Cori
Guides

Configure LLM providers

How llm steps resolve a model provider and credentials — stored in the OS keychain, configured per machine, never in the workflow.

Where credentials live

LLM provider credentials are configured at the machine level, not in the workflow. A workflow's llm step declares the model it needs (e.g., gpt-4o-mini); the machine running the step resolves the provider and its API key.

Keys are stored in the OS keychain (Keychain Access on macOS, Credential Manager on Windows, libsecret on Linux) under the cori service. On machines without a usable keychain — headless Linux, CI — Cori falls back to a 0600 file under ~/.cori/credentials/. Secrets are never written to config.toml.

Never put API keys in a workflow manifest or step file. Workflow files are meant to be shared and version-controlled. Credentials belong to the machine.

Configure a provider

Store a key with cori login — input is hidden and goes straight to the keychain:

cori login anthropic

Supported providers: openai, anthropic, gemini. For scripts and CI, pipe the key instead:

echo "$ANTHROPIC_API_KEY" | cori login anthropic --stdin

Remove a key with:

cori logout anthropic

In the Cori desktop app, the same keys live under Manage → AI Providers: paste a key, it's verified against the provider's API, then stored. The CLI and the desktop app share the same keychain entries — a key saved in either place works in both.

cori config set llm.<provider>.api_key is rejected — secrets don't live in config. cori config get llm.<provider>.api_key still works: it reads through to the keychain, so existing scripts that fetch the key keep working.

Resolution order

At run time a provider's key resolves in two layers:

  1. Environment variable — OPENAI_API_KEY, ANTHROPIC_API_KEY, GEMINI_API_KEY (or GOOGLE_API_KEY). Use this for per-shell overrides and CI.
  2. The secret store — OS keychain, or the file fallback on machines without one.

Missing-key behavior

If a workflow needs a provider that has no key:

  • cori check reports the missing provider with the fix (cori login <provider>).
  • An interactive cori run pauses and tells you to set the env var or run cori login <provider> in another terminal, then continues once the key exists.
  • Non-interactive runs (including runs started over MCP) fail immediately with the same message.
  • The desktop app's launch window shows a paste-a-key form inline when it detects LLM steps without a configured provider — save the key and the run unblocks without leaving the page.

Model resolution

An llm step declares a model value (e.g., gpt-4o-mini, claude-sonnet-4-5). Cori infers the provider from the model name and looks up that provider's key using the resolution order above.

Keeping credentials out of workflows

Never put API keys, tokens, or any credentials in:

  • manifest.md frontmatter
  • Step files (steps/*.ts)
  • types.ts
  • Any file in the workflow folder

Workflow folders are shared. Any credential in a workflow folder becomes a credential leak when the folder is pushed to a git repository.

All credentials go in the OS keychain (via cori login or the desktop app) or as environment variables on the machine running the step.

On this page