- choose a provider;
- enter the credential in a secure browser step;
- test the connection; and
- refresh the models it can use.
Before you begin
source_id and auth_scheme can be used.
1. Start secure setup
This example uses OpenAI. Replace both values with a pair returned by the provider-profile endpoint.continue_url in a browser and complete the provider step.
Do not paste that URL into a support message. The poll response does not return
the continuation URL again.
2. Finish the browser step
state is completed. This secure setup is short-lived,
bound to one organization and provider, and can be used once.
If it expires or fails, start a new setup. Do not reuse its URL.
3. Create and test the connection
4. Refresh models and read the catalog
Provider setup fields
For Bedrock, the region must match the inference-profile ARN. The AWS principal
must be allowed to read and invoke through that profile.
If the connection test fails
Rotate or revoke
Rotation tests the replacement credential before changing the connection. A failed replacement leaves the working credential in place. Revoking a Millwork connection immediately stops later work from using it. It does not revoke the credential in the provider account. Remove or rotate that credential in the provider’s own controls when needed.Run a model
Use a model returned by the refreshed catalog.
Get help
Send safe context without sending the credential.