Files
9router/src/lib/oauth/constants/xai.js
T
Muhammad Mugni HadiandCursor d976f4cc87 feat(xai): add xAI Grok provider with OAuth + API key auth + image
Adapted from PR #1286 (mugnimaestra/feat/xai-grok-provider) to match
existing app architecture. Includes:

- OAuth 2.0 with PKCE on loopback port 56121 (Grok Build)
- API key auth path (console.x.ai)
- Token refresh wiring (open-sse + sse tokenRefresh)
- Dashboard OAuth modal with fixed-port flow + manual code fallback
- Provider registry entries (OAuth + API key)
- xAI image generation via OpenAI-compatible adapter
  (grok-2-image-1212 model, no size/quality/style params)

Excludes (intentionally, to match app patterns):
- Custom xAI Responses executor (DefaultExecutor handles /chat/completions)
- xAI-specific translators (app uses OpenAI as intermediate format)
- Image edits (not supported by current imageGenerationCore)
- Video endpoints (app has no video subsystem yet)
- CLI xai-login command

Refs decolua#1286

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-21 11:33:18 +07:00

62 lines
2.3 KiB
JavaScript

/**
* xAI (Grok) OAuth Configuration
*
* Source of truth: router-for-me/CLIProxyAPI internal/auth/xai/types.go
* Mirrors the upstream Go constants 1:1.
*/
// xAI client_id for OAuth (PKCE public client)
export const XAI_CLIENT_ID = "b1a00492-073a-47ea-816f-4c329264a828";
// OAuth issuer + endpoints
export const XAI_ISSUER = "https://auth.x.ai";
export const XAI_AUTH_ENDPOINT_PATH = "/oauth2/authorize";
export const XAI_TOKEN_ENDPOINT_PATH = "/oauth2/token";
export const XAI_DISCOVERY_PATH = "/.well-known/openid-configuration";
// Scopes (space-separated, matches Go upstream)
export const XAI_SCOPE = "openid profile email offline_access grok-cli:access api:access";
// xAI inference API base URL
export const XAI_API_BASE = "https://api.x.ai/v1";
// Loopback callback (PKCE)
export const XAI_LOOPBACK_PORT = 56121;
export const XAI_CALLBACK_PATH = "/callback";
export const XAI_REDIRECT_URI = `http://127.0.0.1:${XAI_LOOPBACK_PORT}${XAI_CALLBACK_PATH}`;
// PKCE verifier length (bytes pre-base64url)
export const XAI_PKCE_VERIFIER_BYTES = 96;
// Refresh tokens this many seconds before expiry
export const XAI_REFRESH_LEAD_SECONDS = 5 * 60;
// User-Agent — mirror Go grok-cli UA. Version is best-effort; xAI does not pin a specific version.
export const XAI_USER_AGENT = "grok-cli/9router";
/**
* Aggregated config object — mirrors the shape of CLAUDE_CONFIG/CODEX_CONFIG in oauth.js.
* Includes both the discovery-derived defaults and the static fallbacks used when
* discovery is unavailable. Discovery results override authorizeUrl/tokenUrl at runtime.
*/
export const XAI_CONFIG = {
clientId: XAI_CLIENT_ID,
issuer: XAI_ISSUER,
authEndpointPath: XAI_AUTH_ENDPOINT_PATH,
tokenEndpointPath: XAI_TOKEN_ENDPOINT_PATH,
discoveryPath: XAI_DISCOVERY_PATH,
// Static fallbacks (these are also the values returned by xAI discovery today)
authorizeUrl: `${XAI_ISSUER}${XAI_AUTH_ENDPOINT_PATH}`,
tokenUrl: `${XAI_ISSUER}${XAI_TOKEN_ENDPOINT_PATH}`,
discoveryUrl: `${XAI_ISSUER}${XAI_DISCOVERY_PATH}`,
scope: XAI_SCOPE,
apiBaseUrl: XAI_API_BASE,
redirectUri: XAI_REDIRECT_URI,
loopbackPort: XAI_LOOPBACK_PORT,
callbackPath: XAI_CALLBACK_PATH,
pkceVerifierBytes: XAI_PKCE_VERIFIER_BYTES,
refreshLeadSeconds: XAI_REFRESH_LEAD_SECONDS,
userAgent: XAI_USER_AGENT,
codeChallengeMethod: "S256",
};