Back to Codexbar

Provider plugin conversion matrix

docs/plugin-conversion-matrix.md

0.49.012.1 KB
Original Source

Provider plugin conversion matrix

This matrix evaluates all 68 providers in the current capability audit against the prototype documented in plugin-prototype.md. Each provider has one primary blocker.

convertible-now means the canonical first-party flow is GET-only, uses a fixed HTTPS origin and header secret, and fits the generic snapshot. Optional canonical-origin endpoint overrides do not change that bucket; providers whose identity is inherently a user-chosen origin (LLM Proxy and LiteLLM) do not qualify. The convertible rows were checked against the current Swift request methods and snapshot projections; Azure OpenAI, StepFun, and Warp were removed from the audit's earlier “fully expressible” baseline because their current implementations issue POST requests.

converted means the bundled JavaScript conversion is present behind CODEXBAR_JS_PROVIDERS=1. cut-over means the bundled script is the only JavaScriptCore implementation, with any retained native core serving Linux only. The Converted column makes implementation state explicit and the totals are mutually exclusive: convertible-now counts only providers that remain cheap to convert. Remaining buckets name the next blocker after this host-extension slice.

needs-host-extension means an existing native behavior cannot be represented without changing provider semantics or weakening the plugin network policy.

Totals

StatusCount
cut-over11
converted5
convertible-now10
needs-cookie-import19
needs-files/subprocess/oauth-broker15
needs-pty/webview/native8
needs-host-extension0
Total68

