# How to Configure Multiple LLM Providers in VulnClaw: A Complete Guide

> Learn how to configure multiple LLM providers in VulnClaw with our complete guide. Seamlessly switch between 13+ providers using separate configuration profiles for enhanced flexibility.

- Repository: [Unclecheng/VulnClaw](https://github.com/Unclecheng-li/VulnClaw)
- Tags: how-to-guide
- Published: 2026-06-30

---

**VulnClaw supports seamless switching between 13+ LLM providers by maintaining separate configuration profiles and using the `apply_provider_preset` helper to auto-populate provider-specific defaults.**

VulnClaw is an open-source vulnerability analysis framework that abstracts LLM interactions behind a unified configuration layer. To configure multiple LLM providers in VulnClaw, you maintain distinct configuration profiles while leveraging the `LLMProvider` enum and preset system to handle provider-specific endpoints and models automatically.

## Understanding VulnClaw’s LLM Architecture

VulnClaw’s LLM subsystem centers on a single active configuration object (`config.llm`) that dynamically adapts to any supported provider. The architecture relies on three core components defined in [`vulnclaw/config/schema.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/config/schema.py).

### The LLMProvider Enum

The `LLMProvider` enumeration (lines 14-94) defines every supported provider key as a string value. Valid options include `openai`, `minimax`, `deepseek`, `zhipu`, `moonshot`, `qwen`, `siliconflow`, `doubao`, `baichuan`, `stepfun`, `sensetime`, `yi`, and `custom`.

### Provider Presets and Default Configurations

The `PROVIDER_PRESETS` dictionary (lines 33-95) maps each provider to its default `base_url` and `model`. When you switch providers, VulnClaw references this preset to auto-configure the endpoint unless you explicitly override it.

### The LLMConfig Schema

The `LLMConfig` class (lines 102-110) stores the active provider name, API key, authentication mode, and optional overrides. This schema serializes to YAML in the user’s config directory (default: `~/.config/vulnclaw/config.yaml`).

## Switching Between LLM Providers Programmatically

To configure multiple LLM providers in VulnClaw at runtime, use the `apply_provider_preset` helper in [`vulnclaw/config/settings.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/config/settings.py) (lines 311-350). This function safely swaps providers while preserving existing user overrides.

First, initialize the configuration:

```python
from vulnclaw.config.schema import VulnClawConfig

cfg = VulnClawConfig()  # Defaults to OpenAI

```

List available providers using `list_providers` (lines 352-364):

```python
from vulnclaw.config.settings import list_providers

for provider in list_providers():
    print(f"{provider['provider']} – {provider['label']} (default: {provider['default_model']})")

```

Apply a new provider preset:

```python
from vulnclaw.config.settings import apply_provider_preset

cfg = apply_provider_preset(cfg, "zhipu")

# cfg.llm.provider == "zhipu"

# cfg.llm.base_url == "https://open.bigmodel.cn/api/paas/v4"

# cfg.llm.model == "glm-4"

```

Configure authentication credentials:

```python
cfg.llm.api_key = "sk-REPLACE_WITH_YOUR_KEY"
cfg.llm.auth_mode = "static"

```

Override specific fields (optional):

```python
cfg.llm.base_url = "https://custom.endpoint/v1"
cfg.llm.model = "custom-model-v2"

```

## Querying Available Models

Before finalizing a configuration, validate accessible models using `fetch_provider_models` (lines 667-682 in [`vulnclaw/config/settings.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/config/settings.py)):

```python
from vulnclaw.config.settings import fetch_provider_models

models = fetch_provider_models(cfg.llm.base_url, cfg.llm.api_key)
print("Available models:", models)  # Returns sorted list from /v1/models endpoint

```

## Managing Multiple Provider Profiles

Since VulnClaw maintains only one active `LLMConfig` at a time, managing multiple providers requires separate configuration files. Create distinct YAML profiles for each provider:

```python
import yaml
from pathlib import Path
from vulnclaw.config.schema import VulnClawConfig
from vulnclaw.config.settings import apply_provider_preset

def save_profile(cfg, name):
    config_dir = Path.home() / ".config" / "vulnclaw" / "profiles"
    config_dir.mkdir(parents=True, exist_ok=True)
    with open(config_dir / f"{name}.yaml", "w") as f:
        yaml.safe_dump(cfg.model_dump(), f)

# Save ZhiPu profile

cfg_zhipu = apply_provider_preset(VulnClawConfig(), "zhipu")
cfg_zhipu.llm.api_key = "sk-zhipu-key"
save_profile(cfg_zhipu, "zhipu")

# Save OpenAI profile  

cfg_openai = apply_provider_preset(VulnClawConfig(), "openai")
cfg_openai.llm.api_key = "sk-openai-key"
save_profile(cfg_openai, "openai")

```

Load the desired profile at runtime to switch contexts instantly.

## Configuring Providers via the CLI and TUI

The interactive TUI ([`vulnclaw/cli/tui.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/cli/tui.py), lines 1190-1192) and Textual-based UI ([`vulnclaw/cli/tui_textual.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/cli/tui_textual.py), lines 617-635) both consume `config.llm` fields. When you select **"Configure LLM"** from the menu:

- The UI displays the current provider from `config.llm.provider`
- It populates the selection list using `list_providers()`
- It calls `apply_provider_preset` internally when you confirm a switch
- It persists changes to disk automatically

This provides a user-friendly alternative to manual YAML editing for non-technical users.

## Summary

- VulnClaw uses a single active `LLMConfig` object stored in `config.llm` to manage provider settings.
- The `LLMProvider` enum and `PROVIDER_PRESETS` dictionary in [`vulnclaw/config/schema.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/config/schema.py) define supported providers and their default endpoints.
- Use `apply_provider_preset()` from [`vulnclaw/config/settings.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/config/settings.py) to switch providers while auto-populating base URLs and default models.
- Query available models per provider using `fetch_provider_models()` to validate API access before configuration.
- Maintain multiple provider setups by saving separate YAML profiles and loading them at runtime.

## Frequently Asked Questions

### Can I use multiple LLM providers simultaneously in one VulnClaw instance?

No. VulnClaw maintains a single active LLM configuration at runtime via the `config.llm` object. To work with multiple providers, you must maintain separate configuration profiles and switch between them by reloading the config object, or run separate VulnClaw instances with different config files.

### How do I add a custom OpenAI-compatible endpoint that isn't in the preset list?

Set `cfg.llm.provider` to `"custom"` and manually specify `cfg.llm.base_url` and `cfg.llm.model`. The `custom` provider type uses the same OpenAI SDK backend but allows arbitrary endpoints, bypassing the preset defaults while maintaining compatibility with the configuration schema defined in [`vulnclaw/config/schema.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/config/schema.py).

### Where does VulnClaw store my API keys?

API keys are stored in the YAML configuration file at `~/.config/vulnclaw/config.yaml` (or your platform's equivalent user config directory) when using `auth_mode = "static"`. Ensure this file has restricted permissions (600) to prevent unauthorized access to your credentials.

### Why does switching providers sometimes reset my model selection?

The `apply_provider_preset` function only updates `base_url` and `model` if you haven't explicitly overridden them already. If you manually set these fields before switching providers, VulnClaw preserves your custom values. If you rely on defaults, the function populates the new provider's preset values automatically.