Smart routing
Describe the result you want, in text or a voice transcription. Autopilot states the next action and chooses direct work, a bounded delegate, or parallel Wave work. Before delegation it explains the harness, provider, model, effort and reason. It uses the current user's configuration; an installed binary alone does not establish model access.
Direct work fits one bounded owner with a deterministic check. Delegate isolates implementation or research and supplies independent review when the model identity differs. Wave coordinates two or more approved, file-disjoint and order-independent slices behind dependency, cost and acceptance checks. Wave slices resolve through runtime-route --in-place, the same resolver /delegate uses; claude or codex supervise a slice directly, any other implementer runs headless via delegate-exec.
Inspect and select
devkit runtime-route --inventory --models --json
devkit runtime-route --inventory implement --models --json --probe-runtime pi
devkit runtime-route implement --spec devkit/specs/example.mdModel inventory runs bounded native probes without inference and emits only allowlisted fields. installed, native catalog membership, local authentication configuration and live verification are separate facts. live_verified remains false: a configured key can be expired, revoked or unentitled. Pi checks exact offline catalog membership before its provider-level auth status; another harness's login is not imported. Catalog evidence is not a quality benchmark or a billing guarantee.
With --spec, the first matching row of implement_rules in content/model-routing.json orders the implement candidates for /delegate and Wave slices alike — the table and its rationale are the source of truth, not this page.
Explicit DEVKIT_RUNTIME_<TIER> overrides personal runtime preference and spec rules. DEVKIT_DELEGATE_PROVIDER, DEVKIT_DELEGATE_MODEL and DEVKIT_DELEGATE_EFFORT override the selected runtime's personal tuple and canonical defaults. A rejected explicit selection fails instead of silently substituting another model. The receipt includes RUNTIME, PROVIDER, MODEL, EFFORT, MODEL_SOURCE, MODEL_READINESS, ROUTE_REASON and skipped candidates. Pass its tuple unchanged to delegate-visible; required reviews retain their model independence and frozen scope.
Personal policy
Merge only the desired fields into $DEVKIT_HOME/config.json (default ~/.onedot-devkit/config.json). No credentials belong here:
{
"routing": {
"preferences": {"implement": ["pi", "prime", "dsh", "kimi", "codex", "claude"]},
"models": {
"pi": {"implement": {"provider": "openai-codex", "model": "gpt-6.1-sol", "effort": "medium"}},
"prime": {"implement": {"provider": "openai-codex", "model": "gpt-6.1-sol", "effort": "medium"}},
"kimi": {"explore": {"provider": "managed:kimi-code", "model": "kimi-code/k3"}}
},
"pi_extensions": {"anthropic": ["/absolute/personal/path/to/reviewed-extension.ts"]}
}
}Use model identifiers from the user's native catalog. Pi supports its configured native providers, including API key and OAuth authentication. OpenAI Codex remains OAuth only; API credentials cannot silently replace that subscription route. Extension discovery stays disabled. Only absolute, existing personal files outside the project, explicitly listed above, are loaded. The installed Claude adapter requires that allowlist entry; its presence does not establish billing terms.
Kimi selects an existing configured alias and has no effort flag. DSH's effective model comes from the composed headless profile and native settings. Configured tuple changes use a private settings snapshot and native per-run patch, preserving personal files. Its llm-pi-ai plugin can use Codex OAuth when configured inside DSH; Pi's login does not configure DSH automatically. Prime uses an explicit provider/model/thinking tuple and its existing gate and patch lifecycle. Unknown native authentication remains visible in the receipt.
Evidence and fallback
Harness overhead and model quality are separate. The local Pi/DSH DeepSeek V4 comparison covered two small read-only runs: Pi took fewer turns and less elapsed time; DSH found additional issues. It establishes no general implementation ranking and does not measure DeepSeek V4.1. Prime fits tasks needing observable content gates and patch intake. Defaults and personal preferences are policy choices, not claims of measured superiority.
Evaluate new pairs on representative accepted results, including review, retries and recovery. A missing auth configuration removes a Pi candidate. Missing catalog entries or unsupported native overrides fail before inference. A fallback must retain task permissions and be explained; an explicitly pinned tuple disables automatic cross-runtime retry.