Last updated

Codex Router Models — DeepSeek, Kimi, GLM, Copilot & More

Codex Router can add models from DeepSeek, Kimi, GLM (Z.ai), Grok (xAI), Claude (Anthropic), GitHub Copilot, Xiaomi MiMo, opencode Go, Command Code, Meta, Qwen plan and many more compatible providers to the Codex model picker. This page mirrors the current built-in authentication matrix and separately lists providers whose models are discovered or curated from a live account catalog.

DeepSeekDeepSeekKimiKimiGLMGLMGrokGrokClaudeClaudeGitHub CopilotGitHub CopilotOpenRouterOpenRouterOllama CloudOllama Cloud

The built-in model matrix

These entries ship in the registry and appear in the Codex picker once their provider is enabled and authenticated:

Picker labelModel IDAuthentication
K2.7 Coding Highspeed (OAuth)kimi-oauth/kimi-for-coding-highspeedExisting Kimi Code CLI OAuth session
K2.7 Coding (OAuth)kimi-oauth/kimi-for-codingExisting Kimi Code CLI OAuth session
Kimi K3 (OAuth)kimi-oauth/k3Existing Kimi Code CLI OAuth session
Kimi K3 (API)kimi-api/kimi-k3Separately billed Kimi Platform API key
Kimi K3 (China API)kimi-api-cn/kimi-k3Separately billed Moonshot China platform key
DeepSeek V4 Flash (API)deepseek/deepseek-v4-flashDeepSeek API key
DeepSeek V4 Pro (API)deepseek/deepseek-v4-proDeepSeek API key
DeepSeek V4.1 Flash (API)deepseek/deepseek-v4.1-flashDeepSeek API key
Grok 4.5 (OAuth)grok-oauth/grok-4.5Official Grok CLI OAuth session
Grok 4.5 (API)grok-api/grok-4.5Separately billed xAI API key
Claude Opus 4.8 (API)anthropic-api/claude-opus-4.8Separately billed Anthropic API key
GLM-5.2 (Ollama Cloud)ollama-cloud/glm-5.2Ollama Cloud API key
GLM-5.3 (Ollama Cloud)ollama-cloud/glm-5.3Ollama Cloud API key
GLM-5.3-Flash (Ollama Cloud)ollama-cloud/glm-5.3-flashOllama Cloud API key
Kimi K2.7 Code (Ollama Cloud)ollama-cloud/kimi-k2.7-codeOllama Cloud API key
Kimi K3 (Ollama Cloud)ollama-cloud/kimi-k3Ollama Cloud API key
MiniMax M3 (Ollama Cloud)ollama-cloud/minimax-m3Ollama Cloud API key
DeepSeek V4 Pro (Ollama Cloud)ollama-cloud/deepseek-v4-proOllama Cloud API key
DeepSeek V4 Flash (Ollama Cloud)ollama-cloud/deepseek-v4-flashOllama Cloud API key
MiniMax M3minimax-token-plan/minimax-m3MiniMax Token Plan API key
MiMo-V2.5 (Xiaomi API)xiaomi-mimo/mimo-v2.5Xiaomi MiMo API key
MiMo-V2.5-Pro (Xiaomi API)xiaomi-mimo/mimo-v2.5-proXiaomi MiMo API key
Qwen3.8 Max (Plan)qwen-plan/qwen3.8-maxAlibaba Model Studio plan API key
Qwen3.8 Max Preview (Plan)qwen-plan/qwen3.8-max-previewAlibaba Model Studio plan API key
Qwen3.7 Max (Plan)qwen-plan/qwen3.7-maxAlibaba Model Studio plan API key
Qwen3.7 Plus (Plan)qwen-plan/qwen3.7-plusAlibaba Model Studio plan API key
Qwen3.6 Flash (Plan)qwen-plan/qwen3.6-flashAlibaba Model Studio plan API key
DeepSeek V4 Pro (Qwen Plan)qwen-plan/deepseek-v4-proAlibaba Model Studio plan API key
DeepSeek V4 Flash (Qwen Plan)qwen-plan/deepseek-v4-flash-0731Alibaba Model Studio plan API key
GLM-5.2 (Qwen Plan)qwen-plan/glm-5.2Alibaba Model Studio plan API key
GLM-5.3 (Coding Plan)zai-coding/glm-5.3Z.ai GLM Coding Plan API key
GLM-5.2 (Coding Plan)zai-coding/glm-5.2Z.ai GLM Coding Plan API key
GLM-5-Turbo (Coding Plan)zai-coding/glm-5-turboZ.ai GLM Coding Plan API key
GLM-5.3-Flash (Z.ai API)zai-api/glm-5.3-flashSeparately billed Z.ai platform API key
GLM-5.3 (Z.ai API)zai-api/glm-5.3Separately billed Z.ai platform API key
GLM-5.2 (Z.ai API)zai-api/glm-5.2Separately billed Z.ai platform API key
GLM-4.7 (Z.ai API)zai-api/glm-4.7Separately billed Z.ai platform API key
Muse Spark 1.2 (Meta)meta/muse-spark-1.2Meta Model API key
Muse Spark 1.2 Contributor (Meta)meta/muse-spark-1.2-contributorMeta Model API key
Muse Spark 1.1 (Meta)meta/muse-spark-1.1Meta Model API key
GLM-5.2 (ClinePass)clinepass/glm-5.2ClinePass API key
Kimi K3 (ClinePass)clinepass/kimi-k3ClinePass API key
Kimi K2.7 Code (ClinePass)clinepass/kimi-k2.7-codeClinePass API key
Kimi K2.6 (ClinePass)clinepass/kimi-k2.6ClinePass API key
DeepSeek V4 Pro (ClinePass)clinepass/deepseek-v4-proClinePass API key
DeepSeek V4 Flash (ClinePass)clinepass/deepseek-v4-flashClinePass API key
MiMo-V2.5 (ClinePass)clinepass/mimo-v2.5ClinePass API key
MiMo-V2.5-Pro (ClinePass)clinepass/mimo-v2.5-proClinePass API key
MiniMax M3 (ClinePass)clinepass/minimax-m3ClinePass API key
Qwen3.7 Max (ClinePass)clinepass/qwen3.7-maxClinePass API key
Qwen3.7 Plus (ClinePass)clinepass/qwen3.7-plusClinePass API key
Qwen3.8 Max (ClinePass)clinepass/qwen3.8-maxClinePass API key
Hy4 Preview (ClinePass)clinepass/tencent/hy4-previewClinePass API key
Hy4 Preview (Command Code)commandcode/hy4-previewCommand Code API key
Hy4 Preview (NanoGPT)nano-gpt/tencent/hy4-previewNanoGPT API key
Hy4 Preview (Nous Research)nousresearch/tencent/hy4-previewNous Portal API key
Hy4 Preview (opencode Go)opencode-go/hy4-previewopencode Go/Zen API key
Hy4 Preview (OpenRouter)openrouter/tencent/hy4-previewOpenRouter API key
Union Alpha (opencode Go)opencode-go-messages/union-alphaopencode Go/Zen API key
Union Alpha (OpenRouter)openrouter/union-alphaOpenRouter API key
Kimi K3 (ainetcafe)ainetcafe/kimi-k3ainetcafe API key (AINETCAFE_API_KEY)

The table above follows the repository README’s compact primary authentication matrix. Provider-specific sections and guides below also cover newer checked-in routes not yet listed in that table, including Grok 4.6 OAuth and Meta Muse Spark 1.3. opencode Go and Command Code have additional provider-family catalogs, while catalog-only providers discover or curate entries locally.

How the catalog decides what you see

The Codex catalog is credential-aware. It includes models only from enabled external providers that have a stored API key or a valid OAuth session. Native GPT models are included only when codex login status confirms an OpenAI login — so a signed-out login-free session shows only your authenticated external models.

That means adding a model is always two steps: enable the provider and provide credentials. A provider that is enabled but has no key simply shows no models.

Picker order

Codex renders its model picker by priority, and routed models normally land in a band after the highest visible native entry. If your everyday models are external, you can publish them ahead of the native GPT entries instead:

./bin/model-router codex picker-order routed-first
./bin/model-router codex picker-order native-first

native-first is the unchanged default. Under routed-first every routed model — certified v2 spawn routes included — publishes at 1..N in the existing vendor-group order and the natives move after them. The choice is stored in model-picker.json, visibility writers preserve it, and an older file or an unrecognized value keeps the default. Fully quit and reopen Codex after changing it.

OAuth vs API key

Both styles appear in the matrix above, and they are separate account and billing systems even for the same vendor:

  • OAuth reuses the official CLI’s signed-in session (Kimi Code CLI or Grok CLI). Nothing is stored by the router beyond what the official CLI already keeps.
  • API key is a separately billed developer key entered once through a hidden prompt. DeepSeek, Kimi Platform, xAI, Anthropic, Ollama Cloud, Z.ai (plan and platform), Xiaomi, Meta and Qwen plan all use API keys.

