id: SMH-PLAN-AIAGD002
type: plan
title: "Provider and OAuth Plugins"
spec: SMH-SPEC-PLUG0001
status: draft
depends_on: []
Provider and OAuth Plugins
Outcome
Every supported vendor ships as an unprivileged per-family plugin.
Users log in with a Z.ai key and with OpenAI, Anthropic, and Google subscriptions; provider-specific code is gone from the core.
Scope
Per-family provider plugins, the shared OAuth plugin, plugin-to-plugin dependencies, and core adapter removal.
Host surface and scaffolding come from the harness plan.
Behaviors
Ordered by delivery value.
Z.ai provider plugin: key credential from the auth store, OpenAI-compatible stream behind the plugin boundary; one eval turn runs end to end with the core adapter absent from the dispatch path.
OAuth plugin: device or localhost-redirect flows through net-scope effects; tokens cross the secret-proxy boundary to the auth store; renewal refreshes before dispatch.
Plugin dependency: provider plugins declare a dependency on the OAuth plugin's major-versioned module contract; the harness validates the complete set before publication; missing or ambiguous bindings fail at consumption with sorted candidates.
OpenAI plugin: subscription login via the OAuth plugin plus key support; provider registration advertises models with capabilities.
Anthropic plugin: subscription login plus key support; wire format and model catalog live in the plugin.
Google plugin: subscription login plus key support; same registration path.
Core adapter removal: native vendor decoders and vendor catalogs are deleted; mux routes plugin-registered providers; conformance fixtures validate plugin streams against recorded transcripts.
Login surface
flowchart LR
U["smith login --provider VENDOR"] --> O{"flow?"}
O -- key --> K["auth store (stdin secret)"]
O -- subscription --> P["oauth plugin flow"]
P --> N["net-scope http"]
N --> SP["secret-proxy exchange"]
SP --> S["auth store"]
K --> R["resolve before dispatch"]
S --> R
Plan dependencies
flowchart LR
PLUG["PLUG0001 harness + scaffolding"] --> Z["zai plugin"]
Z --> OA["oauth plugin"]
OA --> DEP["plugin dependency validation"]
DEP --> OAI["openai"]
DEP --> ANT["anthropic"]
DEP --> GOO["google"]
OAI --> RM["remove core adapters"]
ANT --> RM
GOO --> RM
---
id: SMH-PLAN-AIAGD002
type: plan
title: "Provider and OAuth Plugins"
spec: SMH-SPEC-PLUG0001
status: draft
depends_on: []
---
# Provider and OAuth Plugins
## Outcome
Every supported vendor ships as an unprivileged per-family plugin.
Users log in with a Z.ai key and with OpenAI, Anthropic, and Google subscriptions; provider-specific code is gone from the core.
## Scope
Per-family provider plugins, the shared OAuth plugin, plugin-to-plugin dependencies, and core adapter removal.
Host surface and scaffolding come from the harness plan.
## Behaviors
Ordered by delivery value.
1. **Z.ai provider plugin**: key credential from the auth store, OpenAI-compatible stream behind the plugin boundary; one eval turn runs end to end with the core adapter absent from the dispatch path.
2. **OAuth plugin**: device or localhost-redirect flows through net-scope effects; tokens cross the secret-proxy boundary to the auth store; renewal refreshes before dispatch.
3. **Plugin dependency**: provider plugins declare a dependency on the OAuth plugin's major-versioned module contract; the harness validates the complete set before publication; missing or ambiguous bindings fail at consumption with sorted candidates.
4. **OpenAI plugin**: subscription login via the OAuth plugin plus key support; provider registration advertises models with capabilities.
5. **Anthropic plugin**: subscription login plus key support; wire format and model catalog live in the plugin.
6. **Google plugin**: subscription login plus key support; same registration path.
7. **Core adapter removal**: native vendor decoders and vendor catalogs are deleted; mux routes plugin-registered providers; conformance fixtures validate plugin streams against recorded transcripts.
## Login surface
```mermaid
flowchart LR
U["smith login --provider VENDOR"] --> O{"flow?"}
O -- key --> K["auth store (stdin secret)"]
O -- subscription --> P["oauth plugin flow"]
P --> N["net-scope http"]
N --> SP["secret-proxy exchange"]
SP --> S["auth store"]
K --> R["resolve before dispatch"]
S --> R
```
## Plan dependencies
```mermaid
flowchart LR
PLUG["PLUG0001 harness + scaffolding"] --> Z["zai plugin"]
Z --> OA["oauth plugin"]
OA --> DEP["plugin dependency validation"]
DEP --> OAI["openai"]
DEP --> ANT["anthropic"]
DEP --> GOO["google"]
OAI --> RM["remove core adapters"]
ANT --> RM
GOO --> RM
```
## Interfaces
- `plugins/provider-zai`, `plugins/provider-openai`, `plugins/provider-anthropic`, `plugins/provider-google`.
- `plugins/oauth`: exports the credential-source module contract.
- `smith login`: vendor login command over key or subscription flows.
## Verification
- Each vendor completes one eval round using only its plugin-registered provider.
- Subscription credentials renew before expiry without re-login.
- A provider plugin missing its OAuth dependency fails at consumption with the consumer and candidates named.
- No native vendor decoder remains; conformance validates each plugin stream against recorded transcripts.
- Credential plaintext never appears in logs, traces, replay, or plugin diagnostics.
- Embedded built-in provider artifacts update without a smith rebuild in dev configurations.
## Stop conditions
- A vendor requires an effect absent from the public world.
- OAuth flows cannot complete without ambient capabilities beyond net-scope and secret-proxy.
- Plugin dependency validation cannot reject incomplete sets atomically.