Model providers
Configure OpenRouter, OpenAI, Anthropic or Gemini for the optional investigator, choose a model, and understand what has and has not been tested.
Providers
| Provider | Default key variable | Interface |
|---|---|---|
openrouter (default) | OPENROUTER_API_KEY | Chat Completions with structured output |
openai | OPENAI_API_KEY | Responses API |
anthropic | ANTHROPIC_API_KEY | Messages API |
gemini | GEMINI_API_KEY | generateContent |
yaml
models:
provider: anthropic
model: your-anthropic-model-id
# api_key_env: MY_CUSTOM_KEY # optional override
# reasoning: high # minimal | low | medium | highThere is no default model ID, no cross-provider fallback and no automatic retry. OpenRouter IDs use the upstream-provider/model form, and OpenRouter routing fallback is disabled.
Choosing a model
- It must support tool calling and structured output through the chosen provider interface.
- Reasoning models work well but think for a long time; budget for minutes, not seconds.
- Start with a small
request_limitand raise it once you have seen typical runs.
Privacy
The investigator sends the scoped incident context, query results and approved file contents to your provider. Lumis redacts common secrets and personal data patterns, but redaction is heuristic: review what your allowlist exposes. OpenAI response storage is disabled; each provider's own retention policy still applies. The provider conversation is not written to the report.
Source: Model providers ↗ in the SDK repository.