See the OAuth vs API key comparison and each model guide for the details.

Enable a provider

./bin/model-router codex providers
./bin/model-router codex providers enable deepseek
./bin/model-router codex provider-key deepseek set
./bin/model-router codex provider-key anthropic-api set

On Windows, use ./model-router.ps1 codex with the same commands. The API-key prompt disables terminal echo, protected files use mode 600 on POSIX and an inheritance-disabled current-user ACL on Windows, and diagnostics report credential presence and source — never the value.

GitHub Copilot

github-copilot exposes only account-visible models that advertise the Responses API, streaming and tool calls. Because the catalog depends on the user’s plan and organization policy, no Copilot model IDs are hard-coded. Store a fine-grained github_pat_ token with the Copilot Requests permission, then curate the live catalog:

./bin/model-router codex provider-key github-copilot set
./bin/curate-models github-copilot

The token is validated through GitHub’s Copilot account endpoint, and the returned inference host is accepted only when it is GitHub-owned. Requests consume the user’s Copilot allowance. Classic ghp_ tokens and the Copilot CLI credential store are not used.

opencode Go and Zen

The opencode provider family covers both opencode endpoints with one stored key (OPENCODE_API_KEY or OPENCODE_GO_API_KEY): the flat-rate Go subscription, whose tested models (Grok 4.5, GLM-5.2, Kimi K3, DeepSeek V4 Pro and more) ship in the registry, and the pay-per-use Zen endpoint, whose larger catalog is available through local curation. Everything appears as one “opencode Go/Zen” provider.

Command Code Provider API

Command Code’s official Provider API is an OpenAI-compatible Chat Completions surface plus an Anthropic Messages surface at https://api.commandcode.ai/provider/v1. It is API-key only — the router no longer signs in through the Command Code CLI. Store a key created in Command Code Studio (COMMAND_CODE_API_KEY or COMMANDCODE_API_KEY in the environment, or the stored key):

./bin/model-router codex provider-key commandcode set
./bin/model-router codex providers enable commandcode

GOAT, Pro, Max, Team and Provider plans use the Provider API. The Go plan uses the coding-plan route: when /provider/v1 returns the exact 403 upgrade_required entitlement response before sending any response bytes, the router retries through Command Code’s /alpha/generate transport and remembers that result for the credential. Other 403s, timeouts, rate limits and server errors do not trigger this fallback. Both paths use the same stored key and provider family.

Meta Model API

Meta’s Muse Spark models speak the Responses protocol at https://api.meta.ai/v1 with a stored META_API_KEY. Five models ship in the registry: Muse Spark 1.3 and 1.2, each with a cheaper Contributor tier whose inputs and outputs Meta may use for training, plus the previous-generation 1.1.

Z.ai metered platform

zai-api is a separate provider for Z.ai’s pay-per-use platform at https://api.z.ai/api/paas/v4. It carries GLM-5.3, GLM-5.2 (1M context) and the cheaper GLM-4.7, with the same reasoning ladders as the Coding Plan route for GLM-5.3 and GLM-5.2. It is a separate credential end to end: its own key file, keychain service and ZAI_PLATFORM_API_KEY environment variable — never the plan’s ZAI_API_KEY. A Coding Plan key is not billable on the metered endpoint and vice versa.

Xiaomi MiMo API

MiMo (Xiaomi API) uses Xiaomi’s official OpenAI-compatible endpoint at https://api.xiaomimimo.com/v1. Unlike MiMo reseller routes, the direct API speaks /chat/completions, so requests never touch the Responses gateway. MiMo-V2.5 and MiMo-V2.5-Pro ship in the registry with a Xiaomi MiMo API key.

GLM-5.3 notes

GLM-5.3 arrived on 2026-08-14. The primary matrix now includes zai-coding/glm-5.3, zai-api/glm-5.3, opencode-go/glm-5.3 and ollama-cloud/glm-5.3; provider-specific catalogs also pin it on OpenRouter, Command Code and Venice. The Ollama Cloud full and Flash entries are candidate registry metadata and still require exact-route proof before they should be described as certified.

