PACINFRAX · RESOURCES
Build with explicit boundaries.
Start with the local development contract. Credentials, project authorization and inference each have a separate responsibility.
Development documentation only. The public API is not available. GPU connections are deferred until hardware is provisioned; local inference remains a deterministic mock.
1. Check the web service
The website runs on port3003. Port3000 is reserved for another local development tool.
curl --fail http://localhost:3003/api/healthzExpected response: {"status":"ok"}. This proves web liveness only, not API, database or model readiness.
2. Keep credentials separate
- Browser login uses an opaque session cookie. Provider tokens must stay server-side.
- User access tokens identify people; project API keys authorize workload scopes.
- Project permissions come from the control directory, not browser claims.
No real credential is issued by the console demo. Never paste secrets into chat or commit them.
3. Inspect the local catalog
After separately starting and configuring the gateway on4100 with a synthetic test key:
curl --fail http://127.0.0.1:4100/v1/models \
-H "Authorization: Bearer $PAX_PROJECT_API_KEY"The key needs models:read. Set it in your local environment. Do not replace it with an ID token or use production credentials.
4. Understand failure states
- 401: credential missing, invalid, expired or revoked.
- 403: scope or project access denied. Do not retry with a broader credential automatically.
- 429: admission limit reached; follow the response retry guidance.
- 503: a required dependency is unavailable; do not treat health as readiness.
Capture sanitized request IDs for diagnosis, never tokens or prompt content.
Developer tools
The local read-only CLI can inspect service health, project metadata, key metadata and the gateway catalog. Build it in the repository, then inspect help:
npm run build --workspace @pacinfrax/cli
node packages/cli/dist/main.js help
node packages/cli/dist/main.js health controlAuthenticated commands require explicit user or project auth mode and environment credentials. They do not create keys, submit inference, or provision GPUs.
Inspect the implemented API contract →Server-side SDKs
Local TypeScript and Python clients implement models, text completion and validated streaming. They are not published packages or live GPU services.
Open the SDK quickstart →What is next
Authenticated console workflows, deployed SDK journeys, usage receipts and support diagnostics are under development. Real GPU inference, commercial billing and production deployment require separate verification and approval.
Read the security boundaries →