Skip to main content

AI providers and models

← Back to Index | Previous: Enterprise roles and access


This chapter expands §8.5 AI models and keys. It documents shipped behaviour on the Enterprise workspace page only — not Control’s scaffold Configuration → AI Models & Keys entry.

13.1 Overview​

ItemDetail
Wherehttps://<dai-host>/dashboard/enterprise/ai-models — Enterprise → AI providers & models
WhoEnterprise deployment and platform super admin (others receive 404)
TabsProvider connections (deployment-wide) · Models (catalog + chat picker) · Team keys (BYOK) (per-team OpenAI / Anthropic / Google)

Provider connection vs team key

PathUse forEnterprise default
Provider connectionBedrock, Azure OpenAI, Vertex AI, Custom gatewayCanonical for platform operators configuring models before chat
Team key (BYOK)Per-team OpenAI, Anthropic, Google keysSecondary — team admins manage their own keys; Bedrock is not a team key

If an operator tries to add Bedrock under Team keys, the product rejects it and directs them to Provider connections.

How a model reaches chat: connection → catalog row on Models → Sync now (registers in the LLM proxy) → Test (one real completion) → row appears in the chat picker.

13.2 Choosing a provider​

KindCredentialDiscover on Models tabUpstream prefix (LiteLLM)
Custom gatewayGateway API keyYes — GET {api_base}/modelsopenai/<id> added on sync (do not type openai/ yourself when adding manually)
BedrockIAM keys or host roleNo — Add model or Bulk importbedrock/… or bedrock_mantle/… (enforced at save)
Azure OpenAIAPI key + API versionNo — Add model or Bulk importazure/<deployment> (hint only — wrong value fails at Test)
Vertex AIService-account JSONNo — Add model or Bulk importvertex_ai/<model> (hint only)

OpenAI, Anthropic, and Gemini without a customer gateway are team keys, not provider connections.

13.3 Bedrock​

13.3.1 Connect on Provider connections​

  1. Add connection → Bedrock
  2. Set Region to match where models are enabled in AWS
  3. Provide IAM access keys or choose host/environment credentials when LiteLLM runs on AWS compute with an instance profile
  4. Test connection checks field shape and decrypts stored credentials — it does not call AWS Bedrock. A green connection tick is not proof of invoke access; use Test on each model row.

Minimum IAM for invoke (region-scoped ARNs on foundation models):

  • sts:GetCallerIdentity
  • bedrock:InvokeModel
  • bedrock:InvokeModelWithResponseStream (required for streaming chat)

13.3.2 Model access — commercial vs GovCloud​

Listing ≠ entitlement. A model can appear in a catalog or Discover list and still fail chat until AWS account access is granted.

PartitionHow to enable model access
Commercial AWSGrant Marketplace permissions (aws-marketplace:Subscribe, aws-marketplace:ViewSubscriptions). Bedrock auto-enables many models on first invoke (allow ~15 minutes). Anthropic models may need a one-time first-use form. Do not use the Bedrock console Model access page — AWS documents it as GovCloud-focused.
AWS GovCloud (US)Bedrock console → Model access — enable each model, per region

IAM invoke permission and model entitlement are separate grants; you need both.

13.3.3 Register models​

Discover is not available for Bedrock in the current release. Use Add model or Bulk import:

FieldValue
Model IDDeslicer catalog slug (e.g. bedrock-claude-4-6-sonnet) or a typed Bedrock / inference-profile id
Upstream modelProvider-prefixed Bedrock id (e.g. bedrock/anthropic.claude-sonnet-4-6-v1:0). Known slugs auto-fill upstream when left blank

Save rejects a catalog slug placed only in Upstream — the slug belongs in Model ID.

13.4 Custom gateway​

13.4.1 API base URL must include /v1​

On Provider connections → Custom gateway, the API base field is pass-through (only a trailing slash is stripped). Include the /v1 suffix yourself:

You enterDiscover callsResult
https://llm-gateway.example.comGET …/modelsUsually 404 on OpenAI-compatible gateways
https://llm-gateway.example.com/v1GET …/v1/modelsCorrect

Test connection uses the same base and succeeds only when {api_base}/models responds.

13.4.2 Manual model add​

Prefer Discover. When adding by hand, copy the exact id from GET {gateway}/v1/models into both Model ID and Upstream model. Deslicer adds the LiteLLM transport prefix on Sync now — do not type openai/ yourself.

Gateway listsType in both fields
gpt-5-nanogpt-5-nano
openai/gpt-5-nano (nested LiteLLM proxy)openai/gpt-5-nano

After a Deslicer AI update that changes custom-gateway prefix handling, run Sync now on affected rows so the proxy receives corrected upstream ids.

13.5 Upstream prefixes (reference)​

Connection kindUpstream formEnforced at save?
Bedrockbedrock/… or bedrock_mantle/…Yes
Custom gatewayGateway id; sync adds openai/ when neededRewritten on sync
Azure OpenAIazure/<deployment>No — fails at Test if wrong
Vertex AIvertex_ai/<model>No — fails at Test if wrong

Cross-region inference profiles use ids such as bedrock/eu.anthropic.claude-…. A bare foundation-model id can fail even when IAM and entitlement look correct — use the profile id AWS documents for your region when Test returns validation or not-found errors.

13.6 Publish and verify​

ActionWhat it proves
Test connection (connection card)Gateway: live GET …/models. Other kinds: credential shape only
Sync nowModel definitions are registered in the LLM proxy — no completion
Test (per model row)One real chat completion — only step that proves invokability
Chat pickerModel is enabled, synced, and allowed for the team’s plan tier

Order that works: Test connection → register models → Sync now → Test each row → confirm in chat.

13.7 Troubleshooting​

SymptomLikely causeFix
Bedrock save error: catalog slug in UpstreamSlug in wrong fieldPut slug in Model ID; upstream must be bedrock/…
Connection green, every model Test failsWrong region, missing entitlement, or wrong upstream idMatch AWS region; fix Marketplace / GovCloud model access; try inference-profile id
Model synced, chat failsSync ≠ verifyRun Test on the row; read AWS error name (IAM vs entitlement vs profile)
Discover 404, connection test passedapi_base missing /v1Set https://…/v1, re-test, Discover again
Listed or synced model fails in chatListed ≠ entitled, or inference profile requiredCommercial: Marketplace permissions; GovCloud: Model access page; retry with profile id
Custom gateway double-prefix errorsFriendly Model ID with different UpstreamUse gateway id in both fields; Sync now after product update
UI Test fails but cause unclearNeed LiteLLM-side /model/info + completion probeFrom /opt/deslicer/ai: bash scripts/enterprise/packaged/diagnose-litellm-model.sh <model_id> (§10.20)

For host-level LLM proxy diagnostics, run the support scripts in Chapter 10 §10.20 before contacting Deslicer Support (§10.21).

LiteLLM fallback noise at install​

Enterprise packaged LiteLLM may log fallback attempts into providers with no configured platform keys. That is a known configuration topic (#1583) — it does not mean your provider connection failed. Operator-managed models on this page are independent of those default fallback edges.


← Back to Index | Previous: Enterprise roles and access