# How to Configure Authentication for Different LLM Providers in SkillSpector

> Configure authentication for various LLM providers in SkillSpector. Learn how to set up API keys and base URLs using environment variables for seamless integration.

- Repository: [NVIDIA Corporation/SkillSpector](https://github.com/NVIDIA/SkillSpector)
- Tags: how-to-guide
- Published: 2026-07-11

---

**SkillSpector uses environment variables to authenticate with LLM providers through a pluggable provider architecture where each vendor implements a `resolve_credentials()` method that returns an `(api_key, base_url)` tuple.**

Configuring authentication for different LLM providers in SkillSpector requires understanding how the NVIDIA/SkillSpector codebase abstracts vendor-specific logic behind a unified provider interface. The system reads secrets from environment variables and constructs LangChain chat models automatically, allowing you to switch between OpenAI, Anthropic, NVIDIA Inference, or Amazon Bedrock without changing application code.

## How Authentication Works in SkillSpector

SkillSpector implements a **provider registry pattern** defined in [`src/skillspector/providers/__init__.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/providers/__init__.py). Each provider class inherits from a common base in [`src/skillspector/providers/base.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/providers/base.py) and must implement the `resolve_credentials()` method.

The authentication flow follows four steps:

1. **Provider Discovery** – The CLI or graph engine looks up the active provider in the `_PROVIDERS` registry.
2. **Credential Resolution** – The selected provider calls `resolve_credentials()` to read environment variables.
3. **Model Construction** – Credentials pass to [`src/skillspector/providers/chat_models.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/providers/chat_models.py), which builds the concrete LangChain instance (e.g., `ChatOpenAI`, `ChatAnthropic`).
4. **Validation** – If `resolve_credentials()` returns `None`, the system calls `raise_no_llm_api_key_configured()` to halt execution before any API request occurs.

## Environment Variable Requirements by Provider

Each LLM vendor expects specific environment variables. The following table summarizes the requirements implemented across the provider modules:

### OpenAI

**Required:** `OPENAI_API_KEY`  
**Optional:** `OPENAI_BASE_URL`

The OpenAI provider in [`src/skillspector/providers/openai/provider.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/providers/openai/provider.py) reads these variables to authenticate with `api.openai.com` or compatible endpoints. Setting `OPENAI_BASE_URL` overrides the default `https://api.openai.com/v1`.

### Anthropic

**Required:** `ANTHROPIC_API_KEY`

The Anthropic provider in [`src/skillspector/providers/anthropic/provider.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/providers/anthropic/provider.py) uses this key for `api.anthropic.com` and does not support custom base URLs—the provider uses the constant `https://api.anthropic.com`.

### Anthropic Proxy

**Required:** `ANTHROPIC_PROXY_API_KEY` and `ANTHROPIC_PROXY_ENDPOINT`

For private proxy deployments, the provider in [`src/skillspector/providers/anthropic_proxy/provider.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/providers/anthropic_proxy/provider.py) requires both variables. If either is missing, `resolve_credentials()` returns `None`, triggering authentication failure.

### NVIDIA Inference (NvBuild)

**Required:** `NVIDIA_INFERENCE_KEY`

The NvBuild provider in [`src/skillspector/providers/nv_build/provider.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/providers/nv_build/provider.py) uses this key with the hard-coded base URL `https://api.nvidia.com/v1` (exposed internally as `BUILD_BASE_URL`).

### Amazon Bedrock

**Required:** Standard AWS credentials (`AWS_ACCESS_KEY_ID`, `AWS_SECRET_ACCESS_KEY`, `AWS_DEFAULT_REGION`)

The Bedrock provider in [`src/skillspector/providers/bedrock/provider.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/providers/bedrock/provider.py) operates differently: it returns `None` for the `(api_key, base_url)` tuple because the LangChain Bedrock client handles AWS Signature-V4 authentication internally using boto3.

## Code Examples for Each Provider

### Configuring OpenAI Authentication

Set the environment variables:

```bash
export OPENAI_API_KEY="sk-your-openai-key"

# Optional: route to a self-hosted compatible endpoint

export OPENAI_BASE_URL="https://my-proxy.example.com/v1"

```

Run the CLI:

```python
from skillspector.cli import main

if __name__ == "__main__":
    # Automatically picks up OPENAI_API_KEY

    main()

```

### Configuring Anthropic Authentication

```bash
export ANTHROPIC_API_KEY="sk-antropic-key"

```

Instantiate the provider directly:

```python
from skillspector.providers.anthropic.provider import AnthropicProvider

provider = AnthropicProvider()
chat = provider.create_chat_model(
    model=provider.resolve_model(),
    max_tokens=512,
    timeout=120,
)

# Returns a LangChain ChatAnthropic instance

