically renamed, and the parent directory is synced before output or delivery.

@postil-dev

postil-dev Bot commented Jul 13, 2026

Copy link
Copy Markdown

Approval rejected: that finding is absent, already approved, revoked, or no longer kind-blocking.

2 similar comments
@postil-dev

postil-dev Bot commented Jul 13, 2026

Copy link
Copy Markdown

Approval rejected: that finding is absent, already approved, revoked, or no longer kind-blocking.

@postil-dev

postil-dev Bot commented Jul 13, 2026

Copy link
Copy Markdown

Approval rejected: that finding is absent, already approved, revoked, or no longer kind-blocking.

@morgaesis
morgaesis merged commit 6598428 into main Jul 13, 2026
7 of 8 checks passed
@morgaesis
morgaesis deleted the codex/anthropic-byok branch July 13, 2026 02:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant