{"record":{"id":"1cc76cbc7a058e91","repo":"Hmbown/CodeWhale","slug":"resolved-a-different-provider","errorCode":null,"errorMessage":"resolved a different provider","messagePattern":"resolved a different provider","errorType":"console","errorClass":null,"httpStatus":null,"severity":"error","filePath":"crates/cli/src/credential_handoff.rs","lineNumber":35,"sourceCode":"    // SAFETY: this one-shot CLI exits before another command can inherit it.\n    unsafe {\n        let _ = libc::signal(libc::SIGPIPE, libc::SIG_IGN);\n    }\n    Ok(())\n}\n\npub(crate) fn resolve_api_key(\n    store: &ConfigStore,\n    secrets: &Secrets,\n    provider: ProviderKind,\n    runtime_overrides: &CliRuntimeOverrides,\n) -> Result<String> {\n    let resolved = store.config.resolve_runtime_options_with_secrets(\n        &runtime_overrides_for_provider(runtime_overrides, provider),\n        secrets,\n    );\n    if resolved.provider != provider {\n        bail!(\"resolved a different provider\");\n    }\n    let source = resolved.api_key_source;\n    if source != Some(RuntimeApiKeySource::Cli) {\n        if provider == ProviderKind::OpenaiCodex {\n            bail!(\"bearer credentials are not an API key\");\n        }\n        let uses_api_key = provider != ProviderKind::Xai\n            || xai_auth_diagnostics(store, runtime_overrides).evaluates_runtime_api_key();\n        ensure!(uses_api_key, \"OAuth bearer credentials are not an API key\");\n        let kimi_bearer = provider == ProviderKind::Moonshot\n            && resolved\n                .auth_mode\n                .as_deref()\n                .is_some_and(auth_mode_uses_kimi_imported_token);\n        ensure!(!kimi_bearer, \"bearer credentials are not an API key\");\n    }\n    ensure!(source.is_some(), \"no runtime-effective API key\");\n    resolved","sourceCodeStart":17,"sourceCodeEnd":53,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/73e0f67d83c59909b571efdfc88c4bc28c309cb1/crates/cli/src/credential_handoff.rs#L17-L53","documentation":"resolve_api_key resolves runtime options for a specific provider and asserts the resolution still selects that provider. If resolve_runtime_options_with_secrets returns a different provider (config routing/overrides redirected the slot), the result would be a key for the wrong provider, so the handoff refuses with this error.","triggerScenarios":"Calling the credential handoff (api_key subcommand) with a provider argument while the config's routing table / model aliases / runtime overrides resolve that request to a different ProviderKind — e.g. a default-provider or alias override masks the requested provider.","commonSituations":"A model_alias or provider override in config.toml routes requests to another provider; ambient config edited after the CLI arg was chosen; requesting `api_key xai` while config defaults to openrouter, etc.","solutions":["Fix the config so the requested provider is actually selected: remove/adjust conflicting model_alias or provider overrides for the invoked route.","Pass explicit runtime overrides on the command so resolution cannot be redirected (the code scopes overrides per provider via runtime_overrides_for_provider).","Run the resolution/diagnostic command to print which provider the config resolves to, then request the API key for that provider."],"exampleFix":"// before (config.toml)\n[providers]\ndefault = \"openrouter\"  # redirects the xai request\n// after\ncodewhale config set providers.default xai\ncodewhale credential api-key xai","handlingStrategy":"validation","validationCode":"let resolved = store.config.resolve_runtime_options_with_secrets(\n    &runtime_overrides_for_provider(&overrides, provider), &secrets);\nif resolved.provider != provider {\n    eprintln!(\"config routes this request to {:?}, not {:?}\", resolved.provider, provider);\n}\n","typeGuard":"fn resolves_to(provider: ProviderKind, resolved: &ResolvedOptions) -> bool { resolved.provider == provider }","tryCatchPattern":"match resolve_api_key(&store, &overrides, provider) {\n    Err(e) if e.to_string() == \"resolved a different provider\" => {\n        eprintln!(\"fix model_alias/provider overrides so the requested provider is selected\");\n    }\n    other => other,\n}","preventionTips":["Audit model_alias and default-provider overrides before requesting keys for a specific provider.","Pass explicit per-provider runtime overrides to bypass ambient routing.","Print the resolved provider in scripts before credential handoff."],"tags":["credentials","provider-routing","config","resolution"],"backgroundTag":"type-mismatch","analyzedSha":"73e0f67d83c59909b571efdfc88c4bc28c309cb1","analyzedAt":"2026-09-22T01:30:00.501Z","contentChangedAt":"2026-09-22T01:30:00.501Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}