Independent. No commercial relationship with any provider indexed here — no credits, no programme, no agreement — checked 8 September 2026. Disclosures · how every number here is evidenced

providers.sgit.ai

Where the key goes — provider reports for people who have to deploy one

One question decides most integrations and almost nobody writes it down: where does the credential live, and what bounds it. This is the hub for a family of sites that answer it one provider at a time — with dates, costs and failures attached.

Prose from the video vault at commit 7d1916aca5f3, 8 September 2026. The four patterns come from the source vault; everything about a provider comes from that provider's own site. When the vault moves ahead, this page is behind — and says so rather than guessing.

Both domains in this family now serve. verified 8 Sep 2026 providers.sgit.ai and elevenlabs.providers.sgit.ai were unpointed for the whole of this site's first release, which is why the links here are not typed but measured: bin/sync-providers.py fetches each site's own published index from its canonical host, and every cross-link goes to whichever host answered. A build check fails if a link disagrees — which caught canonical links while the domains were dead, and now catches a stale project path left behind after they came up.

The argument, in one paragraph

Vendor documentation tells you what an API does. It does not tell you what it cost on a named workload on a named date, what broke, or which credential patterns the product can actually support — and the third one is the question that decides your architecture. A site in this family exists to answer those three, per provider, with every claim carrying the state that says how far it can be trusted.

The strongest form of the answer is a pattern rather than a rule: a browser application can use a paid API without ever holding the key, because a host holds it and enforces the terms. That is pattern three, it is specified and not shipped specified, not shipped, and saying so is the point.

The family

voice · text to speech

ElevenLabs

Text to speech with character-level timestamps. Scoped keys, no per-key spend limit, and the first render's four failures.

https://elevenlabs.providers.sgit.ai

verifiedmeasuredvendor docs
Read the report →
models · one API, many models

OpenRouter

Provisioned keys with a spend limit and a reset — the one provider in this family that can do pattern one. Not built yet.

https://openrouter.providers.sgit.ai · not serving yet

specified, not shipped
Not built yet

The two axes

Everything in this family is indexed on two questions that are usually mixed together. They are orthogonal, and the intersection is on the patterns page.

The credential pattern — a property of the provider

Where the credential lives and what bounds it: nothing, a spend limit, a clock, or a host the application cannot reach. It is decided by what the vendor's product can mint, and no amount of care in your code changes it.

The four patterns →

The capability tier — a property of your tool

What state it keeps: none, this device, or a vault. It decides whether your tool works for somebody with no key, and whether it survives being downloaded and run somewhere else.

The tier axis →

What makes this different from a review site

Nothing here is replaceable by a link to the vendor. If a section could be, it should be deleted — the vendor's own documentation is better and stays fresher.

Every claim carries a state. Six of them, from verified by execution on this date to specified and not shipped, joined to the pages that make them at build time. A claim that appears on a page and not in a ledger fails the build. How that works, and the current mix across the family →

The failures are published. Including our own: the first render in this family broke four times before it made a sound, and one of the four was our bug rather than the vendor's.

And there is no commercial relationship with anybody. None, checked and dated, with the page built before there was anything to disclose so that its later appearance cannot be read as a signal.

The one measurement worth reading first

3 September 2026 · OpenRouter

A 402 that was the point, not an outage

At $4.79 used against a $5.00 limit on a provisioned key, every audio request was refused: 402 — this request requires at least $0.50 in balance for audio output, with limit_source: openrouter_key_limit. verified 3 Sep 2026

That is a bound doing its job, observed rather than described: chosen in advance, enforced by the platform rather than by our code, and visible in the refusal. It is the only evidence in this family that any of this is enforceable in practice — and the reason the comparison is worth generating, because the other provider here cannot do it at all vendor docs 5 Sep 2026.