--- id: SMH-PLAN-AIAGD002 type: plan title: "Provider and OAuth Plugins" spec: SMH-SPEC-PLUG0001 status: draft depends_on: [] --- # Provider and OAuth Plugins ## Outcome Every supported vendor ships as an unprivileged per-family plugin. Users log in with a Z.ai key and with OpenAI, Anthropic, and Google subscriptions; provider-specific code is gone from the core. ## Scope Per-family provider plugins, the shared OAuth plugin, plugin-to-plugin dependencies, and core adapter removal. Host surface and scaffolding come from the harness plan. ## Behaviors Ordered by delivery value. 1. **Z.ai provider plugin**: key credential from the auth store, OpenAI-compatible stream behind the plugin boundary; one eval turn runs end to end with the core adapter absent from the dispatch path. 2. **OAuth plugin**: device or localhost-redirect flows through net-scope effects; tokens cross the secret-proxy boundary to the auth store; renewal refreshes before dispatch. 3. **Plugin dependency**: provider plugins declare a dependency on the OAuth plugin's major-versioned module contract; the harness validates the complete set before publication; missing or ambiguous bindings fail at consumption with sorted candidates. 4. **OpenAI plugin**: subscription login via the OAuth plugin plus key support; provider registration advertises models with capabilities. 5. **Anthropic plugin**: subscription login plus key support; wire format and model catalog live in the plugin. 6. **Google plugin**: subscription login plus key support; same registration path. 7. **Core adapter removal**: native vendor decoders and vendor catalogs are deleted; mux routes plugin-registered providers; conformance fixtures validate plugin streams against recorded transcripts. ## Login surface ```mermaid flowchart LR U["smith login --provider VENDOR"] --> O{"flow?"} O -- key --> K["auth store (stdin secret)"] O -- subscription --> P["oauth plugin flow"] P --> N["net-scope http"] N --> SP["secret-proxy exchange"] SP --> S["auth store"] K --> R["resolve before dispatch"] S --> R ``` ## Plan dependencies ```mermaid flowchart LR PLUG["PLUG0001 harness + scaffolding"] --> Z["zai plugin"] Z --> OA["oauth plugin"] OA --> DEP["plugin dependency validation"] DEP --> OAI["openai"] DEP --> ANT["anthropic"] DEP --> GOO["google"] OAI --> RM["remove core adapters"] ANT --> RM GOO --> RM ``` ## Interfaces - `plugins/provider-zai`, `plugins/provider-openai`, `plugins/provider-anthropic`, `plugins/provider-google`. - `plugins/oauth`: exports the credential-source module contract. - `smith login`: vendor login command over key or subscription flows. ## Verification - Each vendor completes one eval round using only its plugin-registered provider. - Subscription credentials renew before expiry without re-login. - A provider plugin missing its OAuth dependency fails at consumption with the consumer and candidates named. - No native vendor decoder remains; conformance validates each plugin stream against recorded transcripts. - Credential plaintext never appears in logs, traces, replay, or plugin diagnostics. - Embedded built-in provider artifacts update without a smith rebuild in dev configurations. ## Stop conditions - A vendor requires an effect absent from the public world. - OAuth flows cannot complete without ambient capabilities beyond net-scope and secret-proxy. - Plugin dependency validation cannot reject incomplete sets atomically.