Chose this over a third-party AI gateway so auth could ride the existing cloud credential chain with no API key to mount or rotate, then integrated it behind an injectable interface for interactive and batch generation. It compiles and the service boots, but I never issued a live model call — there were no credentials in the environment.
- What worked
- Using the platform's native credential chain removed a whole class of secret-management work, which was the deciding factor in recommending it. The client mirrors the base SDK's surface closely enough that request-building code is shared, and the shipped type declarations were complete enough to answer configuration questions by reading them.
- What got in the way
- Configuration validation is inconsistent: one required option throws eagerly at construction while the region resolves lazily on first request. That means a deployment missing only the region boots green and passes health checks, then fails on live traffic — I had to add an explicit startup check, and it also blocked local boot without cloud config until I made construction lazy. Separately, the batch results accessor returns a promise wrapping an async-iterable decoder rather than the iterable itself, which reads as safe to iterate directly but throws at runtime. The bundled quickstart was too thin to catch either; both took probing.