Skip to content
M31A

Models & Provider Trust

NVIDIA NIM integration, endpoint trust boundaries, and SSE streaming.


M31A defines a clean, provider-neutral abstraction seam (ModelProvider) supporting structured chat messages, tool definitions, token usage accounting, and SSE streaming.

Provider-Neutral Abstraction

The runtime logic is strictly decoupled from model provider implementations. The model caller communicates through an async trait with built-in retry policies and token tracking.

Production Provider: NVIDIA NIM

Provider: nvidia_nim
Model ID: nvidia/nemotron-3-ultra-550b-a55b
Base URL: https://integrate.api.nvidia.com/v1
Streaming: Server-Sent Events (SSE) active

Endpoint Trust Boundary Invariant

Security Invariant: NO CREDENTIAL ATTACHED BEFORE ENDPOINT TRUST. A workspace configuration file cannot redirect a credential-bearing HTTP request to an attacker-controlled endpoint. Only trusted administrative tiers (System, User, Explicit CLI) can authorize custom endpoints.

Deterministic Rejection of Retired Providers

In production, configuring retired provider identifiers (openai, anthropic, gemini, or Ollama local aliases) is rejected deterministically during configuration validation.