pub struct AuthConfig {
pub mode: AuthMode,
pub api_key_header: Option<String>,
pub token_command: Option<String>,
pub tenant_id: Option<String>,
pub client_id: Option<String>,
pub client_secret: Option<String>,
pub scope: Option<String>,
pub token_url: Option<String>,
pub cache_ttl_secs: Option<u64>,
}Expand description
Authentication settings for an LLM endpoint.
Fields§
§mode: AuthModeWhich authentication mode to use. Default: api-key.
api_key_header: Option<String>Header name that receives the API key instead of
Authorization: Bearer (mode = "api-key"). For example the Azure
OpenAI api-key header.
token_command: Option<String>Command whose stdout (first line) is used as the bearer token
(mode = "token-command").
tenant_id: Option<String>Entra tenant id (mode = "entra-client-credentials",
"entra-managed-identity").
client_id: Option<String>Entra client id (mode = "entra-client-credentials").
client_secret: Option<String>Entra client secret (mode = "entra-client-credentials").
scope: Option<String>Entra token scope. Defaults to
https://cognitiveservices.azure.com/.default.
token_url: Option<String>Override for the Entra token endpoint
(mode = "entra-client-credentials"), default
https://login.microsoftonline.com. Also used as the IMDS identity
endpoint base for "entra-managed-identity" (default
http://169.254.169.254). Mainly useful for tests and proxies.
cache_ttl_secs: Option<u64>Seconds to reuse a fetched (non-API-key) token before refetching. For Entra modes the server-issued expiry is used when available; this caps the reuse window. Default 300.