How to Configure Authentication for Different LLM Providers in SkillSpector

SkillSpector uses environment variables to authenticate with LLM providers through a pluggable provider architecture where each vendor implements a resolve_credentials() method that returns an (api_key, base_url) tuple.

Configuring authentication for different LLM providers in SkillSpector requires understanding how the NVIDIA/SkillSpector codebase abstracts vendor-specific logic behind a unified provider interface. The system reads secrets from environment variables and constructs LangChain chat models automatically, allowing you to switch between OpenAI, Anthropic, NVIDIA Inference, or Amazon Bedrock without changing application code.

How Authentication Works in SkillSpector

SkillSpector implements a provider registry pattern defined in src/skillspector/providers/__init__.py. Each provider class inherits from a common base in src/skillspector/providers/base.py and must implement the resolve_credentials() method.

The authentication flow follows four steps:

  1. Provider Discovery – The CLI or graph engine looks up the active provider in the _PROVIDERS registry.
  2. Credential Resolution – The selected provider calls resolve_credentials() to read environment variables.
  3. Model Construction – Credentials pass to src/skillspector/providers/chat_models.py, which builds the concrete LangChain instance (e.g., ChatOpenAI, ChatAnthropic).
  4. Validation – If resolve_credentials() returns None, the system calls raise_no_llm_api_key_configured() to halt execution before any API request occurs.

Environment Variable Requirements by Provider

Each LLM vendor expects specific environment variables. The following table summarizes the requirements implemented across the provider modules:

OpenAI

Required: OPENAI_API_KEY
Optional: OPENAI_BASE_URL

The OpenAI provider in src/skillspector/providers/openai/provider.py reads these variables to authenticate with api.openai.com or compatible endpoints. Setting OPENAI_BASE_URL overrides the default https://api.openai.com/v1.

Anthropic

Required: ANTHROPIC_API_KEY

The Anthropic provider in src/skillspector/providers/anthropic/provider.py uses this key for api.anthropic.com and does not support custom base URLs—the provider uses the constant https://api.anthropic.com.

Anthropic Proxy

Required: ANTHROPIC_PROXY_API_KEY and ANTHROPIC_PROXY_ENDPOINT

For private proxy deployments, the provider in src/skillspector/providers/anthropic_proxy/provider.py requires both variables. If either is missing, resolve_credentials() returns None, triggering authentication failure.

NVIDIA Inference (NvBuild)

Required: NVIDIA_INFERENCE_KEY

The NvBuild provider in src/skillspector/providers/nv_build/provider.py uses this key with the hard-coded base URL https://api.nvidia.com/v1 (exposed internally as BUILD_BASE_URL).

Amazon Bedrock

Required: Standard AWS credentials (AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_DEFAULT_REGION)

The Bedrock provider in src/skillspector/providers/bedrock/provider.py operates differently: it returns None for the (api_key, base_url) tuple because the LangChain Bedrock client handles AWS Signature-V4 authentication internally using boto3.

Code Examples for Each Provider

Configuring OpenAI Authentication

Set the environment variables:

export OPENAI_API_KEY="sk-your-openai-key"

# Optional: route to a self-hosted compatible endpoint

export OPENAI_BASE_URL="https://my-proxy.example.com/v1"

Run the CLI:

from skillspector.cli import main

if __name__ == "__main__":
    # Automatically picks up OPENAI_API_KEY

    main()

Configuring Anthropic Authentication

export ANTHROPIC_API_KEY="sk-antropic-key"

Instantiate the provider directly:

from skillspector.providers.anthropic.provider import AnthropicProvider

provider = AnthropicProvider()
chat = provider.create_chat_model(
    model=provider.resolve_model(),
    max_tokens=512,
    timeout=120,
)

# Returns a LangChain ChatAnthropic instance

Configuring Anthropic Proxy Authentication

export ANTHROPIC_PROXY_API_KEY="proxy-key"
export ANTHROPIC_PROXY_ENDPOINT="https://proxy.mycompany.com/v1"
from skillspector.providers.anthropic_proxy.provider import AnthropicProxyProvider

provider = AnthropicProxyProvider()
chat = provider.create_chat_model(
    model="my-custom-model",
    max_tokens=1024,
)

Configuring NVIDIA Inference Authentication

export NVIDIA_INFERENCE_KEY="nv-inference-key"
from skillspector.providers.nv_build.provider import NvBuildProvider

provider = NvBuildProvider()
chat = provider.create_chat_model(
    model=provider.resolve_model(),
    max_tokens=256,
)

Configuring Amazon Bedrock Authentication

export AWS_ACCESS_KEY_ID="AKIA..."
export AWS_SECRET_ACCESS_KEY="wJalrXUtnF..."
export AWS_DEFAULT_REGION="us-east-1"
from skillspector.providers.bedrock.provider import BedrockProvider

provider = BedrockProvider()
chat = provider.create_chat_model(
    model="anthropic.claude-v2",
    max_tokens=512,
)

Error Handling for Missing Credentials

If a required environment variable is absent, resolve_credentials() returns None, causing the system to invoke raise_no_llm_api_key_configured() from src/skillspector/providers/__init__.py. This raises a clear exception before any network request attempts, preventing silent failures or ambiguous authentication errors.

The public API in src/skillspector/llm_utils.py exposes resolve_credentials() for higher-level code that needs to verify authentication status programmatically.

Summary

Frequently Asked Questions

What happens if I forget to set the required API key?

If the required environment variable is missing, the provider's resolve_credentials() method returns None, which triggers raise_no_llm_api_key_configured() in src/skillspector/providers/__init__.py. This raises a descriptive exception immediately, preventing any LLM API calls from executing with invalid authentication.

Can I use a custom base URL with OpenAI-compatible providers?

Yes. For OpenAI specifically, set the optional OPENAI_BASE_URL environment variable to point to any OpenAI-compatible endpoint. The provider in src/skillspector/providers/openai/provider.py passes this value to the LangChain ChatOpenAI constructor. Note that Anthropic does not support custom base URLs in the standard provider implementation.

Does SkillSpector support rotating AWS credentials for Bedrock?

Yes. The Bedrock provider in src/skillspector/providers/bedrock/provider.py relies on the standard AWS credential chain (AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_DEFAULT_REGION). Because it returns None for the (api_key, base_url) tuple and lets the AWS SDK handle SigV4 signing, you can use IAM roles, instance profiles, or any standard AWS authentication method supported by boto3.

How do I switch between providers without changing code?

Adjust the environment variables to match your target provider's requirements and ensure the correct provider is selected in your SkillSpector configuration. The provider registry in src/skillspector/providers/__init__.py loads the appropriate class based on configuration, and resolve_credentials() automatically picks up the new environment variables at runtime.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →