Model Provider

Anthropic, OpenAI or OpenRouter, with your own key. The provider bills you; Link adds nothing. Your agent never holds the key: Link's proxy adds it on the way out.

Add your key

ANTHROPIC_API_KEY=sk-ant-... lnk agent start   # or OPENAI_API_KEY, OPENROUTER_API_KEY
lnk agent start --model claude-sonnet-5-5      # another model the provider has

With a key and no --model, every harness gets claude-sonnet-5-5 on Anthropic, gpt-6-luna on OpenAI and openrouter/auto on OpenRouter. Link reads the provider's variable when you start an agent with no model, and again at each start to renew the key. Every flag: Switch Models.

Your key never reaches your agent

lnk agent keys wire      # the proxy adds the keys; restarts the agent
lnk agent keys agent     # the harness holds the keys again

With wire, the harness gets placeholders, and Link's proxy, outside the sandbox, adds the real model key on the way to the provider, and the real Telegram bot token on the way to Telegram. Nothing in the sandbox can find either. Link Harness runs this way by default, and so does every other harness whose adapter says it can, OpenClaw, Hermes Agent and DeepSeek Harness among them. Any other holds its keys unless you switch it. Link Harness never holds a bot token: Link carries its channels.

  • It works for Anthropic, OpenAI and OpenRouter keys. With a local model or lan, the setting is kept and does nothing.
  • If a request fails with the placeholder, lnk agent keys agent puts the key back.
  • lnk agent <harness> check reports LEAK if the real key or token is still in the harness's home.

What the proxy passes and refuses: Security.

How large a model's window is, the longest answer it writes, how it's asked to think, and what it costs are facts, so they're data Link ships, never code: a file refreshed with the current figures of every model OpenRouter lists, at every release. A model newer than your Link, or a figure that's wrong, is yours to add or correct, and yours wins, field by field:

lnk model facts                       # every model Link knows, and whose each figure is
lnk model facts claude-sonnet-5-5     # one
lnk model facts --json                # for other programs
# ~/.config/lnk/model-facts.toml
[model."my-finetune"]                 # a model, by its provider's or a router's name
window = 65536                        # its whole window, the answer included, in tokens
answer = 8192                         # the longest answer it writes
thinking = "no"                       # adaptive, budget, effort or no
price = { input = 0.2, output = 0.6 } # dollars a million tokens; cached, too, if it has one

[model."claude-sonnet-5-5"]
window = 500000                       # corrects Link's figure, keeps the rest

A model is found by its own name, or with a router's prefix (anthropic/claude-sonnet-4.6), a dated snapshot's suffix, or . for -. Each harness is handed its agent's model's facts with its settings (model_facts); Link Harness takes its window from them, a runtime on this machine's report next (yours first), and prices a turn its provider didn't price.