feat(providers): add Kimi For Coding via static KIMI_API_KEY

Provider 16 (19th registry variant). Same endpoint + models + Kimi dialect
as the existing OAuth kimi-code platform (api.kimi.com/coding/v1 via the
KIGI_CODE_BASE_URL override), but authenticated with a static KIMI_API_KEY
instead of the device flow — for users who have a Kimi For Coding key rather
than an OAuth subscription. Bearer, OpenAI listing, ChatCompletions,
ChatCompat::Kimi, wire_serves_metadata=true (Kimi /models self-serves
context/thinking), restrict_to_enriched=false (clean 3-model catalog).
/coding/v1/models is auth-gated (401) so it doubles as the validator.

No collision: KIMI_API_KEY was previously unused (grep-verified), and the
house BYOK reads only KIGI_API_KEY/XAI_API_KEY/legacy. kimi-code (OAuth) and
kimi-coding (static key) are independently gated (OAuth-token vs key) and
their models get distinct managed keys (kimi-code/k3 vs kimi-coding/k3) — a
user with both simply sees each Kimi model twice; no dedup collision, no crash.

Review (6 areas): no blocking defects; confirmed the spec correctly mirrors
KIMI_CODE_SPEC (differing only in uses_oauth/api_key_envs/console_host/labels)
and the coexistence is benign. Strengthened the e2e's dialect assertion (Kimi
is the default ChatCompat, so it did not discriminate a parse failure) by
also asserting parse_managed_model_key attributes the key to KimiCoding.

Tests: e2e proves wire-served context (1_048_576 from the wire) with the
models.dev fetch SKIPPED (all-wire-metadata provider, .expect(0)), bare-id
round-trip under kimi-coding/, Kimi dialect; validation test rejects a 401
from /models. Registry at 19; picker 20 rows; snapshot already bundles
kimi-for-coding.
This commit is contained in:
2026-07-21 18:10:23 -04:00
parent 8245deb373
commit c02b4b1ed7
4 changed files with 161 additions and 9 deletions
@@ -622,7 +622,8 @@ mod tests {
"vercel-ai-gateway",
"xai",
"qwen-token-plan",
"qwen-token-plan-cn"
"qwen-token-plan-cn",
"kimi-coding"
]
);
assert_eq!(default_id(&built), Some(XAI_API_KEY_METHOD_ID));
@@ -663,7 +664,8 @@ mod tests {
"vercel-ai-gateway",
"xai",
"qwen-token-plan",
"qwen-token-plan-cn"
"qwen-token-plan-cn",
"kimi-coding"
]
);
assert_eq!(default_id(&built), Some(CACHED_TOKEN_AUTH_METHOD_ID));
@@ -697,7 +699,8 @@ mod tests {
"vercel-ai-gateway",
"xai",
"qwen-token-plan",
"qwen-token-plan-cn"
"qwen-token-plan-cn",
"kimi-coding"
]
);
assert_eq!(default_id(&built), Some(CACHED_TOKEN_AUTH_METHOD_ID));
@@ -734,7 +737,8 @@ mod tests {
"vercel-ai-gateway",
"xai",
"qwen-token-plan",
"qwen-token-plan-cn"
"qwen-token-plan-cn",
"kimi-coding"
]
);
assert_eq!(default_id(&built), None);
@@ -1066,4 +1070,28 @@ mod tests {
bailian.console.aliyun.com"
);
}
/// Kimi-For-Coding static key: /coding/v1/models requires auth (401 for a
/// bad key), so it validates the key. Base resolves via KIGI_CODE_BASE_URL.
#[tokio::test]
#[serial]
async fn kimi_coding_validates_against_models_and_rejects_bad_key() {
use wiremock::matchers::{method, path};
let server = wiremock::MockServer::start().await;
wiremock::Mock::given(method("GET"))
.and(path("/models"))
.respond_with(wiremock::ResponseTemplate::new(401))
.expect(1)
.mount(&server)
.await;
let _base = EnvGuard::set(kigi_env::CODE_BASE_URL_ENV, &server.uri());
let err =
authenticate_platform_api_key(kigi_models::PlatformId::KimiCoding, Some("kc-bad"))
.await
.expect_err("a 401 from /models must reject the key");
assert_eq!(
err.message,
"Invalid API key for kimi-coding \u{2014} check your key on www.kimi.com"
);
}
}