Why this exists
#77 was the incident: a revoked per-provider key took Computer offline and every dispatch posted the provider's error into a thread. #78 moved the runtime onto the Vercel AI Gateway, so provider choice and retry left this repo, and #82 stopped failure comments from echoing provider text.
What #78 did not settle is which credential and which model the deployment should keep running on. The restore on 2026-09-23 used the gateway's free tier, which is a stopgap. This issue is the follow-up that was missing: no issue tracked "replace the direct DeepSeek dependency with a free-token path", only the outage did.
Verified on 2026-09-23 (gateway key already stored on the dev host)
| Model slug |
Result |
Notes |
deepseek/deepseek-v4.1-flash (the pinned slug) |
HTTP 403 |
"Free tier users do not have access to this model." Needs purchased credits. |
google/gemini-2.5-flash |
HTTP 200 |
Free-tier eligible. Tags: tool-use, structured-output, vision, reasoning, 1M context. A single-tool probe returned the expected tool_calls with correct arguments. |
deepseek/deepseek-r1 |
HTTP 200 |
Free-tier eligible, tool-use tagged. A single-tool probe returned prose and no tool call, and it is a reasoning model, so it is the weaker pick for a tool-calling pipeline. |
Production therefore runs COMPUTER_MODEL=google/gemini-2.5-flash with AI_GATEWAY_API_KEY set on Production and Preview. The credential's AI Gateway free tier tags list is short — five free-tagged slugs, none of them a general-purpose tool-caller — so "free" is not a durable answer on its own.
Options with the evidence we have
| Path |
Reaches the pinned DeepSeek slug |
Cost |
New external account |
| AI Gateway, paid credits |
yes |
$0.15/M input, $0.60/M output |
no |
| AI Gateway, free tier |
no (403) |
free |
no |
| DeepSeek direct |
yes |
per DeepSeek pricing |
yes — a replacement key; the current one is revoked (401) |
| OpenRouter |
no DeepSeek among the 21 :free slugs (ling-3.0-flash, nex-n2.5, qwen3.8-27b, nemotron, inkling, laguna, gemma-4, north-mini-code) |
free |
yes; a GOOP_OPENROUTER_API_KEY exists on the host but belongs to Goop, not Computer |
| Groq |
no |
free tier |
yes; no key on the host today |
Recommendation
Keep the gateway lane and buy a small AI Gateway credit balance so deepseek/deepseek-v4.1-flash resolves again. One credential then covers all six roles and there is exactly one failure mode to watch, with the free-tier COMPUTER_MODEL override as an already-proven fallback if credits run out.
Credential requirement, for the record
AI_GATEWAY_API_KEY (or Vercel's injected VERCEL_OIDC_TOKEN) is now a deployment prerequisite: without one of the two the runtime cannot reach any model, and preflight says so by name rather than returning a bare status. Whoever deploys Computer must have a gateway credential available to the project. The key in use is the account-level gateway key already stored on the Zo dev host.
Open question for a human
Buy credits for the gateway, or mint a replacement DeepSeek key and keep the free-tier gateway model as the fallback? Both restore the pinned model; the first keeps one credential, the second keeps the direct provider we just removed.
Why this exists
#77 was the incident: a revoked per-provider key took Computer offline and every dispatch posted the provider's error into a thread. #78 moved the runtime onto the Vercel AI Gateway, so provider choice and retry left this repo, and #82 stopped failure comments from echoing provider text.
What #78 did not settle is which credential and which model the deployment should keep running on. The restore on 2026-09-23 used the gateway's free tier, which is a stopgap. This issue is the follow-up that was missing: no issue tracked "replace the direct DeepSeek dependency with a free-token path", only the outage did.
Verified on 2026-09-23 (gateway key already stored on the dev host)
deepseek/deepseek-v4.1-flash(the pinned slug)google/gemini-2.5-flashtool-use,structured-output,vision,reasoning, 1M context. A single-tool probe returned the expectedtool_callswith correct arguments.deepseek/deepseek-r1tool-usetagged. A single-tool probe returned prose and no tool call, and it is a reasoning model, so it is the weaker pick for a tool-calling pipeline.Production therefore runs
COMPUTER_MODEL=google/gemini-2.5-flashwithAI_GATEWAY_API_KEYset on Production and Preview. The credential'sAI Gateway free tiertags list is short — fivefree-tagged slugs, none of them a general-purpose tool-caller — so "free" is not a durable answer on its own.Options with the evidence we have
:freeslugs (ling-3.0-flash, nex-n2.5, qwen3.8-27b, nemotron, inkling, laguna, gemma-4, north-mini-code)GOOP_OPENROUTER_API_KEYexists on the host but belongs to Goop, not ComputerRecommendation
Keep the gateway lane and buy a small AI Gateway credit balance so
deepseek/deepseek-v4.1-flashresolves again. One credential then covers all six roles and there is exactly one failure mode to watch, with the free-tierCOMPUTER_MODELoverride as an already-proven fallback if credits run out.Credential requirement, for the record
AI_GATEWAY_API_KEY(or Vercel's injectedVERCEL_OIDC_TOKEN) is now a deployment prerequisite: without one of the two the runtime cannot reach any model, andpreflightsays so by name rather than returning a bare status. Whoever deploys Computer must have a gateway credential available to the project. The key in use is the account-level gateway key already stored on the Zo dev host.Open question for a human
Buy credits for the gateway, or mint a replacement DeepSeek key and keep the free-tier gateway model as the fallback? Both restore the pinned model; the first keeps one credential, the second keeps the direct provider we just removed.