Models & Provider Trust
NVIDIA NIM integration, endpoint trust boundaries, and SSE streaming.
M31A defines a clean, provider-neutral abstraction seam (ModelProvider) supporting structured chat messages, tool definitions, token usage accounting, and SSE streaming.
Provider-Neutral Abstraction
The runtime logic is strictly decoupled from model provider implementations. The model caller communicates through an async trait with built-in retry policies and token tracking.
Production Provider: NVIDIA NIM
Provider: nvidia_nim
Model ID: nvidia/nemotron-3-ultra-550b-a55b
Base URL: https://integrate.api.nvidia.com/v1
Streaming: Server-Sent Events (SSE) active
Endpoint Trust Boundary Invariant
Security Invariant: NO CREDENTIAL ATTACHED BEFORE ENDPOINT TRUST. A workspace configuration file cannot redirect a credential-bearing HTTP request to an attacker-controlled endpoint. Only trusted administrative tiers (System, User, Explicit CLI) can authorize custom endpoints.
Deterministic Rejection of Retired Providers
In production, configuring retired provider identifiers (openai, anthropic, gemini, or Ollama local aliases) is rejected deterministically during configuration validation.