Package-level declarations
Types
One increment of a AiProvider.completeStream reply.
A cloud (or on-device) chat-completion backend — one turn in, one text reply out.
Config for HttpChatProvider: the caller's own SSE chat backend, not a named vendor.
AiProvider over a caller-supplied HTTP endpoint speaking the same data: <json> / data: [DONE] SSE contract as AnthropicProvider/OpenAiProvider/GeminiProvider — the shape cv-siddharth-kmp and Candidai were each hand-rolling their own parser for. Every reply frame decodes as HttpChatStreamEvent; the backend is expected to emit {"text":"..."} per token and close the stream (optionally preceded by a data: [DONE] line, discarded rather than decoded) rather than any vendor-specific event shape. See HttpChatConfig.requireDoneSentinel for a backend whose [DONE] isn't actually optional.
Which provider a consumer has selected + the keys needed to build the fallback chain (buildProviderChain). ON_DEVICE and OFFLINE_FALLBACK are the two slots every consumer plugs their own AiProvider into (buildProviderChain's onDevice/fallback params) — this module doesn't ship either implementation. Naming ANTHROPIC/OPENAI/GEMINI here moves that provider to the front of buildProviderChain's cloud chain, ahead of the fixed priority order.
Backed by :settings's EncryptedSharedPreferences (MasterKey.AES256_GCM) store.
Where a BYOK provider API key persists between app launches.
Backed by :settings's KeychainSettings (service com.siddharth.kmp.secure).
Backed by :settings's AES-256-GCM-encrypted PropertiesSettings file (default ~/.kmp-toolkit-secure/secure_settings.enc, key file beside it, 0600).
Not secure. window.sessionStorage is plaintext, readable by any script running on the same page (including an XSS payload), and survives only the current tab's lifetime — closing the tab or opening a new one loses the key. This exists so a browser demo has somewhere to put a pasted key rather than re-prompting on every reload of the same tab; it is not the Keystore/ Keychain guarantee the other three platforms give.
Functions
Builds the provider fallback chain from config: on-device first (if enabled and onDevice is supplied) → configured cloud providers → fallback last. config.selectedProvider, when it names a cloud provider with a non-blank key, is moved to the front of the cloud group so picking a provider actually tries it first; the remaining configured providers still follow as fallbacks, in the fixed Anthropic > OpenAI > Gemini order (a no-op when nothing is selected, since ProviderId.OFFLINE_FALLBACK and ProviderId.ON_DEVICE match no cloud entry). onDevice and fallback are caller-supplied rather than hardcoded — this module ships no on-device LLM or app-specific offline fallback of its own.
Builds an AiProviderConfig from whatever getKey returns for each cloud provider — the read side of SecureKeyStore.setKey, so a settings screen's "save key" action and buildProviderChain's "read keys" side stay in sync without the app gluing them together itself. Takes a plain function rather than a SecureKeyStore so this stays testable with a fake map in commonTest without needing a real platform store; pass store::getKey at the call site.