Skip to content

feat: --base-url for any OpenAI-compatible endpoint - #10

Merged
x1xhlol merged 1 commit into
mainfrom
feat/base-url
Sep 25, 2026
Merged

x1xhlol merged 1 commit into
mainfrom
feat/base-url

Conversation

@x1xhlol

@x1xhlol x1xhlol commented Sep 25, 2026

Copy link
Copy Markdown
Member

Adds a --base-url flag (same as OPENAI_BASE_URL) so a scan can run against any server that speaks the OpenAI chat completions API: Ollama, vLLM, LM Studio, llama.cpp, LiteLLM, Azure, Together, Groq.

Before this, OPENAI_BASE_URL only applied to ids that looked like OpenAI models (gpt-*, o3-*, openai/*) and only when OPENAI_API_KEY was set. A local llama3.1:8b went to OpenRouter instead.

Routing

With a base URL set:

  • No OpenRouter key: every model goes to the endpoint, whatever its id.
  • OpenRouter key set: OpenAI-style ids go to the endpoint and the rest go to OpenRouter. Prefix an id with openai/ to force it to the endpoint; the prefix is stripped, so openai/llama3.1:8b arrives as llama3.1:8b.
  • No OPENAI_API_KEY is needed. Keyless local servers work.

Without a base URL, nothing changes.

zeroleaks scan -f ./prompt.txt --base-url http://localhost:11434/v1 \
  --attacker-model llama3.1:70b --target-model llama3.1:8b \
  --evaluator-model llama3.1:70b

The CLI rejects a --base-url that isn't an http(s) URL before scanning, and shows the endpoint in the scan configuration box.

Behavior change

If you already set OPENAI_BASE_URL without an OpenRouter key, non-OpenAI ids now go to that endpoint instead of to OpenRouter. Before, those calls failed for lack of an OpenRouter key, so nothing that used to work breaks. The e2e test "the models named on screen are the models tested" relied on that failure. It now checks that the requests the mock receives use the models shown on screen.

Tests

New e2e tests against the mock server, using ids that don't look like OpenAI's:

  • --base-url with no keys sends every model to the endpoint, and the scan completes as secure.
  • With an OpenRouter key, openai/-prefixed ids still reach the endpoint with the prefix stripped.
  • A non-http --base-url is rejected before any request.

bun run lint, bun run typecheck, bun test (34 pass) and bun run build all pass locally.

--base-url (or OPENAI_BASE_URL) now works with any server that speaks
the OpenAI chat completions API, not just ones serving OpenAI-style ids.
With no OpenRouter key every model goes to the endpoint; with one, only
OpenAI-style and openai/-prefixed ids do. Keyless local servers work.
@x1xhlol
x1xhlol merged commit 5342451 into main Sep 25, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant