Goose

Goose is Block’s open-source agent. It supports OpenAI-compatible providers via configuration.

Verified against Goose v1.52.0. The config below is re-run against that release every week.

Configure

Goose’s OpenAI provider takes the host only. It appends v1/chat/completions itself, so OPENAI_HOST must not end in /v1. With /v1 on the host every request goes to /v1/v1/chat/completions and fails with a 404. This is the opposite of OpenCode, whose baseURL must end in /v1. Each tool decides for itself how much of the path it adds.

Set the provider, host and model in ~/.config/goose/config.yaml:

YAML
GOOSE_PROVIDER: openai
OPENAI_HOST: https://api.lowrouter.ai
GOOSE_MODEL: auto/mistralai/mistral-large-2512

The API key does not go in that file. Goose ignores an OPENAI_API_KEY line in config.yaml because it reads secrets from the system keyring, and the symptom is a 401 Missing Authorization header on the first request. Two ways to supply it:

  • Run goose configure, pick the OpenAI provider and paste the key when prompted. It is stored in the keyring.
  • Export it in the environment, which takes precedence over the keyring. This is the form for scripts, containers and CI:
Bash
export GOOSE_PROVIDER=openai
export OPENAI_HOST=https://api.lowrouter.ai
export OPENAI_API_KEY=sk-lr-...
export GOOSE_MODEL=auto/mistralai/mistral-large-2512

Then start a session:

Bash
goose session

On a headless machine with no keyring service (a container, a CI runner), also set GOOSE_DISABLE_KEYRING=1 so Goose falls back to file-based secret storage instead of failing to open a keyring.

Picking a model

Set GOOSE_MODEL to any LowRouter model ID. Goose drives its tools through function calling, so for agentic tasks (file reading, shell tools, multi-step reasoning) pick a model with the function-calling tag. The model browser filtered to them lists every one. goose configure cannot enter a custom model name; set GOOSE_MODEL directly, as above.

  • Use a dedicated key. As with the other agents, agentic loops can run away; a key of its own lets you see the spend per agent and revoke it without touching anything else.
  • Limit the toolset Goose has access to. Goose’s extensions config lets you allow only the tools the workflow needs, and fewer enabled tools means fewer surprises.
  • Set a step limit. Goose has a max-step setting; cap it at a small number for unattended runs.

Troubleshooting

  • 404 on every request: OPENAI_HOST ends in /v1 (or another path). Goose adds v1/chat/completions itself; the host is the bare origin.
  • 401 Missing Authorization header or No api key passed in: the key is in config.yaml, where Goose does not read it. Move it to the environment or to goose configure.
  • Tool calls fail silently: verify the chosen model actually supports function calling (its page on the model browser). Some smaller models don’t.