Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
27 commits
Select commit Hold shift + click to select a range
90c78fb
feat: auto-register Altimate Base with no consent gate
anandgupta42 Sep 23, 2026
aca8de6
fix: clear OpenCode Zen block message and retry Altimate Base TPM thr…
anandgupta42 Sep 23, 2026
6eb79ed
refactor: remove the Altimate Base consent dialog and capability mach…
anandgupta42 Sep 23, 2026
2d58fb9
test: cover the no-dialog Altimate Base picker flow and the disclosur…
anandgupta42 Sep 23, 2026
695bbf6
fix: Altimate Base fallback ordering and retry latch
anandgupta42 Sep 23, 2026
59415f6
fix: repair unbalanced `altimate_change` markers and upstream brandin…
anandgupta42 Sep 23, 2026
41dc4d4
fix: headless disclosure, persisted auto-register backoff, retry cap,…
anandgupta42 Sep 23, 2026
2ef2c8a
fix: attached-TUI auth headers, explicit model authority, dismissed-p…
anandgupta42 Sep 23, 2026
367201a
docs: state the new Altimate Base auto-registration behavior
anandgupta42 Sep 23, 2026
7aa7474
fix: mark two lines the strict marker guard flagged as unmarked new code
anandgupta42 Sep 23, 2026
daa773c
fix: mark remaining shifted line the strict marker guard flagged
anandgupta42 Sep 23, 2026
6f92853
fix: close the late-registration gaps and tidy review findings
Sep 23, 2026
9f6b95b
fix: reload providers per process, not per workspace, and qualify the…
Sep 23, 2026
b103818
fix: treat a renewed Base credential as changed, and scope the backof…
Sep 23, 2026
fcd6c5b
fix: tell a credential reissued after logout from an untouched one
Sep 23, 2026
f29253f
fix: return the logout nonce from a fresh Base registration
Sep 23, 2026
66056a6
fix: serialize the register route's reload, and tighten the Base tests
Sep 23, 2026
13c5c78
fix: keep Zen's variant off a restored Base session, and cycle past a…
Sep 23, 2026
3a975b4
fix: keep the rejected-to-restored reload, cycle off explicit Zen, an…
Sep 23, 2026
c64a48c
fix: reload once when overlapping register calls repair the same cred…
Sep 23, 2026
c16e521
fix: snapshot the reload count after the pre-registration read
Sep 23, 2026
16873f0
fix: capture the pre-registration read and reload count on the reload…
Sep 23, 2026
0565811
fix: honor an explicit keyless-Zen pick, and notice a late Base regis…
Sep 23, 2026
51c6a8a
fix: keep an explicit keyless-Zen pick across conversation switches
Sep 23, 2026
e31844d
fix: carry an explicit keyless-Zen pick to an agent without its own m…
Sep 23, 2026
8ed38f8
fix: key explicit picks unambiguously
Sep 23, 2026
5903ed4
test: pin autoRegisterWithin's late-notice callback wiring per entryp…
sahrizvi Sep 23, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -60,7 +60,9 @@ altimate # Launch the TUI

Altimate Base is the free, no-signup option. It is rate limited, and its requests and responses
are logged and may be used to improve Altimate products and services; do not send secrets or
confidential code. The setup dialog shows this disclosure and defaults to **No** before registering.
confidential code. If you don't pick another provider, a fresh install registers it automatically
— no dialog to accept — and prints this notice once. Opt out with `ALTIMATE_BASE_AUTO_REGISTER=0`,
`altimate providers logout altimate-base`, or `disabled_providers` in config.

Or set an environment variable directly:
```bash
Expand Down
50 changes: 35 additions & 15 deletions docs/docs/configure/providers.md
Original file line number Diff line number Diff line change
Expand Up @@ -62,23 +62,43 @@ If you need stronger guarantees — no training on your data, metadata-only rete
[Altimate LLM Gateway](https://help.altimate.ai/datamates/user-guide/components/llm-gateway/)
instead.

Choose **Altimate Base** from the first-run picker or `/connect`. A disclosure is shown before any
registration request; **No** is selected by default. After registration, the model is available as
Choose **Altimate Base** from the first-run picker or `/connect` — or do nothing at all: every
install that is not yet registered registers it automatically at startup, so it works the same way
headlessly (`run`, `serve`, `acp`, `web`). Startup waits up to three seconds for this; a slower
registration finishes in the background and applies from the next launch (a `serve` client can
apply it sooner through the register route). After a network error, rate limit or gateway server error, startup skips
registration for a retry backoff of one hour (longer if the gateway asks, up to 24 hours). This happens whether or not you
also have a model of your own; a registered Base only becomes your default when nothing you
configured is usable. There is no confirmation dialog to accept.
