Skip to main content

KeyCall

One consistent interface for validating AI-provider API keys, listing and filtering the models available to them, and making normalized calls, so every product stops rebuilding the same model-picker filters and provider wrappers.

Status: early release (0.1.0). Key validation, model listing and filtering, and text generation all work and are live-verified against every supported provider. Streaming, tool calling, structured output, and non-text modalities are not implemented yet. The API is settled but may still shift before 1.0.

Docs: USAGE.md for the full API and CLI reference · CHANGELOG.md for version history.

Quick start

from keycall import KeyCall, Message, ModelCategory, TextInput

with KeyCall(provider="openai", api_key=secret) as client:
    discovery = client.list_models(categories={ModelCategory.TEXT_GENERATION})

    result = client.generate_text(
        model=discovery.models[0].id,
        messages=[Message(role="user", content=[TextInput(text="Hello.")])],
    )

print(result.text)
print(result.usage.total_tokens)
print(result.round_trip_duration_ms)
  • Explicit provider, always. KeyCall never guesses which vendor issued a key and never sends a credential to more than the one provider you name.
  • No credential storage. Keys live in memory for the client's lifetime, wrapped in a redacting type that keeps them out of reprs, logs, traces, exceptions, and pickles. Your app decides how to store them.
  • Model filtering built in. Text-generation models by default; embeddings, image, audio, and other categories on request; unknown models never silently enter the default picker.
  • Typed errors. Invalid key, rate limit, provider outage, timeout, and malformed response are distinguishable, never collapsed into "invalid key."
  • Hardened transport. TLS always verified, redirects refused, response sizes capped, SSRF and DNS-rebinding guards on custom endpoints, and generation is never silently retried.

Provider support

Live-verified 2026-08-05 (one model-list call plus one bounded generation per provider):

Provider Protocol Listing Generation
OpenAI openai verified verified
Anthropic anthropic verified verified
Google Gemini gemini verified verified
DeepSeek openai-compatible verified verified
Perplexity openai-compatible verified verified
Moonshot/Kimi openai-compatible verified verified
Custom endpoint (explicit base_url) openai-compatible fixtures only fixtures only

Two provider quirks worth knowing, both handled:

Gemini keeps retired models in its list endpoint (gemini-2.5-flash returns "no longer available to new users") with no lifecycle field to pre-filter on, and meters quota per model and tier, so one model's 429 says nothing about the next. Its supportedGenerationMethods is also a transport signal rather than a modality claim: TTS variants advertise generateContent and then refuse a text response, so KeyCall lets a distinctive identifier modality outrank it.

Perplexity's GET /v1/models is scoped to the Agent API and returns vendor-prefixed router models (anthropic/..., perplexity/sonar) that the Sonar route rejects. Sonar's own models are not API-discoverable, so KeyCall maintains them in its catalog and uses the list call purely as a credential check.

Because of quirks like these, keycall verify --generate walks the filtered models in provider order and prints the outcome of every attempt until one succeeds, so drift stays visible rather than being masked by a silent retry.

Verifying keys from the command line

keycall verify --source ./keys.toml
keycall verify --source ./keys.toml --generate

--generate also makes one small bounded call per target. Sources can be TXT, JSON, or TOML, an explicit env:VAR_NAME reference, or an interactive prompt. See keycall-test-keys.example.toml for the format and USAGE.md for the full reference. Keys never appear in output, and KeyCall never writes to or deletes your credential file.

Installation

pip install keycall

Development

pip install -e ".[dev]"
pytest

Author

Built by Mo Shehu.

License

AGPL-3.0-or-later. See LICENSE.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

keycall-0.1.0.tar.gz (63.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

keycall-0.1.0-py3-none-any.whl (58.5 kB view details)

Uploaded Python 3

File details

Details for the file keycall-0.1.0.tar.gz.

File metadata

  • Download URL: keycall-0.1.0.tar.gz
  • Upload date:
  • Size: 63.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for keycall-0.1.0.tar.gz
Algorithm Hash digest
SHA256 a1c38c8007af490088b6d4619f06865b9267c753ff73b6d3797f8c35ede923c8
MD5 95d42e535037d21b1bbd007b387bf6ba
BLAKE2b-256 0290856ca5e1a9b69c3ca2dc1e855c329b84b5627be1f487a6c3fbb149a19116

See more details on using hashes here.

Provenance

The following attestation bundles were made for keycall-0.1.0.tar.gz:

Publisher: release.yml on shehuphd/keycall

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file keycall-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: keycall-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 58.5 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for keycall-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 cf662c7445b400b9b0d380f443f9b088bd65047f5ea4924ddbb1cb367189f113
MD5 59e2fde90afdbc03fc3d4622e8538622
BLAKE2b-256 66b187becb63129f8b3b02e210cd7be3180f4313326d7f9c2f0d4ef6eb8b63c7

See more details on using hashes here.

Provenance

The following attestation bundles were made for keycall-0.1.0-py3-none-any.whl:

Publisher: release.yml on shehuphd/keycall

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page