Skip to content

feat(usage-limits): add Moonshot balance providers - #186

Open
mynameistito wants to merge 4 commits into
mainfrom
feat/issue-170-moonshot-balance
Open

mynameistito wants to merge 4 commits into
mainfrom
feat/issue-170-moonshot-balance

Conversation

@mynameistito

@mynameistito mynameistito commented Oct 5, 2026 •

Copy link
Copy Markdown
Owner

What changed

  • Add separate moonshotai (USD) and moonshotai-cn (CNY) balance providers, using each region's official endpoint and auth entry.
  • Read available_balance as-is, including zero and negative values, and require a successful response before displaying it.
  • Update the config schema, examples, READMEs, and usage-limits guide with the region and credential-isolation details.

Verification

  • bun run check
  • bun run typecheck
  • bun run test
  • bun run build
  • bun run test:package
  • bun run test in apps/web

Closes #170


Summary by cubic

Adds Moonshot/Kimi API pay-as-you-go balance tracking as two region-isolated providers: moonshotai for global USD balances and moonshotai-cn for China CNY balances. Each provider only uses its region's official endpoint and never sends credentials to the other region.

Behavior details

  • Displays the API's available_balance directly, including zero and negative amounts.
  • Fails closed when the response lacks code: 0, status: true, or a finite numeric balance.
  • Updates the config schema, examples, and docs for both providers, including a Moonshot logo in the web docs. Closes feature: add Moonshot/Kimi API balance providers #170.

Written for commit e126062. Summary will update on new commits.

Review in cubic

@changeset-bot

changeset-bot Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: e126062

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 2 packages
Name Type
@mynameistito/opencode-usage-limits Minor
@mynameistito/opencode-plugins-docs Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@github-actions github-actions Bot added dependencies Automatically managed pull request metadata docs Automatically managed pull request metadata release Automatically managed pull request metadata size/l Automatically managed pull request metadata usage-limits Automatically managed pull request metadata labels Oct 5, 2026
@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 37 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: f99d6cf6-364b-4595-bd59-98c52522eb80
📥 Commits

Reviewing files that changed from the base of the PR and between 61f39cf and e126062.

📒 Files selected for processing (5)
  • apps/web/docs/usage-limits.mdx
  • apps/web/theme.css
  • packages/opencode-usage-limits/__tests__/providers/index.test.ts
  • packages/opencode-usage-limits/__tests__/providers/moonshotai.test.ts
  • packages/opencode-usage-limits/src/providers/moonshotai.ts

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 5f11f916-0814-4652-83d0-2ee2aa8e847f
📥 Commits

Reviewing files that changed from the base of the PR and between 7383cea and 61f39cf.

📒 Files selected for processing (23)
  • .changeset/moonshotai-balance.md
  • README.md
  • apps/web/docs/index.mdx
  • apps/web/docs/usage-limits.mdx
  • packages/opencode-usage-limits/README.md
  • packages/opencode-usage-limits/__tests__/config.test.ts
  • packages/opencode-usage-limits/__tests__/format.test.ts
  • packages/opencode-usage-limits/__tests__/providers/helpers.ts
  • packages/opencode-usage-limits/__tests__/providers/index.test.ts
  • packages/opencode-usage-limits/__tests__/providers/moonshotai.test.ts
  • packages/opencode-usage-limits/__tests__/usage.test.ts
  • packages/opencode-usage-limits/examples/usage-limits.jsonc
  • packages/opencode-usage-limits/package.json
  • packages/opencode-usage-limits/src/config-schema.ts
  • packages/opencode-usage-limits/src/config.ts
  • packages/opencode-usage-limits/src/errors-shared.ts
  • packages/opencode-usage-limits/src/errors/response-decode.ts
  • packages/opencode-usage-limits/src/format.ts
  • packages/opencode-usage-limits/src/providers/index.ts
  • packages/opencode-usage-limits/src/providers/moonshotai.ts
  • packages/opencode-usage-limits/src/types.ts
  • packages/opencode-usage-limits/src/usage.ts
  • packages/opencode-usage-limits/usage-limits.schema.json

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Summary

Summary by CodeRabbit

  • New Features
    • Added separate Moonshot/Kimi API balance providers for global USD and China CNY accounts, with optional regional credentials.
    • Balances, including zero and negative amounts, can now be displayed accurately.
    • Added setup examples and documentation distinguishing API balances from Kimi For Coding subscription quotas.

Walkthrough

This change adds global and China Moonshot/Kimi API balance providers. It adds region-specific configuration and credential handling, accepts finite negative balances, and updates provider registration, tests, examples, and documentation.