The disclosure above is shown once per install: in the TUI as a toast the first time Base becomes
the active model, and for a headless entrypoint as a one-line notice to stderr the first time it runs
with Base registered (`serve` skips it when
`ALTIMATE_CLI_CLIENT=datamates`, since the VS Code extension shows its own notice). After registration, the model is available as
`altimate-free/altimate-base` and becomes the free fallback when no paid Altimate Gateway or
explicit model is selected. Big Pickle is retired as a new selection — it no longer appears in the
picker or the full model catalog for users choosing a model for the first time. Users already on
Big Pickle are still detected on launch and offered Altimate Base through the same consent gate.
If you decline the default switch, `declinedManagedBaseDefault: true` in the state directory's `model.json` keeps public Zen ahead of registered Base for headless and ACP defaults, with Base used only as a last resort; accepting migration or explicitly selecting Base clears the flag.

Registration is per machine, not per host. Once any host on a machine has registered Altimate
Base (the TUI's consent gate, or the HTTP registration route used by IDE integrations), every
other host on that machine treats Base as the default free model without showing its own
prompt: the TUI migrates an implicit free default silently, and headless `altimate run`,
`altimate serve`, and ACP sessions resolve to Base ahead of the keyless public Zen tier. The
disclosure is therefore shown once per machine, by whichever host registers. Declining as
described above applies to all hosts on the machine too. Administrators auditing a fleet can
check `model.json` for `declinedManagedBaseDefault` and the registered `altimate-free` provider
entry in `auth.json`.
Big Pickle are migrated to Altimate Base the same automatic way once it registers, not through a
separate confirmation: `declinedManagedBaseDefault` is still read from `model.json` for backward
compatibility, but no longer changes the outcome — the keyless public Zen tier rejects
unauthenticated traffic outright, so there is no longer a working "stay on public Zen" choice to
honor.

To opt out: set `ALTIMATE_BASE_AUTO_REGISTER=0` before this install first registers Base, run
`altimate providers logout altimate-base` afterward, or keep it out of your own choices with
`enabled_providers` / `disabled_providers`. The env var is the only one of these that stops the
background registration call itself; the other two only control whether Base can be *selected* as
your model on this machine. Logging out un-registers it and also stops automatic registration on
this machine: later launches skip it until you pick Altimate Base again in the picker (or an IDE
calls the registration route), which reconnects it.

Registration is per machine, not per host: once any host on a machine has registered Altimate
Base (auto-registration on any entrypoint, or the HTTP registration route used by IDE
integrations), every other host on that machine treats Base as the default free model too — the
TUI migrates an implicit free default silently, and headless `altimate run`, `altimate serve`, and
ACP sessions resolve to Base ahead of the keyless public Zen tier. Logging out on any host applies
to all hosts on the machine, since the credential is a single shared file. Administrators auditing
a fleet can check for the Altimate Base credential file, `altimate-base.json`, in the data directory
(it is stored separately from the shared provider-auth file).

Official release binaries embed the current gateway endpoint at build time. Operators and local
development can override it without changing code:
Expand All @@ -91,7 +111,7 @@ altimate
The URL must use HTTPS. Credentials,
query strings, and fragments in the URL are rejected. `ALTIMATE_FREE_GATEWAY_URL` is retained as a
legacy fallback, but `ALTIMATE_BASE_GATEWAY_URL` takes precedence. If the configured gateway host
changes, credentials issued by the previous host are not loaded and the consented registration
changes, credentials issued by the previous host are not loaded and the registration
flow must run again.

Altimate Base waits up to **5 minutes** for the gateway to send response headers, because the
Expand Down
2 changes: 1 addition & 1 deletion docs/docs/getting-started/quickstart.md
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ On a fresh install, a welcome panel appears with a curated 6-provider picker:

- **Altimate LLM Gateway** *(recommended)* — 10M tokens free, no API keys. Routes to the best model per task across Sonnet, Opus, GPT-5, and more. Sign-in opens a browser tab; complete Google or email signup and you're back in the TUI. If your terminal can't open a browser (SSH / tmux / WSL), the CLI prints the URL — paste it into a browser on your desktop.
- **Anthropic** / **OpenAI** / **Google** — paste an API key or OAuth in.
- **Altimate Base** — a hosted open model, free and rate limited, with no signup or API key. Requests and responses may be logged and used to improve Altimate's products, so do not send secrets or confidential code. Registration happens only after an explicit confirmation that defaults to **No**.
