Context Boundary
- Repo/module:
talkincode/GameKit, AI controls in the browser UI and /api/ai Worker
- Version/commit:
main, 9eb811e7bc3db3193b57609425723c478e438d32
- Runtime: browser application calling a Cloudflare Worker
- OS/browser: not recorded; provider-specific browser/CORS behavior is not yet selected
- Dependencies/config: current text and image models are Workers AI bindings; no provider setting exists
Expectation vs. Reality
Expected: Users can configure their own AI API credentials and provider/model in Settings, then choose that configuration for AI requests.
Actual: The client sends text and image requests to /api/ai, while the Worker uses fixed Workers AI model constants. There is no UI or stored configuration for a user-owned endpoint, API key, or model.
Reproduction Path
- Open GameKit and choose an AI action.
- Try to select a different provider or enter a personal API endpoint, key, and model.
- Observe that no such setting is available and requests continue through
/api/ai to the fixed Worker models.
Minimal reproduction: the client call targets /api/ai; the Worker selects TEXT_MODEL or IMAGE_MODEL without reading user provider configuration.
Blast Radius
- Affected users/paths: users who want to use their own provider, model, or billing account.
- Frequency: every AI text or image request currently uses the configured Workers AI binding.
- Severity rationale: users cannot choose their own provider; if the goal is to stop spending the operator's public Workers AI quota, recommend P1 for the product decision, otherwise P2 as a provider-choice enhancement.
- Workaround: use the current built-in provider or generate content in an external tool and import it manually.
Evidence
Decisions Needed
- Should user-owned APIs be an additional option, or replace the built-in Workers AI path?
- Which first-version contract is intended (for example, OpenAI-compatible text API), and is image generation in scope?
- API keys must not enter project files/exports. The same-origin preview isolation finding in issue #6 should be resolved before persisting credentials in browser storage.
Context Boundary
talkincode/GameKit, AI controls in the browser UI and/api/aiWorkermain,9eb811e7bc3db3193b57609425723c478e438d32Expectation vs. Reality
Expected: Users can configure their own AI API credentials and provider/model in Settings, then choose that configuration for AI requests.
Actual: The client sends text and image requests to
/api/ai, while the Worker uses fixed Workers AI model constants. There is no UI or stored configuration for a user-owned endpoint, API key, or model.Reproduction Path
/api/aito the fixed Worker models.Minimal reproduction: the client call targets
/api/ai; the Worker selectsTEXT_MODELorIMAGE_MODELwithout reading user provider configuration.Blast Radius
Evidence
/api/ai: store.tsx, asset requestDecisions Needed