Changes

Moonshot/Kimi API balances

Layer / File(s) Summary
Provider configuration and auth
packages/opencode-usage-limits/src/types.ts, packages/opencode-usage-limits/src/config-schema.ts, packages/opencode-usage-limits/src/config.ts, packages/opencode-usage-limits/src/errors-shared.ts, packages/opencode-usage-limits/usage-limits.schema.json, packages/opencode-usage-limits/__tests__/config.test.ts
Adds moonshotai and moonshotai-cn configuration and auth parsing, with corresponding schema entries and tests.
Signed balance amounts and display
packages/opencode-usage-limits/src/usage.ts, packages/opencode-usage-limits/src/format.ts, packages/opencode-usage-limits/__tests__/usage.test.ts, packages/opencode-usage-limits/__tests__/format.test.ts
Allows finite signed balance amounts and formats negative currency balances. Tests cover negative values and negative values that round below one cent.
Regional balance requests and provider wiring
packages/opencode-usage-limits/src/providers/moonshotai.ts, packages/opencode-usage-limits/src/providers/index.ts, packages/opencode-usage-limits/src/errors/response-decode.ts, packages/opencode-usage-limits/__tests__/providers/*
Adds regional balance requests, response validation, credential selection, provider registration, and tests for regional credentials, errors, and custom origins.
Documentation, examples, and release metadata
.changeset/moonshotai-balance.md, README.md, apps/web/docs/*, packages/opencode-usage-limits/README.md, packages/opencode-usage-limits/examples/usage-limits.jsonc, packages/opencode-usage-limits/package.json
Documents the two regional pay-as-you-go balances and their distinction from Kimi For Coding subscription quotas. Adds configuration examples and release metadata.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant UsageLimits
  participant MoonshotProvider
  participant CredentialSources
  participant MoonshotBalanceAPI
  UsageLimits->>MoonshotProvider: Request regional balance
  MoonshotProvider->>CredentialSources: Resolve matching region credential
  MoonshotProvider->>MoonshotBalanceAPI: GET balance endpoint with bearer token
  MoonshotBalanceAPI-->>MoonshotProvider: Return balance response
  MoonshotProvider-->>UsageLimits: Return regional currency balance
Loading

Merge Risk: ⚪ Minimal · up to 61f39

No actionable pre-merge issue was established; the regional balance providers are ready for normal merge checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 61f39

The integrations keep automatically discovered credentials region-specific and validate responses before displaying balances. Explicit credential overrides remain user-controlled. No introduced security defect was established, but live redirect behavior and credential-file permissions remain unverified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The new sensitive scope is the selected Moonshot account credential and its returned balance within the local user's plugin process. Redirecting an initial request to a custom origin requires explicit credential configuration. The loaded configuration comes from the user's XDG directory, not a repository configuration path. Credential compromise impact would depend on the external key's permissions, which were not established.

Trust Boundaries and Controls

  • observed — Tests assert matching regional bearer credentials for OpenCode entries and nested auth-file entries. The auth-file root-key path is a documented explicit override, so reusing that file can reuse one credential across regions; the advertised isolation is not a universal restriction on user-supplied overrides.
  • observed — The unchanged HTTP runtime delegates redirects to globalThis.fetch without an explicit redirect policy or final-origin check. Credential-file reads are bounded and close their file handles, but the inspected implementation does not validate file ownership or permissions. These are remaining production-control gaps, not established credential-exfiltration findings.

Resilience and Maintainability Implications

  • observed — Regional state is keyed separately, invalid responses cannot publish a new successful balance, and interruption handling preserves cancellation rather than converting it into an ordinary refresh result. Same-ID cached values lack credential provenance, but that local stale-display behavior predates this PR; no cross-region state transfer was established.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely identifies the main change: adding Moonshot balance providers.
Description check ✅ Passed The description explains the provider behavior, regional credential isolation, linked issue, and validation commands. It does not include the template’s OpenCode and plugin compatibility details or an…
Linked Issues check ✅ Passed #170 requires independent global and China balance providers, direct available_balance display, fail-closed validation, and region-isolated credentials. src/providers/moonshotai.ts uses the offici…
Out of Scope Changes check ✅ Passed The changes to balance parsing and formatting support #170's requirement to display authoritative zero and negative balances. Provider registration, config/auth wiring, tests, changeset, and documenta…
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 1…
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks the balance line,
For dollars, yuan, and signs that shine.
Two regions keep their keys apart,
Zero and negatives still play their part.
I nibble clover, pleased to see,
Clear balances hopping home to me.

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Deploying with Alchemy Alchemy

The latest deployment for this pull request.

Status Name Latest commit Updated (UTC)
Deployment successful
View Cloudflare logs
opencode-plugins-docs-pr-186 e126062c 2026-10-05T09:18:49.989Z

Diagnostics: View GitHub Actions run

@codecov

codecov Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

This branch was successfully deployed

1 active deployment
pr-186 — e126062c Deployed Oct 5, 2026 by github-actions[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Automatically managed pull request metadata docs Automatically managed pull request metadata release Automatically managed pull request metadata size/l Automatically managed pull request metadata usage-limits Automatically managed pull request metadata

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feature: add Moonshot/Kimi API balance providers

1 participant