# Provider guide
Provider construction, request serialization, HTTP transport, catalogs and stream assembly.
## Where to look
| Selection validation and construction | `factory.rs` |
| Request/conversation types | `request.rs`; shared `Provider` trait: `openai.rs` |
| Codex/compatible endpoints | `openai/codex.rs`, `openai/compatible.rs` |
| Bodies/headers/catalogs | `openai/{bodies,headers,catalog}.rs` |
| Anthropic Messages | `anthropic.rs`, `anthropic/stream.rs` |
| Claude CLI relay/admission/inert MCP/replay | `claude_subscription.rs`, `claude_admission.rs`, `claude_inert.rs`, `claude_projection.rs` |
| Attempts/semantic timeout vs byte-idle transport | `openai_stream.rs` / `transport.rs` |
| SSE and Chat/Responses assembly | `sse.rs`, `stream.rs`, `stream/` |
| Duplicate-skill overlay / turn routing / live quota | `skill_projection.rs` / `codex_session.rs` / `codex_usage.rs` |
## Local contracts
- Preparation selects provider; factory validates/builds it. Keep provider-family auth headers separate and Chat Completions/Responses body builders distinct.
- Claude subscription authenticates only through installed `claude` CLI, separate from Anthropic API keys. Relay admits one official Messages request; native headers stay memory-only. Cancellation closes sockets/process tree; inert native MCP never executes tools. Validate complete upstream stop/usage before events and preserve ordered host replay.
- Codex web search uses `openai/codex/web_search.rs` and existing transport/auth refresh. Bound raw SSE, require `response.completed`, retain citations and distinguish synthesis from page content. No experimental endpoint or Exa fallback.
- Codex replay replaces null role content with space, removes role `tool_calls` and reasoning/function-call `id`/`status` while retaining calls/outputs and identity.
- Preparation gates primary reasoning updates. Durable `ProviderConversationItem::ReasoningSelection` projects eligible ordered `configuration_update` items with original effort; body builders omit unprojected selections.
- Duplicate-skill replacement is request-owned overlay with validated earlier witnesses and serializer call-ID filtering. Retain raw storage, rebuild after conversation changes; no disk reads or cross-request availability state.
- Fast tier/routing diagnostics alone are not semantic progress. Preserve partial arguments, call IDs, response order and terminal events; bound event/argument buffers. Retry policy belongs above parsers.
- Distinguish byte-idle from semantic-progress failure; honor workload-specific configured timeouts. Redact catalog/wire diagnostics; terminal streaming boundaries belong to output owners.
- Codex routing is turn-scoped: conversation session ID stays stable, children distinct, server turn state private/bounded and unchanged across retries. Reset on turn/account changes; never persist state or salts. Prefix diagnostics are local-only.
- Quota uses stored Codex OAuth, bounded direct HTTP and one refresh on 401; never substitute cached quota after failure.
Request-body profiling: `openai/profiling.rs`; shared parser workload: `../profiling/profile_harness/cpu.rs`. Neither establishes live auth/stream behavior.