```

### Configuring Anthropic Proxy Authentication

```bash
export ANTHROPIC_PROXY_API_KEY="proxy-key"
export ANTHROPIC_PROXY_ENDPOINT="https://proxy.mycompany.com/v1"

```

```python
from skillspector.providers.anthropic_proxy.provider import AnthropicProxyProvider

provider = AnthropicProxyProvider()
chat = provider.create_chat_model(
    model="my-custom-model",
    max_tokens=1024,
)

```

### Configuring NVIDIA Inference Authentication

```bash
export NVIDIA_INFERENCE_KEY="nv-inference-key"

```

```python
from skillspector.providers.nv_build.provider import NvBuildProvider

provider = NvBuildProvider()
chat = provider.create_chat_model(
    model=provider.resolve_model(),
    max_tokens=256,
)

```

### Configuring Amazon Bedrock Authentication

```bash
export AWS_ACCESS_KEY_ID="AKIA..."
export AWS_SECRET_ACCESS_KEY="wJalrXUtnF..."
export AWS_DEFAULT_REGION="us-east-1"

```

```python
from skillspector.providers.bedrock.provider import BedrockProvider

provider = BedrockProvider()
chat = provider.create_chat_model(
    model="anthropic.claude-v2",
    max_tokens=512,
)

```

## Error Handling for Missing Credentials

If a required environment variable is absent, `resolve_credentials()` returns `None`, causing the system to invoke `raise_no_llm_api_key_configured()` from [`src/skillspector/providers/__init__.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/providers/__init__.py). This raises a clear exception before any network request attempts, preventing silent failures or ambiguous authentication errors.

The public API in [`src/skillspector/llm_utils.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/llm_utils.py) exposes `resolve_credentials()` for higher-level code that needs to verify authentication status programmatically.

## Summary

- SkillSpector authenticates via **environment variables** read through each provider's `resolve_credentials()` method.
- **OpenAI** requires `OPENAI_API_KEY` and optionally `OPENAI_BASE_URL` (defined in [`src/skillspector/providers/openai/provider.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/providers/openai/provider.py)).
- **Anthropic** requires `ANTHROPIC_API_KEY` (defined in [`src/skillspector/providers/anthropic/provider.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/providers/anthropic/provider.py)).
- **Anthropic Proxy** requires both `ANTHROPIC_PROXY_API_KEY` and `ANTHROPIC_PROXY_ENDPOINT` (defined in [`src/skillspector/providers/anthropic_proxy/provider.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/providers/anthropic_proxy/provider.py)).
- **NVIDIA Inference** requires `NVIDIA_INFERENCE_KEY` with a fixed base URL (defined in [`src/skillspector/providers/nv_build/provider.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/providers/nv_build/provider.py)).
- **Amazon Bedrock** relies on AWS credentials and returns `None` for the credential tuple because AWS SDK handles signing (defined in [`src/skillspector/providers/bedrock/provider.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/providers/bedrock/provider.py)).
- Missing credentials trigger `raise_no_llm_api_key_configured()` from the provider registry in [`src/skillspector/providers/__init__.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/providers/__init__.py).

## Frequently Asked Questions

### What happens if I forget to set the required API key?

If the required environment variable is missing, the provider's `resolve_credentials()` method returns `None`, which triggers `raise_no_llm_api_key_configured()` in [`src/skillspector/providers/__init__.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/providers/__init__.py). This raises a descriptive exception immediately, preventing any LLM API calls from executing with invalid authentication.

### Can I use a custom base URL with OpenAI-compatible providers?

Yes. For OpenAI specifically, set the optional `OPENAI_BASE_URL` environment variable to point to any OpenAI-compatible endpoint. The provider in [`src/skillspector/providers/openai/provider.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/providers/openai/provider.py) passes this value to the LangChain `ChatOpenAI` constructor. Note that Anthropic does not support custom base URLs in the standard provider implementation.

### Does SkillSpector support rotating AWS credentials for Bedrock?

Yes. The Bedrock provider in [`src/skillspector/providers/bedrock/provider.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/providers/bedrock/provider.py) relies on the standard AWS credential chain (`AWS_ACCESS_KEY_ID`, `AWS_SECRET_ACCESS_KEY`, `AWS_DEFAULT_REGION`). Because it returns `None` for the `(api_key, base_url)` tuple and lets the AWS SDK handle SigV4 signing, you can use IAM roles, instance profiles, or any standard AWS authentication method supported by boto3.

### How do I switch between providers without changing code?

Adjust the environment variables to match your target provider's requirements and ensure the correct provider is selected in your SkillSpector configuration. The provider registry in [`src/skillspector/providers/__init__.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/providers/__init__.py) loads the appropriate class based on configuration, and `resolve_credentials()` automatically picks up the new environment variables at runtime.