A gateway connects Kestrel One to a model provider. An approved model is one that an administrator has tested and allowed members to select.
Make a model available
- Register the provider gateway from the administrative model settings.
- Discover the models exposed by that gateway.
- Test the intended model with streaming and a complete tool-call/tool-result round trip.
- Approve the model only after those checks succeed.
- Confirm that an authorized member can select it in a Thread.
Provider credentials remain on trusted Kestrel One services. A member’s browser requests an approved model by identifier; it never receives the provider URL, raw credential, or runner token.
Managed deployments add an infrastructure readiness check to the same approval flow.