# AI providers

> Bring-your-own-key LLM credentials for the whole organization, and how to choose between providers.

Source: https://triagic.com/docs/admin/ai-providers

**AI Providers** is org-admin only. One credential set per provider, shared
organization-wide and pulled down by every desktop install.

Nothing in Triagic investigates without one of these configured.

## The providers [#the-providers]

| Provider            | Credentials                                                                   | Embeddings | Typical default models                        |
| ------------------- | ----------------------------------------------------------------------------- | ---------- | --------------------------------------------- |
| **Azure OpenAI**    | Endpoint, API key, deployment, API version                                    | Yes        | `gpt-5.5`                                     |
| **OpenAI**          | API key, optional base URL and TLS options                                    | Yes        | `gpt-5.5`, `gpt-5.5-mini`                     |
| **Anthropic**       | API key, optional base URL and TLS options                                    | No         | `claude-sonnet-5`, `claude-opus-5`            |
| **Google (Gemini)** | API key                                                                       | Yes        | `gemini-2.5-pro`, `gemini-2.5-flash`          |
| **OpenRouter**      | API key                                                                       | No         | `openai/gpt-5.5`, `anthropic/claude-sonnet-5` |
| **Ollama**          | Host (defaults to `http://localhost:11434`), optional API key and TLS options | Yes        | `llama3.3:70b`                                |

> **Note:** Embedding support is not optional in practice
>
> Similar-ticket search is a vector search over past investigations, and it needs
> embeddings. Without an embedding-capable provider it degrades gracefully rather than
> failing, but you lose one of the things that makes Triagic improve with use. If your
> preferred chat provider has no embeddings, configure a second provider that does.

### Azure OpenAI specifics [#azure-openai-specifics]

The **deployment** field is the deployment name on your Azure resource, not a
canonical model id: against the Foundry surface, the API's `model` field carries the
deployment name. Prune your model registry to deployments that actually exist on your
resource; an override for a model that is not in the registry falls through rather
than failing.

### Sending OpenAI or Anthropic somewhere else [#sending-openai-or-anthropic-somewhere-else]

**OpenAI** and **Anthropic** each take an optional **Base URL**. Leave it empty and the
key goes to the vendor. Fill it in and the same key goes to whatever speaks that API at
that address instead: LiteLLM, vLLM, an Azure AI or Cloudflare AI gateway, or a proxy
of your own.

| Field                      | Required        | What to put                                                                                                                                                                     |
| -------------------------- | --------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Base URL**               | no              | The gateway's root, including the version path OpenAI clients expect: `https://llm.acme.internal/v1`. Empty means `https://api.openai.com/v1` (or `https://api.anthropic.com`). |
| **CA certificate path**    | no              | Only when the gateway's certificate is signed by a private CA. An absolute path on the machine running Triagic to that CA's PEM bundle.                                         |
| **Verify TLS certificate** | no, defaults on | Turn off only for a self-signed gateway you cannot supply a CA bundle for.                                                                                                      |

The model names you configure have to be the ones the gateway itself accepts. A
gateway usually renames or namespaces them, and Triagic passes yours through unchanged.

> **Warning:** A base URL is where your API key goes
>
> The key you saved is sent to this address on every call. It is refused if it points at
> a loopback or private-IP literal, which is what stops a URL field from being used to
> make this server probe its own network. An internal *hostname* is accepted, because
> that is what an on-premise gateway actually uses, so make sure the name resolves to
> the host you think it does.

### Ollama specifics [#ollama-specifics]

Ollama runs on the *member's* machine, not here. The host you configure is resolved
locally by each desktop install, so `http://localhost:11434` means each member's own
Ollama. This is the only provider where a shared configuration does not mean a shared
endpoint.

| Field                      | Required                                 | What to put                                                                                                                                                                           |
| -------------------------- | ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Host**                   | no, defaults to `http://localhost:11434` | Where Ollama listens, from the member's machine.                                                                                                                                      |
| **API key**                | no                                       | Ollama has no authentication of its own. Fill this in only when it sits behind a reverse proxy that demands a token; the value is sent as `Authorization: Bearer`.                    |
| **CA certificate path**    | no                                       | For an `https://` host whose certificate comes from a private CA, the usual shape once a reverse proxy is in front. An absolute path on the member's machine to that CA's PEM bundle. |
| **Verify TLS certificate** | no, defaults on                          | Turn off only for a self-signed proxy you cannot supply a CA bundle for.                                                                                                              |

## Secrets and validation [#secrets-and-validation]

Saved keys come back masked as `•••`. Saving with the mask untouched keeps the stored
value; typing over it replaces it.

The portal does not test-call a provider; there is no long-lived process here to make
the round trip from. Cards show:

> Validated by your desktop app after sync.

A wrong key surfaces the first time an investigation runs on a member's machine. If
runs start failing right after a credential change, that is the first place to look.

## Choosing a model, and where [#choosing-a-model-and-where]

This page holds **credentials**. Which model is actually used is decided on the
desktop:

1. A per-thread override picked in the Console composer.
2. The install's runtime default, set on the **Usage** page.
3. The configured fallback.

Background triage and the playbook classifier always follow the runtime default and
never a per-thread override.

## Cost control [#cost-control]

Model choice is the biggest lever on spend, and it is not set here. See
[Spending](/docs/admin/spending) for the cap that actually stops runs, and
[History and usage](/docs/desktop/history-and-usage#usage) for where the numbers live.

Two things worth knowing when you compare providers:

* **An investigation is several calls**, not one. Agent iterations dominate; the
  classifier and metadata extraction are small but run on every ticket.
* **Cheaper models make more iterations.** A model that needs twelve tool calls where
  a better one needs four is not necessarily cheaper, and it is definitely slower.

## Audit [#audit]

Every provider create, update and delete writes an audit entry. See
[Audit log](/docs/admin/audit).
