LLM proxy and vault
Call models through one OmniRun API key, and keep the secrets your sandboxes need in a per-user vault.
LLM proxy
Use hundreds of AI models through a single API key with built-in spend tracking and rate limiting. OpenAI-compatible: just change your base URL.
Auth uses the same omr_ API key as sandbox operations. Three endpoints: POST /llm/v1/chat/completions, GET /llm/v1/models, and GET /llm/v1/usage.
// Using the OpenAI SDK
import OpenAI from "openai";
const client = new OpenAI({
baseURL: "https://api.omnirun.io/llm/v1",
apiKey: "omr_your_api_key",
});
const completion = await client.chat.completions.create({
model: "openai/gpt-4o-mini",
messages: [{ role: "user", content: "Hello!" }],
});
console.log(completion.choices[0].message.content);import { LLM } from "@omnirun/sdk";
const llm = new LLM({
apiUrl: "https://api.omnirun.io",
apiKey: "omr_your_api_key",
});
// Non-streaming
const response = await llm.chatCompletion({
model: "openai/gpt-4o-mini",
messages: [{ role: "user", content: "Hello!" }],
});
// Streaming
for await (const chunk of llm.streamChatCompletion({
model: "openai/gpt-4o-mini",
messages: [{ role: "user", content: "Hello!" }],
})) {
process.stdout.write(chunk);
}
// Check usage
const usage = await llm.getUsage();$ curl https://api.omnirun.io/llm/v1/chat/completions \
-H "Authorization: Bearer omr_your_api_key" \
-H "Content-Type: application/json" \
-d '{"model": "openai/gpt-4o-mini",
"messages": [{"role": "user",
"content": "Hello!"}]}'Models and spend
Available models
"openai/gpt-4o-mini" // Free tier
"anthropic/claude-sonnet-4.6" // Free tier
"google/gemini-3.1-pro-preview" // Free tier
"kilo-auto/balanced" // Free tier
"kilo-auto/free" // Free tier
// 300+ more models available
// GET /llm/v1/models for full listSpend tracking
// Free tier: €5.00 credit
// Spend tracked per-request from upstream
// 402 response when cap exceeded
GET /llm/v1/usage
// → { "spendUsedCents": 42,
// "spendCapCents": 500,
// "remainingCents": 458 }Vault
Secure credential storage with per-user isolation. Store API keys and secrets in your vault, then inject them into sandboxes at creation time.
When vaultInject: true is set, all vault credentials are written to /tmp/.omnirun-env inside the sandbox and automatically sourced by the agent process. Vault sandboxes are exempt from idle auto-kill.
Initialize vault
$ curl -X POST https://api.omnirun.io/vault/init \
-H "Authorization: Bearer $OMNIRUN_KEY"
# Auto-created on first loginStore credentials
$ curl -X POST https://api.omnirun.io/vault/credentials \
-H "Authorization: Bearer $OMNIRUN_KEY" \
-d '{"key": "OPENAI_API_KEY",
"value": "sk-..."}'Inject into sandbox
const sandbox = await Sandbox.create('playground', {
vaultInject: true,
});
// Credentials written to /tmp/.omnirun-env
// Auto-sourced by the sandbox agent