# Route across providers (/guides/routing-and-providers)



## Automatic routing [#automatic-routing]

Set `provider` to `auto` or omit it. Explicit fallback providers are tried in your order, followed
by other managed or BYOK providers in their configured order.

```json
{
  "provider": "auto",
  "source": {
    "kind": "environment",
    "environment": "metal/node",
    "version": "latest"
  },
  "resources": {
    "vcpu": 2,
    "memory_mb": 4096,
    "architecture": "any"
  },
  "lifecycle": {
    "runtime_timeout_seconds": 1800,
    "on_runtime_timeout": "destroy"
  },
  "fallback": {
    "providers": ["e2b", "runloop", "daytona"],
    "max_attempts": 3
  }
}
```

Current routing uses your fallback order and the configured provider order. It does not rank
candidates by price, speed, reliability, or a balanced score.

By default, automatic routing only considers providers that can execute processes and read and
write files. Set `features.process.execute`, `features.filesystem.read`, or
`features.filesystem.write` to `false` to opt out. Add `features` to require more, such as `{"process": {"ordered_output": true}}` for streamed
output or `{"isolation": ["microvm"]}` for a microVM boundary.

## Choose a provider explicitly [#choose-a-provider-explicitly]

Use an explicit provider for capability testing, compliance, or a provider template. Supported providers are Blaxel, Cloudflare, CodeSandbox, Daytona, E2B, Freestyle, Modal, Northflank, Prime Intellect, Runloop, and Vercel.

Provider templates work with CodeSandbox, E2B, Freestyle, Prime Intellect, and Runloop. They cannot use fallback. Prime templates refer to `prime/` images accessible to your Prime account; see [Prime Intellect sandboxes](/guides/prime-intellect).

## Safe fallback [#safe-fallback]

OpenMetal skips any candidate that cannot satisfy the requested source, resources, features,
network policy, or regions before calling it. After a provider call, it falls back after capacity,
unavailable, known absent timeout, and unsupported-request failures. Unknown outcomes enter
reconciliation before any further provider attempt.

Authentication, invalid request, and customer errors do not fan out.

## Bring your own key [#bring-your-own-key]

BYOK credentials belong to an organization, are encrypted at rest, and are never returned by the
API. The provider bills BYOK capacity directly, so it does not consume OpenMetal credits.

```bash
openmetal provider-credential set --file provider.json
openmetal provider-credential list
```

<Callout type="warn" title="Capabilities differ">
  An accepted runtime operation is not proof of provider support. Inspect its terminal state and
  error. See the concepts page before depending on process streaming, files, pause, or endpoints.
</Callout>

See [routing concepts](/concepts/routing) for current capability details.
