Skip to main content
An LLM provider holds the API key for your models. LLM providers belong to one workspace, and every Helix Cloud session in that workspace uses them to call your models. Keys are stored encrypted and are never shown again.

Before you start

  • Sign in and select a workspace: see Installation. Every command on this page works in the selected workspace, or the one --workspace <name-or-id> names.
  • Have the LLM provider’s API key in a file or an environment variable, so you can pipe it in with --api-key-stdin. The global --api-key flag is your Mutagent key, not this one.
  • A coding agent runs mutagent providers list --json first to see whether the LLM provider already exists, and confirms with you before any command that writes or deletes a key.

mutagent providers mirror

Copy the API keys from your local Helix setup into the workspace as LLM providers. The command shows what it will copy and asks first. If the workspace has no default model, it sets one. Mirroring does not test the keys: check mutagent helix models afterwards, then run a model.
From a coding agent, run it in two steps. First, without --yes: it sends nothing, exits 1, and the JSON output holds the plan. Show the plan to the person, including endpoint and API format changes. Only after they agree, run it again with --yes:
When the run sets the workspace default model, workspaceDefaultModelSet names it. See LLM providers and models for what is and is not copied.

mutagent providers add

Add an LLM provider. The key is tested against the LLM provider before it is saved. If the test fails, nothing is saved and the LLM provider’s error is shown. If the workspace has no default model yet, adding a provider with a key sets one. An existing default is never changed. Pass the key on stdin with --api-key-stdin, so it stays out of your shell history:
azure, vertex, bedrock, and custom take extra flags: zai-coding-plan is the Z.AI GLM Coding Plan. It takes only an API key: its address is fixed, so --base-url is refused.
With --json, success returns "success": true with the new LLM provider’s id, name and workspaceId, and the command exits 0. Then check it:

mutagent providers list

List the workspace’s LLM providers.
The JSON has a data array. Each entry has id, name, provider (the type), baseUrl, isActive and isDefault. Use the id with get, test, update and delete.

mutagent providers get

Show one LLM provider. The key is masked.

mutagent providers test

Test the saved key against the LLM provider again, and list the models the LLM provider reports.
A passing test exits 0. A failing test exits 1 with the error code PROVIDER_TEST_FAILED and the LLM provider’s own error.

mutagent providers update

Change an LLM provider. Only the flags you pass change. An update never changes the workspace default model.

mutagent providers delete

Remove an LLM provider.
mutagent providers rm is the same command. mutagent providers ls is the same as list.

OpenRouter

OpenRouter is one of the LLM provider types. One OpenRouter key gives your cloud runs models from many vendors through your OpenRouter account.
Every model your key can reach on OpenRouter is available to your cloud runs. mutagent helix models lists them after you add the provider.

If it fails

See Errors and exit codes.