Matrix

ProviderStatusConvertedReason
codexneeds-pty/webview/nativeNoPTY CLI, OAuth files/refresh, browser cookies, WKWebView scraping, local logs, and reset-credit details exceed this host.
openaiconvertedYesConverted: fixed-origin bearer GET pagination with daily spend, model, line-item, and token details.
azureopenaineeds-pty/webview/nativeNoThe current quota probe is a POST chat completion against a user-configured deployment origin.
claudeneeds-files/subprocess/oauth-brokerNoFull parity needs credential files/Keychain, OAuth refresh, CLI/PTY, cookies, local logs, and admin details.
fireworksconvertible-nowNoIdentity can now carry the successful empty-billing state without inventing a rate window or cost.
clinepasscut-overYesCut over on both engines: fixed-origin bearer GET, typed quota lanes, credential aliases, and classified failures match native behavior; the Swift fetcher and Linux fixtures are deleted.
cursorneeds-cookie-importNoBrowser cookies/app database provide auth, and integer request history also has bespoke detail.
opencodeneeds-cookie-importNoSkipped: React server-function response parsing needs a protocol-specific text decoder beyond matchFirst.
opencodegoneeds-files/subprocess/oauth-brokerNoLocal auth/SQLite state and browser sessions are required, with an additional bespoke usage model.
alibabaneeds-cookie-importNoThe console path needs imported cookies, CSRF/sec-token discovery, redirects, and embedded response parsing.
alibabatokenplanneeds-cookie-importNoFull parity depends on Aliyun console cookies, CSRF/sec-token acquisition, and several dependent calls.
qwencloudneeds-cookie-importNoSkipped: CSRF plus form POST and redirect-aware routing are not covered by JSON POST.
factoryneeds-cookie-importNoWorkOS/browser cookies and local storage recover the session; the API-key-only path is merely partial.
geminineeds-files/subprocess/oauth-brokerNoGemini CLI credential/config files, Google OAuth refresh, and a curl fallback own the current flow.
antigravityneeds-pty/webview/nativeNoProcess/port discovery, localhost IDE RPC, OAuth files, and a persistent PTY make this a native integration.
copilotneeds-cookie-importNoAPI-token usage fits, but billing budgets require GitHub cookies/nonces and the device flow needs POST.
devinneeds-files/subprocess/oauth-brokerNoFull auth discovery reads Chromium localStorage and organization state; manual bearer alone is partial.
zaicut-overYesCut over on both engines: regional and validated override endpoints, personal/team settings, quota lanes, model totals, and hourly/daily token charts; dashboard routing remains native and the fetch twin is deleted.
minimaxneeds-cookie-importNoBrowser cookies/storage and group discovery feed a large service/billing/history-specific payload.
manusconvertedYesConverted: declared-domain cookie import, session-token extraction, JSON POST, and generic credit windows.
kimineeds-cookie-importNoBrowser cookies plus Kimi credential/device files and regional identity headers exceed the current broker.
kiloneeds-files/subprocess/oauth-brokerNoThe default source reads Kilo's local auth file and organization metadata.
kironeeds-pty/webview/nativeNoUsage exists only through bounded CLI pipe/PTY automation and a bespoke credit/overage model.
vertexaineeds-files/subprocess/oauth-brokerNoADC/gcloud files, OAuth refresh, optional subprocess fallback, and local cost logs are required.
augmentneeds-files/subprocess/oauth-brokerNoThe preferred strategy spawns auggie; the alternative imports browser cookies and maintains sessions.
jetbrainsneeds-pty/webview/nativeNoThere is no HTTP strategy; native IDE discovery and local XML parsing are the provider.
moonshotconvertible-nowNoBalance can remain intentionally identity-only, matching the native sparse snapshot.
ampneeds-files/subprocess/oauth-brokerNoCLI subprocess and browser-cookie strategies plus workspace credit details are outside this host.
t3chatconvertedYesConverted: declared-domain cookie import, JSONL text parsing, and generic base/overage windows.
ollamaneeds-cookie-importNoSkipped: hosted parity requires HTML bootstrap/state extraction plus API-key fallback arbitration.
syntheticcut-overYesCut over on both engines: fixed-origin bearer GET with generic windows, cost, dates, and identity; the native fetch twin is deleted.
warpneeds-pty/webview/nativeNoWarp sends a POST GraphQL operation, which the GET-only HTTP broker cannot express.
openroutercut-overYesCut over on JavaScriptCore: endpoint and client-header overrides plus one-second best-effort key enrichment match native behavior; the native fetch core is Linux-only.
elevenlabsconvertible-nowNoVerified xi-api-key GET; heterogeneous character/minute quotas map to named generic windows.
windsurfneeds-files/subprocess/oauth-brokerNoChromium localStorage, IDE databases, and binary protobuf decoding supply the current session.
zedneeds-files/subprocess/oauth-brokerNoZed server settings and a named Keychain credential must be read locally.
perplexityconvertedYesConverted: declared-domain cookie import and generic recurring, bonus, and purchased credit windows.
mimoneeds-cookie-importNoBrowser/Firefox session import and a local cache feed balance, plan, and token-specific details.
doubaoneeds-files/subprocess/oauth-brokerNoFull parity needs a CLI subprocess or Volcengine HMAC signing and POST-based plan calls.
sakananeeds-cookie-importNoSkipped: app-owned wiring and PAYG detail fixtures are outside the core descriptor seam.
abacusneeds-cookie-importNoSkipped: exact calendar-month window parity needs a host date helper not in this slice.
mistralneeds-cookie-importNoSkipped: CSRF discovery and dependent wallet, credit-note, and model-history calls exceed the minimal broker.
deepseekneeds-files/subprocess/oauth-brokerNoPlatform auth/profile selection reads Chromium localStorage, and the result has a bespoke history model.
deepinfraconvertible-nowNoVerified fixed-origin bearer GET pair; spend limit and balance project into generic cost/windows.
codebuffneeds-files/subprocess/oauth-brokerNoFull credential parity reads a local Manicode credential file; environment-key mode is partial.
crofcut-overYesCut over on JavaScriptCore: fixed-origin bearer GET with exact credit formatting and America/Chicago daily reset; native fetch code is Linux-only.
venicecut-overYesCut over on JavaScriptCore: fixed-origin bearer GET with DIEM/USD allocation projection; native fetch code is Linux-only.
commandcodeneeds-cookie-importNoSkipped: live subscription/depletion flags lack reconstructable fixtures within the per-provider cap.
qoderconvertedYesConverted: declared global/China cookie domains, browser headers, and merged generic quota window.
stepfunneeds-files/subprocess/oauth-brokerNoDevice registration, password login, refresh, quota, and plan operations are POST-based token-broker work.
bedrockneeds-files/subprocess/oauth-brokerNoAWS profiles/CLI credentials, SigV4 signing, pagination, and two services need host-owned credential/signing APIs.
grokneeds-pty/webview/nativeNoPersistent stdio JSON-RPC, auth/session files, cookies, logs, and binary gRPC-web are strongly native.
groqneeds-cookie-importNoSkipped: Stytch session exchange and console history remain a multi-step auth flow.
llmproxyconvertible-nowNoSettings origins now preserve native HTTPS/public and approved private-network HTTP behavior.
litellmconvertible-nowNoSettings origins now preserve native private-network HTTP behavior, and zero-spend identity-only snapshots are valid.
deepgramcut-overYesCut over on JavaScriptCore: project discovery, aggregation, configured origins, numeric validation, and classified auth/permission/rate/network/API/parse failures match native behavior; the native fetch core is Linux-only.
poecut-overYesCut over on both engines: fixed-origin bearer GET balance/history pagination with daily points and model/type summaries; the native fetch twins are deleted.
chutesconvertible-nowNoTolerant no-usage payloads can return an API identity without inventing quota data.
neuralwattconvertible-nowNoClassified transient failures can request the same single delayed retry and capped Retry-After behavior as native.
clawroutercut-overYesCut over on JavaScriptCore: validated configured origins, classified failures, exact confidence, budget/ledger details, and provider charts match native behavior; the native fetch core is Linux-only.
longcatneeds-cookie-importNoSkipped: browser-cookie retry needs domain/path-aware cookie selection across multiple imported sessions; the generic broker currently returns one flattened header.
sub2apicut-overYesCut over on JavaScriptCore: configured HTTPS/loopback origins, a hard 15-second request deadline, strict parsing, exact confidence, and classified failures match native behavior; the native fetch core is Linux-only.
wayfinderneeds-pty/webview/nativeNoThe local unauthenticated HTTP gateway, metrics text, and routing/savings model violate HTTPS-only generic scope.
zenmuxconvertible-nowNoVerified fixed-origin bearer GET pair; subscription and optional PAYG balance map generically.
aiandconvertible-nowNoAn empty 30-day log window can omit unknowable currency and return its API identity.
zoommateneeds-cookie-importNoSkipped: cookie-to-JWT exchange plus paginated history requires provider-specific retry state.
xaicut-overYesCut over on both engines: bearer GET balance plus best-effort JSON POST history and billing details; the native fetch twins are deleted.
notionneeds-cookie-importNoWorkspace selection and AI allowance calls require imported Notion cookies and forwarded session headers.