You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
OpenGranter can validate an already fetched OpenRouter SSE response, but no internal invoker sends an authorized stream:true request to OpenRouter. A streaming invoker must use the same fixed endpoint, secret, model/provider scope, request snapshots and timeout safety as the current non-streaming adapter, then pass its response through the bounded SSE validator.
Scope
Add an internal text-only delegated OpenRouter streaming invoker. Share request validation/body construction with the non-streaming invoker so supported text and sampling controls preserve their existing semantics. Capture the approved model/provider attempt before any await; reject function-tool controls that the text-only stream decoder cannot represent. Send one POST to the fixed OpenRouter chat URL with stream:true, exact provider.only, a server-held Bearer key, redirect rejection and bounded timeout. Await validated delta delivery through the existing response boundary. Return final normalized usage only on complete terminal/usage/done; classify pre-header and midstream failures safely without retry or leaking raw errors.
Do not expose client stream:true, write usage/audit, add direct-provider streaming, or change route orchestration. The future gateway integration must apply authentication, IAM, limits and audit before calling this invoker.
Acceptance
Authorized text request reaches only the fixed endpoint with a captured model/provider set and existing supported controls; callback receives validated deltas in order and completion returns final usage.
Invalid attempts, unsupported tool controls, malformed requests and missing credentials stop before HTTP. Scope changes during credential resolution cannot alter the request or accepted response.
HTTP status, malformed/incomplete SSE, timeout, redirect/network and callback failures retain fixed safe categories and possible-billing metadata; no upstream body/key enters errors.
Problem
OpenGranter can validate an already fetched OpenRouter SSE response, but no internal invoker sends an authorized
stream:truerequest to OpenRouter. A streaming invoker must use the same fixed endpoint, secret, model/provider scope, request snapshots and timeout safety as the current non-streaming adapter, then pass its response through the bounded SSE validator.Scope
Add an internal text-only delegated OpenRouter streaming invoker. Share request validation/body construction with the non-streaming invoker so supported text and sampling controls preserve their existing semantics. Capture the approved model/provider attempt before any await; reject function-tool controls that the text-only stream decoder cannot represent. Send one POST to the fixed OpenRouter chat URL with
stream:true, exactprovider.only, a server-held Bearer key, redirect rejection and bounded timeout. Await validated delta delivery through the existing response boundary. Return final normalized usage only on complete terminal/usage/done; classify pre-header and midstream failures safely without retry or leaking raw errors.Do not expose client
stream:true, write usage/audit, add direct-provider streaming, or change route orchestration. The future gateway integration must apply authentication, IAM, limits and audit before calling this invoker.Acceptance