ReferenceProviders

Providers

bro command reference for providers.

2 min readEdit this page

See Init and config for shared conventions and environment variables.

Two ways a provider becomes available: BYOK (its API key in the environment — see BYOK) and providers login (OAuth against subscription providers such as Claude or Codex subscriptions — see Model sources). providers list shows the catalog and which providers are active in the current config.

bro providers

Provider management

Usage: bro providers <COMMAND>

bro providers list

List every configured provider

Usage: bro providers list [OPTIONS]

FlagDescription
-c, --config <CONFIG>Path to bitrouter.yaml. When omitted, the binary resolves in this order: ./bitrouter.yaml → $BITROUTER_HOME/bitrouter.yaml → ~/.bitrouter/bitrouter.yaml → zero-config in-memory defaults (bro init is the explicit way to scaffold a file)
--socket <SOCKET>Explicit local control socket for the daemon's accepted provider catalog

bro providers login

Log in to an upstream provider — interactive credential setup. Per-provider methods are auto-derived from the catalog: claude-code adopts the live Claude Code session; anthropic accepts an API-key paste; openai-codex runs the ChatGPT PKCE flow; github-copilot the GitHub device flow; everything else accepts a pasted API key. Logging in to the built-in bitrouter provider runs the same cloud sign-in as bro cloud login.

Usage: bro providers login [OPTIONS] <PROVIDER>

ArgumentDescription
<PROVIDER>Provider id (e.g. claude-code, openai-codex, bitrouter)
FlagDescription
-l, --label <LABEL>Account label this credential is stored under (default default). Ignored for the bitrouter provider (it uses the cloud credential) [default: default]
--import-existingImport an existing vendor CLI session without prompting for a browser sign-in. Currently supported by openai-codex
--no-browserDo not run a browser-based provider OAuth flow
--api-key <KEY>Seed a BYOK provider non-interactively from this API key — skips the method menu and the stdin paste. The provider must accept a pasted key (OAuth-only backends reject it)
--key-stdinRead the API key from stdin (one line) instead of prompting — for pipelines, e.g. printf %s "$KEY" | bro providers login openai --key-stdin
bro providers login <provider-id>

Opens the provider's OAuth flow and stores the credential in the local credential store — no key to paste. providers logout removes it.

bro providers logout

Log out of an upstream provider — clears every stored credential for it. For the built-in bitrouter provider this is cloud logout

Usage: bro providers logout <PROVIDER>

ArgumentDescription
<PROVIDER>Provider id whose stored credentials should be removed

How is this guide?

On this page