Goose
Goose is Block’s open-source agent. It supports OpenAI-compatible providers via configuration.
Verified against Goose v1.52.0. The config below is re-run against that release every week.
Configure
Goose’s OpenAI provider takes the host only. It appends
v1/chat/completions itself, so OPENAI_HOST must not end in
/v1. With /v1 on the host every request goes to
/v1/v1/chat/completions and fails with a 404. This is the opposite
of OpenCode, whose baseURL must end in /v1. Each tool
decides for itself how much of the path it adds.
Set the provider, host and model in ~/.config/goose/config.yaml:
GOOSE_PROVIDER: openai
OPENAI_HOST: https://api.lowrouter.ai
GOOSE_MODEL: auto/mistralai/mistral-large-2512The API key does not go in that file. Goose ignores an
OPENAI_API_KEY line in config.yaml because it reads secrets from the
system keyring, and the symptom is a 401 Missing Authorization header on the first request. Two ways to supply it:
- Run
goose configure, pick the OpenAI provider and paste the key when prompted. It is stored in the keyring. - Export it in the environment, which takes precedence over the keyring. This is the form for scripts, containers and CI:
export GOOSE_PROVIDER=openai
export OPENAI_HOST=https://api.lowrouter.ai
export OPENAI_API_KEY=sk-lr-...
export GOOSE_MODEL=auto/mistralai/mistral-large-2512Then start a session:
goose sessionOn a headless machine with no keyring service (a container, a CI
runner), also set GOOSE_DISABLE_KEYRING=1 so Goose falls back to
file-based secret storage instead of failing to open a keyring.
Picking a model
Set GOOSE_MODEL to any LowRouter model ID. Goose drives its tools
through function calling, so for agentic tasks (file reading, shell
tools, multi-step reasoning) pick a model with the function-calling
tag. The model browser filtered to them
lists every one.
goose configure cannot enter a custom model name; set GOOSE_MODEL
directly, as above.
Recommended setup
- Use a dedicated key. As with the other agents, agentic loops can run away; a key of its own lets you see the spend per agent and revoke it without touching anything else.
- Limit the toolset Goose has access to. Goose’s
extensionsconfig lets you allow only the tools the workflow needs, and fewer enabled tools means fewer surprises. - Set a step limit. Goose has a max-step setting; cap it at a small number for unattended runs.
Troubleshooting
404on every request:OPENAI_HOSTends in/v1(or another path). Goose addsv1/chat/completionsitself; the host is the bare origin.401 Missing Authorization headerorNo api key passed in: the key is inconfig.yaml, where Goose does not read it. Move it to the environment or togoose configure.- Tool calls fail silently: verify the chosen model actually supports function calling (its page on the model browser). Some smaller models don’t.