Live-catalog providers

These OpenAI-compatible providers are registered for routing and credential isolation but ship no preselected models, because their catalogs change too often to pin and live-verify individual entries:

ProviderProvider ID
Groqgroq
Together AItogether
Fireworks AIfireworks
Cerebrascerebras
Mistral AImistral
NVIDIA NIMnvidia-nim
SiliconFlowsiliconflow
Hugging Face Routerhuggingface
Google Gemini APIgemini-api
GitHub Copilotgithub-copilot
Chuteschutes
OrcaRouterorca
Google Cloud Vertex AIvertex

devin-cli is the OAuth exception: after devin auth login, the router reads only the model configuration available through the installed Devin CLI and ships no preselected Devin models. vertex is the Google Cloud exception, covered below. opencode-free and kilo-free are separate anonymous gateways whose live catalogs are filtered to their documented free subsets; no key is requested, but availability and limits remain provider-controlled.

Add a key, then curate the models you want from the provider’s live catalog:

./bin/model-router codex provider-key groq set
./bin/curate-models groq

Curation also asks whether the model rejects a forced tool_choice; answering yes stores an auto-tool-choice request profile so the router downgrades the forced choice for that model only.

Vertex AI (Google Cloud)

vertex authenticates with Application Default Credentials from gcloud auth application-default login — never a stored API key and never a silent gcloud auth login user token — and it is never selected by a default install:

gcloud auth application-default login
./bin/control vertex set PROJECT_ID LOCATION
./bin/curate-models vertex

The provider is catalog-only: it lists Model Garden models for curation, and a discovered id is not routable until you curate it onto a reviewed adapter. --no-discovery is honored, keeping Vertex credentials out of discovery runs. For accounts where Model Garden’s publisher-model list is unavailable, curation has an explicit offline mode that uses only the reviewed entries in config/vertex/support-catalog.json:

./bin/curate-models vertex --static --models MODEL_ID

--static never falls back silently after a live discovery failure and cannot be combined with --refresh; requests still require working ADC, Vertex API enablement, IAM and model access. It is a curation escape hatch, not proof that the account can use every reviewed model.

Providers with pinned and live-catalog models

These API-key providers ship reviewed routes and also let you curate additional models from the account’s live catalog:

ProviderProvider IDBase URLKey from
OpenRouteropenrouterhttps://openrouter.ai/api/v1openrouter.ai/settings/keys
NanoGPTnano-gpthttps://nano-gpt.com/api/v1nano-gpt.com
Venicevenicehttps://api.venice.ai/api/v1venice.ai/settings/api
Nous Research (Hermes)nousresearchhttps://inference-api.nousresearch.com/v1portal.nousresearch.com
ainetcafeainetcafehttps://microquickjs.com/v1ainetcafe API key (AINETCAFE_API_KEY)

Venice API access is an entitlement, not just a key: a free Venice account has none. A Pro subscription, a funded USD balance, or staked VVV that grants VCU is what makes a key usable — the router prints the requirement when you connect the provider rather than letting it arrive as a 403 inside Codex. Nous Research keys are Nous Portal API keys and authenticate the same endpoint the Hermes agent uses; the checked-in registry now lists 28 Nous models including Hermes 4 and free portal tiers, but that is not the full 372-model catalog. OpenRouter ships pinned routes such as Grok 4.6 and Union Alpha on top of its curatable catalog. ainetcafe ships one pinned route, ainetcafe/kimi-k3, against its OpenAI-compatible endpoint, reusing the same kimi-k3 request profile as the other Kimi K3 relays with the default 256K context and text + image input.

GLM-5.3-Flash (formerly Ox Alpha)

The stealth 1M-context reasoning model first shipped as “Ox Alpha” has graduated: OpenCode Go now publishes it as the named, metered glm-5.3-flash, and exact-route live probes certified the named model on OpenRouter, Z.ai API and Z.ai Coding. No checked-in Ox Alpha route remains — the unproved Command Code and Venice presets were withdrawn after wire verification, and the OpenCode Free / OpenRouter / Nous presets were dropped:

Picker labelModel IDNeeds a keyStatus
GLM-5.3-Flash (opencode Go)opencode-go/glm-5.3-flashopencodeNamed replacement
GLM-5.3-Flash (Command Code)commandcode/glm-5.3-flashCommand CodeAvailable — catalog-pinned
GLM-5.3-Flash (OpenRouter)openrouter/glm-5.3-flashOpenRouterAvailable
GLM-5.3-Flash (Z.ai API)zai-api/glm-5.3-flashZ.ai APIAvailable
GLM-5.3-Flash (Z.ai Coding)zai-coding/glm-5.3-flashZ.ai CodingAvailable
GLM-5.3-Flash (Ollama Cloud)ollama-cloud/glm-5.3-flashOllama CloudCandidate — exact-route proof required
Ox Alpha (Venice)venice/ox-alphaWithdrawn — wire verification was billing-blocked
Ox Alpha (OpenCode Free / OpenRouter / Nous)opencode-free/ox-alpha etc.Withdrawn

