Skip to content

feat: configurable judgment backend (Command Code and custom endpoints) - #136

Merged
DevMortimer merged 2 commits into
mainfrom
feat/configurable-backend
Sep 28, 2026
Merged

DevMortimer merged 2 commits into
mainfrom
feat/configurable-backend

Conversation

@DevMortimer

Copy link
Copy Markdown
Owner

What

typesafeBackend in the user config now takes:

  • "commandcode": judgments go to api.commandcode.ai under /provider/v1/systemone, with the key from COMMANDCODE_API_KEY and the model typesafe/jev.

  • An endpoint object for any server that speaks the same decisions protocol (POST /v1/systemone):

    { "label": "Corp judge gateway", "host": "https://gw.example.com", "path": "/judge/systemone", "keyEnv": "GW_JUDGE_KEY", "defaultModel": "jev-1.13" }

This uses pi-typesafe 0.8.0, which resolves and validates both forms.

Why

Two backends were hardcoded, so a third host serving Jev, or a self-hosted server, needed a code change and a release (#134).

Behavior

  • User file only. A project's .pi/pi-warden.json still cannot set typesafeBackend, in the string or the object form.
  • Key isolation. An endpoint object gets only the key from its own keyEnv variable. TYPESAFE_API_KEY and the /typesafe login store are never sent to it.
  • The destination is visible. For a non-TypeSafe backend, /warden status, the /warden enable dialog and the /warden test confirmation name the label, host and model sent, and the consent text names the real host.
  • No silent fallback (changed). An unknown name, or an object pi-typesafe refuses, used to fall back to "typesafe". It now turns judgments off and shows the refusal once and in /warden status. A mistyped value never sends judgments to api.typesafe.ai.
  • An endpoint that names no defaultModel turns judgments off with one notice instead of failing on every request.

Verification

  • npm run check: typecheck clean, 1197 tests pass, 0 fail, build clean. Main: 1186 pass.
  • New tests cover: the commandcode spec and an object reaching createTypeSafe unchanged; an unknown name and an invalid object turning judgments off without creating a client; the project file not setting either form; status and consent naming the custom label and host; key messages naming the object's keyEnv.
  • Also removes a duplicated eval:replay script key in package.json.

Closes #134. Refs #34.

pi-typesafe 0.8.0 resolves and validates the backend: the names "typesafe",
"openrouter", and "commandcode", or an endpoint object with its own label,
host, path, keyEnv, and defaultModel. The spec goes to createTypeSafe,
authState, and ensureApiKey unchanged, so the status line describes the key
the requests use. A non-TypeSafe backend names its label, host, and model in
/warden status, the /warden enable dialog, and the /warden test confirmation,
and the consent disclosure names the real destination host. The TypeSafe key
and the login store never go to an endpoint object.

An unknown typesafeBackend name, or an object the judge refuses, no longer
silently falls back to typesafe: judgments turn off with the refusal message
shown once and in /warden status, and nothing is sent to api.typesafe.ai
because a value was mistyped.
@DevMortimer
DevMortimer merged commit b3a43df into main Sep 28, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat: configurable judgment endpoint (custom base URL, key and model id) instead of two hardcoded backends

1 participant