#!/usr/bin/env bash # Shared helpers for live API probing. Source this file: `source scripts/lib.sh` # - Loads .env (never echoes keys) # - oai / ant : curl wrappers (auth headers injected, never printed) # - log_request : appends a sanitized record to reports/live-requests.jsonl set -o pipefail # Works under bash (BASH_SOURCE) and zsh (%x); falls back to PWD. _lib_src="${BASH_SOURCE[0]:-}" if [ -z "$_lib_src" ] && [ -n "${ZSH_VERSION:-}" ]; then _lib_src="${(%):-%x}"; fi if [ -n "$_lib_src" ]; then ATLAS_ROOT="$(cd "$(dirname "$_lib_src")/.." && pwd)"; else ATLAS_ROOT="$PWD"; fi export ATLAS_ROOT if [ -f "$ATLAS_ROOT/.env" ]; then set -a # shellcheck disable=SC1091 . "$ATLAS_ROOT/.env" set +a fi : "${OPENAI_API_KEY:?OPENAI_API_KEY missing (see .env.example)}" : "${ANTHROPIC_API_KEY:?ANTHROPIC_API_KEY missing (see .env.example)}" # xAI / Gemini are optional (warn only) [ -n "${XAI_API_KEY:-}" ] || echo "warning: XAI_API_KEY not set" >&2 [ -n "${GEMINI_API_KEY:-}" ] || echo "warning: GEMINI_API_KEY not set" >&2 export GEMINI_API_VERSION="${GEMINI_API_VERSION:-v1beta}" export ANTHROPIC_VERSION="${ANTHROPIC_VERSION:-2023-06-01}" mkdir -p "$ATLAS_ROOT/tmp-live" "$ATLAS_ROOT/reports" LIVE_LOG="$ATLAS_ROOT/reports/live-requests.jsonl" # Mask anything that looks like a key in arbitrary text (defense in depth for logs). mask() { sed -E 's/sk-(ant-)?[A-Za-z0-9_-]{8,}/sk-***REDACTED***/g; s/xai-[A-Za-z0-9_-]{16,}/xai-***REDACTED***/g; s/AIza[A-Za-z0-9_-]{20,}/AIza***REDACTED***/g; s/AQ\.[A-Za-z0-9_-]{20,}/AQ.***REDACTED***/g; s/(Bearer|x-api-key:?|x-goog-api-key:?) *[A-Za-z0-9._-]{8,}/\1 ***REDACTED***/gI; s/([?&]key=)[A-Za-z0-9._-]{8,}/\1***REDACTED***/g'; } # log_request provider method path http_status est_cost_usd note log_request() { local ts; ts="$(date -u +%Y-%m-%dT%H:%M:%SZ)" printf '{"ts":"%s","provider":"%s","method":"%s","path":"%s","status":%s,"est_cost_usd":%s,"note":"%s"}\n' \ "$ts" "$1" "$2" "$3" "${4:-0}" "${5:-0}" "$(printf '%s' "${6:-}" | mask | sed 's/"/\\"/g')" >> "$LIVE_LOG" } # oai METHOD PATH [curl args...] e.g. oai GET /v1/models ; oai POST /v1/responses -d @body.json # Writes body to stdout, sets OAI_STATUS. oai() { local method="$1" _p="$2"; shift 2 local out; out="$(mktemp)" OAI_STATUS="$(curl -sS -o "$out" -w '%{http_code}' -X "$method" "https://api.openai.com$_p" \ -H "Authorization: Bearer $OPENAI_API_KEY" -H "Content-Type: application/json" "$@")" cat "$out"; rm -f "$out" export OAI_STATUS } # ant METHOD PATH [curl args...] Adds x-api-key + anthropic-version. Pass -H 'anthropic-beta: ...' as needed. ant() { local method="$1" _p="$2"; shift 2 local out; out="$(mktemp)" ANT_STATUS="$(curl -sS -o "$out" -w '%{http_code}' -X "$method" "https://api.anthropic.com$_p" \ -H "x-api-key: $ANTHROPIC_API_KEY" -H "anthropic-version: $ANTHROPIC_VERSION" -H "Content-Type: application/json" "$@")" cat "$out"; rm -f "$out" export ANT_STATUS } # xai METHOD PATH [curl args...] (OpenAI-compatible base https://api.x.ai) xai() { local method="$1" _p="$2"; shift 2 local out; out="$(mktemp)" XAI_STATUS="$(curl -sS -o "$out" -w '%{http_code}' -X "$method" "https://api.x.ai$_p" \ -H "Authorization: Bearer $XAI_API_KEY" -H "Content-Type: application/json" "$@")" cat "$out"; rm -f "$out" export XAI_STATUS } # gemini METHOD PATH [curl args...] PATH like /v1beta/models/gemini-2.5-flash:generateContent (key sent as header, never in URL) gemini() { local method="$1" _p="$2"; shift 2 local out; out="$(mktemp)" GEMINI_STATUS="$(curl -sS -o "$out" -w '%{http_code}' -X "$method" "https://generativelanguage.googleapis.com$_p" \ -H "x-goog-api-key: $GEMINI_API_KEY" -H "Content-Type: application/json" "$@")" cat "$out"; rm -f "$out" export GEMINI_STATUS } # Multipart variants (no forced Content-Type; pass -F fields). Note: OAI_STATUS/ANT_STATUS are set in the # CURRENT shell only when the function is not run inside $(...) or a pipeline — redirect to a file instead: # oai_form POST /v1/files -F purpose=user_data -F file=@x.txt > out.json; echo "$OAI_STATUS" oai_form() { local method="$1" _p="$2"; shift 2 local out; out="$(mktemp)" OAI_STATUS="$(curl -sS -o "$out" -w '%{http_code}' -X "$method" "https://api.openai.com$_p" \ -H "Authorization: Bearer $OPENAI_API_KEY" "$@")" cat "$out"; rm -f "$out" export OAI_STATUS } ant_form() { local method="$1" _p="$2"; shift 2 local out; out="$(mktemp)" ANT_STATUS="$(curl -sS -o "$out" -w '%{http_code}' -X "$method" "https://api.anthropic.com$_p" \ -H "x-api-key: $ANTHROPIC_API_KEY" -H "anthropic-version: $ANTHROPIC_VERSION" "$@")" cat "$out"; rm -f "$out" export ANT_STATUS } # Save a sanitized JSON/text payload to a file under sources/ or tmp-live/ save_sanitized() { # save_sanitized (reads stdin) mkdir -p "$(dirname "$1")"; mask > "$1" }