Leif holds nothing. Every credential lives in your stores — OS keychain, process env, your own cloud's secret store, or the provider's own CLI keystore. Leif is a resolver, not a holder.
This page maps every provider to its current and target connection method. Manage on any provider card opens its panel in a floating dialog with Diagnose / Activate / Details tabs — a live diagnosis, copy-paste activation commands per OS, and where that provider stands versus a stronger route. Esc, the dimmed background, or Done all close it.
Two different things share this page. Apps that connect TO Leif (Claude Desktop, Codex, the cloud hosts) attach by writing one MCP entry into their own config. Providers Leif routes to are activated inside Leif and never connect as a host — that distinction is why Vertex/GCP appears under providers, not apps.
▶ Test connection reports the true resolve + registry status. It is not a live provider ping: green means the credential resolves and is registered, amber means setup is needed, red means policy is blocking it.
AI — LLM Connections
What Leif can route to — and which of that provider's apps can route back through Leif.
AI App Connections
These attach to Leif but hold no credential and route to no model of their own.
AI Cloud Connections
Web and phone apps — claude.ai, ChatGPT, Grok, Gemini — reach Leif through a tunnel giving its edge a public HTTPS URL. Nothing goes public until you press Start.
AI IDE Connections
Coding surfaces — editor extensions and terminal-first agents. They attach exactly like any other app; Leif becomes a tool your coding agent can call.
src/auth/strategies.ts · src/storage/resolve.ts
Attaching an app is not the same as turning on a model route — they are separate acts with separate buttons, and Leif will never conflate them. Every attach is previewed before it is written, backed up, and recorded as a locally signed receipt you can revoke.