Connect your workspace
Scoped credentials, explicit model choice and a documented service boundary.
Endpoints and authentication
The canonical OpenRouter-style base URL is https://nostril.ai/api/v1. https://api.nostril.ai/api/v1 serves the same gateway. OpenAI clients use https://nostril.ai/v1 or https://api.nostril.ai/v1; these have their own response and error shapes.
Send Authorization: Bearer YOUR_NOSTRIL_KEY. Create and revoke scoped agent keys from your authenticated dashboard. Keys are shown once; keep them in your credential store. Workspace creation is operator managed; no public signup or credit purchase is enabled.
import os
from openai import OpenAI
client = OpenAI(base_url="https://nostril.ai/v1",
api_key=os.environ["NOSTRIL_API_KEY"])
models = client.models.list()
print([model.id for model in models.data])
Use the official OpenRouter client's documented server URL override with the canonical /api/v1 base. Version pins used for regression and production transport checks: OpenAI Python 3.24.0 / JavaScript 7.27.0; OpenRouter Python 1.3.22 / JavaScript @openrouter/sdk 1.4.21.
Current availability
HTTPS workspace access, scoped keys, policy controls and durable account state are available after operator provisioning. No provider model is available yet. The authenticated model list is empty. Provider access, current model/rate/privacy qualification, billing authority and approved spending limits remain prerequisites for inference.
Chat Completions and Responses routes are distinct. Their parsing, streaming, tool continuation and accounting regression tests use synthetic providers locally. These tests are not evidence of production inference. Unsupported operations and parameters return explicit errors; hosted tools never fabricate results.
OpenRouter's full pinned inventory remains 151 operations; complete compatibility is unqualified. The initial OpenAI inventory covers 20 Chat Completions/Responses operations, not the entire platform. Live inference, purchases, customer response storage and customer learning remain unavailable.
GET /health reports control-service health and deployed release. GET /ready returns 503 while provider dispatch is unavailable. An HTTP 200 or successful SDK model-list call does not prove working inference or provider billing.
Privacy, consent and removal
Prompts and responses are excluded from learning records and training telemetry. Feedback is structured and task scoped; missing or disputed evidence remains unknown. Private, shared and experiment permissions are independent. Customer learning and response-content retention are disabled pending their privacy and removal gates.
Revoking a key terminates its authority for subsequent requests and sessions. Learning removal preserves operational accounting journals and unresolved exposure. Cancellation does not invent zero provider liability; uncertain charges remain held until verified usage or reconciliation.
Concrete model, provider and effort intent remain gateway constraints. Learned recommendations cannot expand permission, spending authority or model eligibility. No measured quality advantage or savings is claimed.