Forum

Notifications
Clear all

Is there a community-maintained list of safe-to-allow model provider URLs?

3 Posts
3 Users
0 Reactions
29 Views
(@ciso_skeptic_linda)
Eminent Member
Joined: 3 months ago
Posts: 25
Topic starter   [#1392]

Vendors publish "required" endpoints that are wildly over-permissive. Their default configs are a joke for security. I need to know the absolute minimum for an agent to function, not their sales-driven wishlist.

* Is anyone maintaining a vetted, technical list of model provider URLs (OpenAI, Anthropic, etc.)?
* One that breaks down core inference APIs vs. ancillary services (monitoring, billing, "optional" features)?
* Updated with runtime changes so our allowlists don't break or become a backdoor?

If it doesn't exist, we should start one. I'm tired of playing whack-a-mole with outbound rules every quarter.

Linda


Trust but verify? I skip the trust.


   
Quote
(@framework_hardener)
Eminent Member
Joined: 3 months ago
Posts: 27
 

Linda, you're absolutely right about the whack-a-mole problem. I haven't seen a maintained, vetted list, just scattered gists and internal docs that rot.

The real headache is the "optional" features. Take OpenAI: you can block `platform.openai.com` and just allow `api.openai.com` for core chat/completions, but then their Python library's implicit call to `api.openai.com/v1/audio/...` for TTS might surprise you if a dev uses a new feature. Vendors silently add endpoints under the same domain.

We could start a repo, but the maintenance burden is huge. Maybe we crowdsource a simple tool that pings and validates the minimal set? A script that attempts core functions against a proposed allowlist and reports failures.

Otherwise, it's just another list that's out of date in six weeks.


hardened by default


   
ReplyQuote
(@reasoning_dev)
Eminent Member
Joined: 3 months ago
Posts: 22
 

A validation script is a clever angle. The problem I've hit with that approach is that you need live API keys and credits to test each provider's endpoints. That creates a barrier for crowd-sourcing, and you can't easily run it in a CI pipeline for a private deployment.

What if the tool generated the minimal allowlist *and* a set of integration tests? The tests could be run by the actual dev team with their own creds, flagging when a new endpoint is called. This shifts the maintenance from a central list to each project's test suite catching drift.

But as you said, the domain sprawl is the killer. OpenAI adding TTS under the same base path is exactly the kind of silent expansion that breaks a static list.



   
ReplyQuote