OmniRunDocs

LLM proxy and vault

Call models through one OmniRun API key, and keep the secrets your sandboxes need in a per-user vault.

Same omr_ API keyapi.omnirun.io/llm/v1

LLM proxy

Use hundreds of AI models through a single API key with built-in spend tracking and rate limiting. OpenAI-compatible: just change your base URL.

Auth uses the same omr_ API key as sandbox operations. Three endpoints: POST /llm/v1/chat/completions, GET /llm/v1/models, and GET /llm/v1/usage.

// Using the OpenAI SDK
import OpenAI from "openai";

const client = new OpenAI({
  baseURL: "https://api.omnirun.io/llm/v1",
  apiKey: "omr_your_api_key",
});

const completion = await client.chat.completions.create({
  model: "openai/gpt-4o-mini",
  messages: [{ role: "user", content: "Hello!" }],
});

console.log(completion.choices[0].message.content);

Models and spend

Available models
"openai/gpt-4o-mini"          // Free tier
"anthropic/claude-sonnet-4.6"  // Free tier
"google/gemini-3.1-pro-preview"  // Free tier
"kilo-auto/balanced"         // Free tier
"kilo-auto/free"             // Free tier

// 300+ more models available
// GET /llm/v1/models for full list
Spend tracking
// Free tier: €5.00 credit
// Spend tracked per-request from upstream
// 402 response when cap exceeded

GET /llm/v1/usage
// → { "spendUsedCents": 42,
//     "spendCapCents": 500,
//     "remainingCents": 458 }

Vault

Secure credential storage with per-user isolation. Store API keys and secrets in your vault, then inject them into sandboxes at creation time.

When vaultInject: true is set, all vault credentials are written to /tmp/.omnirun-env inside the sandbox and automatically sourced by the agent process. Vault sandboxes are exempt from idle auto-kill.

Initialize vault
$ curl -X POST https://api.omnirun.io/vault/init \
  -H "Authorization: Bearer $OMNIRUN_KEY"

# Auto-created on first login
Store credentials
$ curl -X POST https://api.omnirun.io/vault/credentials \
  -H "Authorization: Bearer $OMNIRUN_KEY" \
  -d '{"key": "OPENAI_API_KEY",
       "value": "sk-..."}'
Inject into sandbox
const sandbox = await Sandbox.create('playground', {
  vaultInject: true,
});

// Credentials written to /tmp/.omnirun-env
// Auto-sourced by the sandbox agent