- Manage provider configuration centrally at the project level in MeshAgent.
- Track usage, billing, and budget controls across tools and team members in one place.
- Use the same integration pattern for raw HTTP requests, official SDKs, and higher-level frameworks.
Before you start
MeshAgent provides managed OpenAI and Anthropic access by default. To use your own provider credentials, configure them per project in MeshAgent Accounts under Integrations. See Integrations for details. For localhost URLs and temporary local credentials on your machine, use the Local CLI Proxy. For Codex or Claude,meshagent setup can configure them to use MeshAgent directly.
To inspect your own LLM usage for the current project, open the LLM Proxy page in MeshAgent Studio and check the My Usage tab. Use MeshAgent Accounts to manage billing, model and app restrictions, and quotas.
How it works
- Your client sends a normal OpenAI-, Anthropic-, or Grok-compatible request to MeshAgent.
- Your client authenticates with a MeshAgent OAuth access token or participant token.
- MeshAgent validates the provider path and model, then forwards the request.
- MeshAgent returns the provider-compatible response and records usage for the project resolved from the credential.
meshagent ask and the MeshAgent Codex and Claude integrations.
For OpenAI-compatible clients, the router supports Chat Completions and Responses over HTTP, including streamed responses. It also proxies WebSocket upgrades for the Responses API and Realtime API. The legacy /v1/completions endpoint is not part of the supported route set; use /v1/chat/completions or /v1/responses.
Select a deployment and project
meshagent setup signs you in and stores an OAuth session locally. meshagent project list shows the projects you can use and their IDs. The current project is marked with *. Use meshagent project activate PROJECT_ID to switch projects first.
Find the proxy URLs
Read the URLs from the active MeshAgent CLI profile. This works for meshagent.com and self-hosted deployments:
The Anthropic value is the SDK base URL. For raw Anthropic HTTP requests, append the normal endpoint path, such as
/v1/messages.
Authentication
The proxy accepts either of these values inAuthorization: Bearer <token>:
- A MeshAgent OAuth access token, such as the value printed by
meshagent auth token. The token must include thellm:invokescope. OAuth requests must also includeMeshagent-Project-Id, and the signed-in user must have LLM proxy access to that project. - A MeshAgent participant token whose API grant permits LLM requests. The project is embedded in the participant token, so
Meshagent-Project-Idis optional; when supplied, it must match the token’s project.
Make a raw HTTP request
Set the project ID shown bymeshagent project list, then call the deployment-specific URL directly.
Send an OpenAI-compatible request
Send an Anthropic-compatible request
$(meshagent auth token) with the participant token and omit the Meshagent-Project-Id header.
Use the OpenAI and Anthropic SDKs
Official SDKs use provider environment variables, so set them from the active MeshAgent deployment and OAuth session before running the examples:Meshagent-Project-Id as a default SDK header because they use an OAuth token.
OpenAI SDK
Anthropic SDK
Use other frameworks
Configure an OpenAI-compatible framework with the value frommeshagent config get openai.url, or an Anthropic SDK with the value from meshagent config get anthropic.url. Use an OAuth or participant token as the framework’s API key. When using OAuth, configure Meshagent-Project-Id as a default request header.
For example, LangChain can use the OpenAI-compatible route directly:
meshagent llm proxy process is running.
Automatic environment variables in room services
Service containers usingcontainer.template: agent receive the standard provider variables automatically. agent is the default template for containers declared in a service manifest.
OPENAI_BASE_URLandANTHROPIC_BASE_URLpoint to the MeshAgent proxy reachable by the room runtime.OPENAI_API_KEYandANTHROPIC_API_KEYcontain the container’s MeshAgent participant token.MESHAGENT_TOKENcontains the same token.- Grok-compatible services also receive
GROK_BASE_URL,XAI_BASE_URL,GROK_API_KEY, andXAI_API_KEY. - Values explicitly set in
container.environmentoverride these defaults. container.template: nonedisables all template-provided values. In that case, configure the URLs and credentials yourself.
agent role, and default agent API permissions. The LLM variables are therefore available only when the agent template can create that runtime participant identity. See Deploy Services for the complete template behavior.
Configure models, apps, and quotas
Open the project in MeshAgent Accounts, then select Models:- Allowed Models restricts proxy traffic to selected provider/model pairs. If the restriction is off, the project is not model-allowlisted.
- Apps allows or blocks requests using glob-style
User-Agentpatterns. You can also reject requests that omitUser-Agent. - Quotas sets default monthly dollar limits for users and service accounts. Blank means unlimited. Limits reset at the start of each UTC month and are soft limits, so an in-flight request may finish after the balance is exhausted.
- A quota manager can set per-user and per-service-account overrides from Members, return a subject to the project default, or reset its current balance.
Log proxy traffic to a feed
Usemeshagent llm logger to manage project loggers that copy matching LLM proxy events into a destination feed. Create the destination feed first, then create a logger with a JMESPath metadata filter:
bash
meshagent llm logger list, meshagent llm logger get LOGGER_ID, meshagent llm logger update LOGGER_ID, and meshagent llm logger delete LOGGER_ID to manage existing loggers.
Supported Provider Paths
MeshAgent exposes these provider-compatible paths. MeshAgent proxies OpenAI, Anthropic, and Grok endpoints.OpenAI-Compatible
The main generation and realtime transports are:
For WebSocket clients, use the same proxy host and change the URL scheme from
https to wss (or http to ws). Send the same MeshAgent bearer credential and, for OAuth, the same project header during the WebSocket handshake.
/v1/chat/completions/v1/responses/v1/responses/compact/v1/responses/input_tokens/v1/embeddings/v1/audio/speech/v1/audio/transcriptions/v1/audio/translations/v1/modelsand/v1/models/*/v1/images/*/v1/realtimeand/v1/realtime/*
Anthropic-Compatible
/v1/messages/v1/messages/count_tokens/v1/messages/batches*/v1/complete/v1/modelsand/v1/models/*
Grok/OpenAI-Compatible
/v1/messages/v1/responsesand/v1/responses/*/v1/responses/compact/v1/responses/input_tokens/v1/modelsand/v1/models/*