- **Altimate Base** — a hosted open model, free and rate limited, with no signup or API key. Requests and responses may be logged and used to improve Altimate's products, so do not send secrets or confidential code. Every install registers it automatically at startup, whichever provider you pick — there is no confirmation dialog — and this notice is shown once, when Base is first used; it only becomes your model when nothing else you configured is usable. Opt out with `ALTIMATE_BASE_AUTO_REGISTER=0`, `altimate providers logout altimate-base`, or `disabled_providers` (see [providers](../configure/providers.md#altimate-base)).
- **Search all providers…** — full picker if you need Bedrock, Databricks AI Gateway, Cloudflare AI Gateway, Snowflake Cortex, DigitalOcean Inference, etc.

Or set an environment variable and skip the picker:
Expand Down
2 changes: 1 addition & 1 deletion docs/docs/reference/network.md
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,7 @@ altimate needs outbound HTTPS access to:
| Destination | Purpose |
|-------------|---------|
| Your LLM provider API | Model inference (Anthropic, OpenAI, etc.) |
| Official Altimate Base gateway (embedded in release), or the host set by `ALTIMATE_BASE_GATEWAY_URL` | Altimate Base registration and inference when you explicitly enable Altimate Base |
| Official Altimate Base gateway (embedded in release), or the host set by `ALTIMATE_BASE_GATEWAY_URL` | Altimate Base registration (automatic at startup on any install not yet registered, unless `ALTIMATE_BASE_AUTO_REGISTER=0`, after logging out of Base, or during the 1–24 h retry backoff after a network error, rate limit or gateway server error) and inference |
| `registry.npmjs.org` | Package updates |
| `models.dev` | Model catalog (can be disabled) |
| Your warehouse endpoints | Database connections |
Expand Down
26 changes: 18 additions & 8 deletions docs/docs/reference/security-faq.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,13 +11,23 @@ Answers to the most common security questions about running Altimate Code in you

## Does Altimate Code send my data to external services?

Altimate Code sends prompts and context to the LLM provider you configure (Anthropic, OpenAI, Azure OpenAI, AWS Bedrock, etc.). **You choose the provider.** No data is sent anywhere else except optional [telemetry](#what-telemetry-is-collected), which contains no code, queries, or credentials.

Altimate Base is an optional hosted provider. Its confirmation dialog explains that requests and
responses are logged and may be used to improve Altimate products and services; do not send
secrets or confidential code. The dialog defaults to **No**, and no registration request is made
unless you explicitly accept. This request logging is part of the Altimate Base service and is
separate from anonymous product telemetry.
Altimate Code sends prompts and context to the LLM provider you configure (Anthropic, OpenAI, Azure OpenAI, AWS Bedrock, etc.). **You choose the provider.** Beyond that provider, Altimate Code contacts the Altimate Base gateway to register this install (see below), and sends optional [telemetry](#what-telemetry-is-collected), which contains no code, queries, or credentials.

Altimate Base is Altimate's own hosted free model. By default, every install that is not yet
registered registers it automatically at startup, whether or not you also have a model of your own.
Registration sends only a hash of a random per-install secret and the CLI version, not your prompts or code. It is skipped when
`ALTIMATE_BASE_AUTO_REGISTER=0` is set, after you log out of Base, when no gateway is configured, and
during the retry backoff that follows a network error, rate limit or gateway server error. There is
no confirmation dialog to accept. It only becomes your default model when nothing you configured is
usable. Requests and responses are
logged and may be used to improve Altimate products and services, including the model; secrets are
automatically masked before storage, but don't rely on it — avoid sending secrets or confidential
code. This notice is shown once — a toast in the TUI the first time Base becomes the active model, or a one-line stderr notice the first time
a headless entrypoint (`run`, `serve`, `acp`, `web`) runs with Base registered — and is part of the Altimate
Base service, separate from anonymous product telemetry. To opt out: set
`ALTIMATE_BASE_AUTO_REGISTER=0` before Base ever registers, run `altimate providers logout
altimate-base` afterward, or exclude it from your own model choices with `enabled_providers` /
`disabled_providers` (see [providers](../configure/providers.md#altimate-base)).

**What identifies you to Altimate Base.** Registration sends a SHA-256 hash of a locally generated
installation secret — the secret itself never leaves your machine. That hash is stable, so logged
Expand Down Expand Up @@ -110,7 +120,7 @@ You can also configure per-agent permissions. For example, restrict the `analyst
| Destination | Purpose |
|-------------|---------|
| Your configured LLM provider | Model inference |
| Altimate Base gateway | Registration and inference only after you explicitly enable Altimate Base |
| Altimate Base gateway | Registration (automatic at startup on any install not yet registered) and inference |
| Your warehouse endpoints | Database queries |
| `registry.npmjs.org` | Package updates |
| `models.dev` | Model catalog (can be disabled) |
Expand Down
Loading
Loading