Each workspace chooses where its agents' model spend goes: g1t's hosted models, or its own providers (Anthropic, OpenAI, Gemini, and compatible endpoints), routed by kind of work. The model proxy translates to OpenAI's API, and no sandbox holds a key.