Problem
Model exclusions remove a model from the listing and from routing. Verified on eceasy/cli-proxy-api:v7.3.6 with:
oauth-excluded-models:
codex:
- "*"
GET /v1/models no longer lists the codex models (intended) ✅
- but the models also stop being routable:
POST /v1/responses {"model":"codex-go/gpt-5.6-sol", ...} fails with unknown provider for model codex-go/gpt-5.6-sol ❌
Same behaviour with the per-credential form (codex-api-key[].excluded-models).
Why a listing-only variant is needed
A gateway that builds its catalogue from discovery cannot afford that trade-off. Concretely: Bifrost's model catalogue is union(upstream /v1/models, its own datasheet), so hiding another channel's models from the catalogue currently requires excluding them (breaking the calls) or disabling list_models for the provider (which also removes the models from the gateway's own /v1/models). There is no way to keep a clean catalogue and keep every model callable by clients that hardcode model names.
Proposal
Any of these would work:
- A
listing-only flag on an exclusion entry:
oauth-excluded-models:
codex:
- model: "*"
listing-only: true
-
A separate option with the same shape as oauth-excluded-models, e.g. oauth-hidden-models, whose entries are filtered out of listings only.
-
Same for the per-credential excluded-models.
Current workaround
None that keeps both the catalogue clean and the models callable.
Problem
Model exclusions remove a model from the listing and from routing. Verified on
eceasy/cli-proxy-api:v7.3.6with:GET /v1/modelsno longer lists the codex models (intended) ✅POST /v1/responses {"model":"codex-go/gpt-5.6-sol", ...}fails withunknown provider for model codex-go/gpt-5.6-sol❌Same behaviour with the per-credential form (
codex-api-key[].excluded-models).Why a listing-only variant is needed
A gateway that builds its catalogue from discovery cannot afford that trade-off. Concretely: Bifrost's model catalogue is
union(upstream /v1/models, its own datasheet), so hiding another channel's models from the catalogue currently requires excluding them (breaking the calls) or disablinglist_modelsfor the provider (which also removes the models from the gateway's own/v1/models). There is no way to keep a clean catalogue and keep every model callable by clients that hardcode model names.Proposal
Any of these would work:
listing-onlyflag on an exclusion entry:A separate option with the same shape as
oauth-excluded-models, e.g.oauth-hidden-models, whose entries are filtered out of listings only.Same for the per-credential
excluded-models.Current workaround
None that keeps both the catalogue clean and the models callable.