loadAiProviderConfig

fun loadAiProviderConfig(getKey: (ProviderId) -> String?, selectedProvider: ProviderId = ProviderId.OFFLINE_FALLBACK, useOnDevice: Boolean = false): AiProviderConfig(source)

Builds an AiProviderConfig from whatever getKey returns for each cloud provider — the read side of SecureKeyStore.setKey, so a settings screen's "save key" action and buildProviderChain's "read keys" side stay in sync without the app gluing them together itself. Takes a plain function rather than a SecureKeyStore so this stays testable with a fake map in commonTest without needing a real platform store; pass store::getKey at the call site.

selectedProvider and useOnDevice aren't secrets (no reason to encrypt "which provider is picked"), so the caller passes them through from wherever its own app settings already keep them; this only owns the part that actually needs at-rest protection.