docs

providers and keys

the model providers bise knows, where a key comes from, and how to add one.

bise talks to the model providers directly with your key. there is no bise account and no bise server in between: your prompts go from your Mac to the provider you picked.

add a key

the fastest way is the first run: when bise finds no key, it asks for one and checks it. after that, any time:

  • in bise: /provider, then the provider, then paste the key.
  • in a terminal:
bise login anthropic        # asks for the key, hidden
bise login                  # no provider: pick one from the list

bise login makes one tiny call with the key before it saves it, so a wrong key never gets saved. from a script, the key comes on stdin:

printf '%s' "$MY_KEY" | bise login openai --check
bise login openai --from ~/.env    # reads OPENAI_API_KEY=... from that file
flagwhat it does
--checkone tiny call first, saved only if it answers (for a script)
--no-checksave it without the call
--model provider/modelthe model of that call (default: the one in use, else the provider's)
--from FILEread the key from a PROVIDER_API_KEY=... line in a .env or shell file

to remove a saved key: bise logout anthropic.

where a key comes from

for each provider, bise takes the first key it finds, in this order:

  1. ~/.bise/auth.json: what bise login, /provider and the first run save. only you can read it (mode 0600).
  2. the environment: the provider's variable, for example ANTHROPIC_API_KEY.
  3. the old .env files of earlier versions: ~/.bend-harness/.env, ~/.vibe/.env.

so a key you saved in bise wins over the one in your shell. when your environment holds another key for the same provider, bise says once that it isn't used. bise logout <provider> goes back to the environment's key.

to see where each key comes from (never the key itself):

bise providers

and to test one with a tiny call, without saving anything:

bise auth check anthropic

the providers

bise models prints this list with each model's context, price and key state. the first run offers the first five; the others work with bise login <id> or their variable.

provideridkey variablestarts withget a key
AnthropicanthropicANTHROPIC_API_KEYanthropic/claude-opus-5-5platform.claude.com
OpenAIopenaiOPENAI_API_KEYopenai/gpt-6-astraplatform.openai.com
Google AI StudiogoogleGEMINI_API_KEY (or GOOGLE_API_KEY)google/gemini-3.8-flashaistudio.google.com
MistralmistralMISTRAL_API_KEYmistral/mistral-medium-latestconsole.mistral.ai
OpenRouteropenrouterOPENROUTER_API_KEYopenrouter/anthropic/claude-sonnet-5.5openrouter.ai
GroqgroqGROQ_API_KEYgroq/openai/gpt-oss-120bconsole.groq.com
xAIxaiXAI_API_KEYxai/grok-4.7console.x.ai
DeepSeekdeepseekDEEPSEEK_API_KEYdeepseek/deepseek-v4-proplatform.deepseek.com
Together AItogetherTOGETHER_API_KEYtogether/zai-org/GLM-5.3api.together.ai
Fireworks AIfireworksFIREWORKS_API_KEYfireworks/accounts/fireworks/models/glm-5p3app.fireworks.ai
CerebrascerebrasCEREBRAS_API_KEYcerebras/gpt-oss-120bcloud.cerebras.ai
Ollamaollamanone, localollama/<model>ollama.com
LM Studiolmstudionone, locallmstudio/<model>lmstudio.ai

listed but not usable yet: Azure OpenAI, Google Vertex AI and Amazon Bedrock (they need a cloud login bise doesn't do yet). to reach them today, put a gateway in front: see gateways and local models.

some keys only do one job:

provideridkey variablewhat for
ElevenLabselevenlabsELEVENLABS_API_KEYvoice: speech to text
DeepgramdeepgramDEEPGRAM_API_KEYvoice: speech to text
TypeSafetypesafeTYPESAFE_API_KEYthe checker of auto mode

one key is enough

with a single key, bise fills every role from that provider: main and the agents use the model you picked, the small jobs (titles, summaries) use the provider's cheap model, and voice uses the provider's speech model when it has one (Mistral, OpenAI). models and roles says how to change each one.

providerits cheap model, for small jobs
Anthropicclaude-haiku-4-5
OpenAIgpt-6-luna
Google AI Studiogemini-3.5-flash-lite
Mistralmistral-small-latest
OpenRoutergoogle/gemini-3.8-flash

any model, listed or not

a model name is provider/model. any model the provider serves works, even when bise doesn't list it: it gets the provider's defaults (context, output, images). the provider is the part before the first /, so openrouter/moonshotai/kimi-k3 is OpenRouter's moonshotai/kimi-k3.

bise models            # every provider and model bise knows
bise models openai     # only these

what leaves your Mac

your messages, the files and command output the agents read, and the images you paste go to the provider of the model that works on them. nothing goes to bise. a few features send more, and each one says so the first time: voice sends your audio to its speech provider, and auto mode's checker sends the commands it checks to its model.