Skip to main content
Document scan, Flow setup and Flow generation call a model. A Flow run does not, unless you turn on the optional visual judge. There are two ways a server reaches the model:

Workspace provider

Open Settings › Models and fill in the form: Press Test & save. The server makes a live call to the provider before it stores anything, and a refusal comes back in the provider’s own words. Once saved, the page shows the provider, the model, the key’s masked tail and when it was updated. To keep the stored key, leave API key blank. That works only while the provider stays the same. Switching providers needs a new key. The key is stored encrypted under TRUECOURSE_SECRET_KEY. The server checks the provider again before every run. A run in a workspace with no provider is refused, and the app points you to Settings. A provider that fails the check is reported with its own message. The credentials travel with the run that asked for them, and never become a default for the whole server.

Operator mode

Set TRUECOURSE_LLM_TRANSPORT=claude-code in the server’s environment. Every workspace then runs on the claude login of the server process. The Models page becomes read-only. It shows Claude Code (operator), the model, and the variable that set it. Operator mode is for a self-hosted instance with a single operator. Never set it on a deployment that serves other people’s workspaces. The machine that runs the server needs Claude Code installed and signed in. If the binary is not claude on the PATH, set CLAUDE_CODE_BINARY to its path. CLAUDE_CODE_BIN is accepted too. In operator mode, agent sessions run on Opus. The steps that make a single call run on per-stage tiers you can override. See Models & environment.

Next steps

Models & environment

Which model runs where, and the environment variables that tune runs.

Storage

How the provider key is encrypted and kept.