feat(catalog): make OpenRouter attribution headers opt-in

OpenRouter's HTTP-Referer and X-Title headers surface installations
on its public leaderboard. Previously openrouter.toml shipped these
as literal Fabro values, which would auto-advertise every
self-hosted installation regardless of operator intent (test
environments, scratch accounts, private deployments).

Strip the default extra_headers and document the opt-in pattern in
the integration docs. Users who want leaderboard appearance add
their own headers to settings.toml under
[llm.providers.openrouter.extra_headers].

Also add a data-handling section to the integration docs flagging
that requests transit OpenRouter's infrastructure and are subject
to their logging/moderation policies.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
Scott Werner 2026-05-27 16:02:54 -04:00
parent 674fc5871a
commit 8bc8eae3f1
2 changed files with 23 additions and 4 deletions

View file

@ -23,6 +23,20 @@ enabled = true
That's the entire configuration — Fabro ships the model catalog, base URL, and attribution headers for you.
## Data handling
Requests sent through OpenRouter pass through their infrastructure before reaching the underlying model. Prompt content, completions, and metadata are subject to OpenRouter's logging, moderation, and data-retention policies — review them at [openrouter.ai/docs/features/privacy-and-logging](https://openrouter.ai/docs/features/privacy-and-logging) before sending sensitive prompts. You can also use OpenRouter's per-request privacy controls (`provider.data_collection` and provider routing filters) via the `provider_options.openrouter` field described below.
## Attribution (optional, opt-in)
OpenRouter recognizes two attribution headers — `HTTP-Referer` (your site URL) and `X-Title` (your app name) — that surface your install on OpenRouter's public leaderboard. Fabro does NOT send these by default, so self-hosted installations stay anonymous. To opt in, add them to your settings:
```toml title="settings.toml"
[llm.providers.openrouter.extra_headers]
"HTTP-Referer" = { literal = "https://your-site.example" }
"X-Title" = { literal = "Your App" }
```
## Configure credentials
For server-backed runs, store `OPENROUTER_API_KEY` in the Fabro server vault:

View file

@ -9,10 +9,15 @@ enabled = false
[providers.openrouter.auth]
credentials = ["env:OPENROUTER_API_KEY", "vault:OPENROUTER_API_KEY"]
[providers.openrouter.extra_headers]
"HTTP-Referer" = { literal = "https://fabro.sh" }
"X-Title" = { literal = "Fabro" }
# Attribution headers (HTTP-Referer, X-Title) are NOT sent by default.
# Self-hosted Fabro installations stay anonymous on OpenRouter's public
# leaderboard unless the operator opts in. To advertise, add to
# settings.toml:
#
# [llm.providers.openrouter.extra_headers]
# "HTTP-Referer" = { literal = "https://your-site.example" }
# "X-Title" = { literal = "Your App" }
#
# To enable OpenRouter, add the following to ~/.fabro/settings.toml:
#
# [llm.providers.openrouter]