Reasoning effort is low · high · max on the certified Flash routes, defaulting to max — the model always thinks, and its upstream rejects any other rung by name; the router clamps the requested effort onto those three rungs. Z.ai Coding, Z.ai API, OpenRouter and Command Code Flash routes declare native text-and-image input, so pasted images bypass Vision Bridge; suffix-free GLM-5.3 remains text-only. The Ollama Cloud candidate is listed but not yet certified. Existing opencode-go/ox-alpha selections and locally curated opencode-go/ox-alpha-free selections migrate to opencode-go/glm-5.3-flash automatically. The picker keeps the advertised 1M context, but Codex compacts every GLM-5.3-Flash route at 400K because larger live multimodal histories returned empty completions before the advertised limit.

The free preview is over: what survives is the named model on credentialed routes, with per-provider retention terms (OpenCode advertises zero data retention, Venice anonymizes, others say less).

Union Alpha (opencode Go and OpenRouter)

OpenCode Go’s current stealth preview is Union Alpha. It is a separate model from Ox Alpha / GLM-5.3-Flash: OpenCode does not name the maker, documents a 262,144-token window with 131,072 tokens of advertised output, text and image input, and currently lists it as free for a limited time.

Picker labelModel IDNeeds a keyNotes
Union Alpha (opencode Go)opencode-go-messages/union-alphaopencode Go/ZenAnthropic Messages hop, currently free
Union Alpha (OpenRouter)openrouter/union-alphaOpenRouterSame preview as stealth/union-alpha

The Go route speaks the Anthropic Messages API rather than Chat Completions, and the hop reserves the measured 32,768-token completion cap so a Desktop-sized first turn plus that reserve still fits the 262,144 window; compaction stays at 180,000, above the cached tool-schema floor. Console Go also rejects a single message over 2,500,000 characters, so an oversized ImageGen data URL is replaced with a labeled stub while Codex keeps the file. OpenRouter publishes the same preview as stealth/union-alpha but advertises no reasoning-effort ladder, so its route stores the conservative single high rung and accepts tool_choice auto only. ClinePass and Command Code do not list this id, and Omen Alpha remains in the live Go catalog only as a deprecated entry that is not checked in. Rebuild the catalog and fully quit and reopen Codex to see the new picker rows.

Local backends: Ollama and LM Studio

Models running on your own machine appear in the picker under the local provider. Ollama keeps its native route, and LM Studio can run as a second local backend alongside it — its models use the stable lmstudio/<model-id> namespace so identical IDs never collide:

./bin/model-router codex providers enable lmstudio
./bin/curate-models lmstudio

The default endpoint is http://127.0.0.1:1234/v1; set MODEL_ROUTER_LMSTUDIO_BASE_URL when LM Studio listens elsewhere. Models are published only when you explicitly choose them, and are labelled experimental in the picker. See the local LLMs guide for the full workflow.

Curating a generic Ollama provider no longer falls back to a 131,072-token guess with text-only input. When the provider is an OpenAI-chat endpoint rooted at /v1, discovery also asks that server’s own /api/show for each listed model, proves the answer is Ollama-shaped, and fills in only the fields the model list left blank — so a model the server runs at 1M with vision is curated at its served window and modalities. The probe is bounded, stops on a missing route or after three leading refusals, and skips a model the server cannot describe. Curation stores the advertised window and image input, while discovery reports them as contextLengths and inputModalities; a documented default never masquerades as a served one.

Provider setup guides

Each provider has its own step-by-step guide: DeepSeek, Kimi, GLM, Grok, Claude, opencode Go, opencode Zen, GitHub Copilot, Ollama Cloud, Command Code, Meta Muse Spark, Qwen plan, Nous Research, Venice, MiniMax, Xiaomi MiMo, ClinePass and local LLMs. Add anything else with custom models.

Verify a model

After enabling a provider, restart Codex and confirm the picker entry. For a live, quota-consuming check of a specific model:

./bin/test-model 'groq/MODEL_ID' --live --yes

See the per-model guides — DeepSeek, Kimi, GLM, Grok, Claude — for step-by-step setup, and the troubleshooting guide if models do not appear.