AI providers
AI providers are the model backends agent work runs against: the credentials that power model routing, voice, and image/video for the workspace. Provider surfaces live at /ai/providers and /ai/agents/providers, with Models, Providers, and Gateways tabs. One credential per capability: model routing, voice, and image/video. Secret values are stored in GCP Secret Manager, never in this wiki. Cards read Ready (Manage) or Not connected (Connect); per-provider behavior beyond that is not documented in source yet.
- Provider wiring is platform work, not tenant config. Tenants feel providers through session behavior and availability, not through keys they hold.
- No password, API key, token, connection string, or private key goes in this wiki. Names of variables where source names them, values never.
- Session trouble that looks like a provider issue (slow, down, or empty externals) is handled the same way: output stays sane, the session degrades instead of wedging, and the pattern gets reported with examples.
- If provider-shaped trouble repeats, treat it as design feedback: narrow the scope, check the environment tool list, escalate with session references.

Grounding on the gateway-key step: Provisioning and internals. Model selection per workload: Model registry.

