LLM providers
You bring your own keys. An LLM provider added to a workspace belongs to that workspace only; two workspaces never share one. Add them in the web app under Configuration › LLM Providers or withmutagent providers add, or copy the keys you signed in with in Helix using
mutagent providers mirror.
Every entry is tested against the provider before it is stored, and a stored entry can be re-tested
with mutagent providers test <id>. mutagent providers list --models shows the models each entry
offers.
OpenAI, Anthropic, Google Gemini, Moonshot AI, Z.AI (GLM), DeepSeek and xAI also take an optional
base URL override and a model allow-list. For Z.AI (GLM), the default model is
glm-5.3. Z.AI
(Coding Plan) offers the GLM models your plan includes.
LLM provider setup lists every field.
Helix on your machine does not need any of these: it calls the provider directly with the key in
your environment or the one you set with
/login. Workspace LLM providers are used by the hosted
parts, such as cloud sessions and managed agents.Sandbox providers
A sandbox provider runs cloud sessions and managed agents: an isolated machine with Helix and your agent’s tools on it.
Cloud sandboxes, and the GitHub and Slack runs that use them, are not open to every account yet.
They open to every account after production acceptance.
LLM providers and Environments are per workspace because they hold your keys and your secrets. The
sandbox provider holds neither, so one list serves every workspace; the keys and Environment a
session needs are passed in from the workspace that launches it.
mutagent sandbox providers lists the sandbox providers, and mutagent sandbox presets lists the
presets: named sandbox definitions a cloud session can be launched from. See
Sandbox providers.
Trace sources
Helix reads traces where they already are. It does not copy them to Mutagent.
Local sources are described in Local trace sources. Langfuse and
OpenObserve can also be connected to a workspace once, with
mutagent integrations sources add, so
Mutagent pulls the traces for you instead of Helix reading them from your machine.
Apply targets
After you approve a fix, Helix writes it to a target. Every target lands the change as a GitHub pull request on your repository; nothing is written to your default branch. With no target configured, every stage is report-only.Channels
Connect them in the web app under Configuration › Integrations (each has a Connect button),
or with
mutagent gateway connect github and mutagent gateway connect slack. Each app is installed
once for your organization. The repositories Mutagent can use are the ones you give the Mutagent
GitHub App access to on GitHub. GitHub and Slack connect through the gateway, which starts each run
in a cloud sandbox.