generativelanguage.googleapis.com), Vertex gives you enterprise-grade rate limits and GCP billing/credits, and is the right choice when you want Gemini usage to draw on your Google Cloud account rather than an AI Studio key.
Vertex authenticates with OAuth2, not an API keyVertex has no static API key for the standard endpoint. Every request needs a short-lived OAuth2 access token (≈1 hour TTL) minted from either a service-account JSON or Application Default Credentials (ADC). Mibyan mints and auto-refreshes these tokens for you — you never paste a token by hand. This is why pasting a temporary token into a custom provider’s
api_key field does not work: it expires mid-session.Prerequisites
- A Google Cloud project with the Vertex AI API enabled and billing active.
- Credentials, one of:
- a service-account JSON key file with the
roles/aiplatform.userrole, or - Application Default Credentials via
gcloud auth application-default login(or the metadata server when running on a GCP VM).
- a service-account JSON key file with the
google-auth— installed automatically the first time you select Vertex (lazy install). Runmibyan setupto repair a managed install if that fails.
Quick Start
Configuration
Vertex splits its settings by sensitivity:- The credential path is a pointer to a secret and lives in
~/.mibyan/.env. - Project ID and region are non-secret routing settings and live in
~/.mibyan/config.yaml.
~/.mibyan/.env:
~/.mibyan/config.yaml:
How authentication works
- Mibyan resolves credentials in this order:
VERTEX_CREDENTIALS_PATH→GOOGLE_APPLICATION_CREDENTIALS→ ADC. - It mints an OAuth2 access token (
cloud-platformscope) and caches it, refreshing when the token is within 5 minutes of expiry. - The token is handed to a standard OpenAI client pointed at the Vertex endpoint:
Regional locations use a
{region}-aiplatform.googleapis.comhost instead. - If a session runs longer than the token lifetime and a request returns
401, Mibyan re-mints the token and retries automatically. On a long-running gateway, if ADC’s refresh token has itself expired, Mibyan falls back to the service-account JSON when one is configured.
Available Models
Vertex requires thegoogle/ vendor prefix on model IDs. The mibyan model picker offers:
global region for Gemini 3.xThe Gemini 3.x preview models are served through the global endpoint. Regional endpoints (us-central1, etc.) may 404 them. Leave region: global unless you have a specific reason to pin a region.Switching Models Mid-Session
/model switches among already-configured providers and models; it does not collect new credentials. Configure Vertex with mibyan model first.
Reasoning / Thinking
Vertex exposes Gemini’s thinking budget through the OpenAI-compatible surface. Mibyan maps its reasoning-effort setting ontoextra_body.google.thinking_config automatically, so reasoning_effort works the same way it does on other Gemini surfaces.
Diagnostics
Troubleshooting
”Vertex AI credentials could not be resolved”
Mibyan found neither a service-account JSON nor working ADC. Either setVERTEX_CREDENTIALS_PATH in ~/.mibyan/.env, or run gcloud auth application-default login. If your project isn’t embedded in the credentials, set vertex.project_id in config.yaml.
google-auth not installed
Mibyan lazy-installs it the first time you select the Vertex provider. If that fails, run mibyan setup to repair the managed install.
404 on Gemini 3.x models
You are probably on a regional endpoint. Setregion: global in the vertex: section of config.yaml (or unset VERTEX_REGION).
403 / permission denied
The service account (or your ADC identity) needs theroles/aiplatform.user role on the project, and the Vertex AI API must be enabled for that project.
Related
- Google Gemini (AI Studio) — static-API-key Gemini without GCP
- AWS Bedrock — another native cloud-provider integration
- AI Providers
- Configuration

