Subscriptions and API channels
Connect subscriptions, official OpenAI APIs and OpenAI-compatible API services.
Codex, Claude, Antigravity and Grok Build subscription accounts support OAuth authorization and credential JSON import. Quota reporting covers Codex, Claude, Antigravity and Grok subscription periods. Previously stored accounts can be reauthorized, verified, enabled and assigned to workspace resource groups.
API channels
As a workspace administrator, open API channels → Add API channel. Enter a name, base URL and upstream API key. For official OpenAI use https://api.openai.com/v1. For a third-party service, include its required API prefix such as /v1, without appending /chat/completions, query parameters or credentials. Local HTTP services are supported.
After saving, Verify connection, inspect Models, add the channel to a resource group, grant member access and create a personal gateway key. Discovery reads {Base URL}/models; the service must expose an OpenAI-format model list and Chat Completions. Native model namespaces such as openai/model are preserved.
The pinned SDK converts existing Responses, Chat Completions, Claude Messages and Gemini client formats into upstream Chat Completions, with streaming and regular responses. Tool and reasoning capabilities depend on the upstream and conversion path. /v1/responses/compact remains Codex-only.
Keys are encrypted, never returned in channel metadata and never enter OAuth refresh. If a key is rejected, choose Replace API key and verify again. Rotation preserves the channel and existing conversation bindings; changing the endpoint requires a separate channel. SubLane tracks requests and tokens but does not query API balances or subscription quotas.
The administrator endpoint is POST /api/channels, accepting name, api_key, base_url and optional proxy_id. Rotate a key through PUT /api/channels/{id}/key, keeping the same base URL. Subscription credential JSON imports still reject API keys; API JSON imports must explicitly use provider: "openai".
Subscription quota
Subscription quota applies only to subscription accounts. API channel balances are not queried.
Grok reads the official Grok Build CLI billing metadata (GET https://cli-chat-proxy.grok.com/v1/billing?format=credits) and displays the included subscription percentage and its weekly or monthly reset period. Missing usage remains unknown. Legacy included credit totals are used only when the modern period is absent. On-demand spending, prepaid balances and product breakdowns are not treated as separate subscription allowances.
Claude reports its five-hour and weekly usage windows, including additional named windows when supplied. Antigravity reports remaining allowance and reset time for each model. The model list shows three entries by default, with constrained models first; expand it to inspect every reported model. Reset cards are shown only for Codex.
Queries read provider metadata without sending inference requests. Missing percentages or reset times stay unknown. Successful snapshots persist across restart; refresh failures retain the previous observation and mark it stale. Snapshots remain fresh for at most two minutes, shortened by an upcoming reset. Reporting does not certify model access or guarantee that a request will succeed. Fresh main quota windows gate Codex and Claude account selection. Antigravity gates only an exact match to the requested native model, including SDK thinking suffixes; an exhausted model does not exclude unrelated models or the entire account. Unknown, stale, future-dated and already-reset data does not imply exhaustion. Existing conversations keep their account binding when quota is exhausted.
Connect a subscription
- As a workspace administrator, open Subscription accounts → Add account, select the provider and enter a name.
- Choose browser authorization or credential JSON import. For Codex, Claude and Antigravity browser authorization, sign in on the provider's page and paste the complete callback URL back into SubLane. For Grok, approve the displayed device code on the authorization page; SubLane completes the connection automatically.
- Select Verify connection, then open Models to see the catalog reported by that account.
- Add the account to a resource group, grant member access and create a personal gateway key.
| Provider | Callback URL |
|---|---|
| Codex | http://localhost:1455/auth/callback?... |
| Claude | http://localhost:54545/callback?... |
| Antigravity | http://localhost:51121/oauth-callback?... |
SubLane does not run a local callback receiver, so a browser connection error at the callback address is expected. Copy the whole URL, including code and state. Authorization state is bound to the administrator session, single-use and valid for ten minutes. Codex and Claude use PKCE.
You can select a workspace network proxy before authorization or import. Token exchange, refresh, discovery and model execution use that account's server-side route; the browser sign-in page uses the browser's own network route.
Credential imports and refresh
Codex accepts nested token data or flat credential exports. Claude, Antigravity and Grok accept flat credential JSON exported by CLIProxyAPI, including access and refresh tokens and account identity. API-key credentials and imported endpoint or proxy overrides are rejected. SubLane does not scan local credentials automatically.
Grok imports use type: "xai" with OAuth access and refresh tokens, expired or expires_at, and identity from sub, id_token, account_id or email. Imported endpoints, using_api and API-key mode cannot switch subscription execution to metered API billing. Grok Build access depends on your subscription entitlement. Device attempts expire after at most ten minutes; cancellation or expiry prevents a late response from saving an account.
Reauthorization preserves the upstream account identity. Claude also retains one encrypted device identity across refresh, reauthorization and restart; legacy records acquire it before provider IO. Explicit credential failures require reauthorization, while temporary token failures use bounded retry backoff and respect upstream Retry-After.
Models and client protocols
Use a personal SubLane key to request GET /v1/models, then select an exact native model ID from that pool catalog. Catalogs include eligible Codex, Claude, Antigravity and Grok accounts. Grok uses the internal provider ID xai; use native model IDs from the catalog for client requests. Legacy provider-prefixed requests remain compatible. Existing conversations retain their account binding when accounts become disabled, busy or unavailable.
Client protocol and subscription provider are independent. OpenAI-compatible Responses and Chat Completions, Claude Messages and Gemini formats use the pinned SDK adapters to reach eligible accounts. Responses supports WebSocket; /v1/responses/compact is restricted to Codex accounts. Supported model features depend on the selected provider and conversion path.
Verification boundary
Automated tests use synthetic credentials and mocked upstreams. Enabling the integrations does not certify every real subscription or desktop-client workflow; perform separate acceptance checks for your accounts and clients. SubLane encrypts credentials and keeps them separate from member gateway keys. See the architecture.