Provider terms
Read this before deploying. The defensible shape is narrow, and the code enforces it rather than merely documenting it.
Read this before deploying
A run executes on the end user's own machine, under their own login, for their own
account.
That is materially different from an operator pooling subscriptions to serve
strangers, and that difference is what the whole design is arranged around. It is not a
matter of intent; it is a property the system has to keep true, which is why the
mechanisms below enforce it rather than describe it.
None of that is legal advice, and Soba cannot give you a compliance guarantee. The
providers' terms are theirs to interpret and change, so read them, and if the exposure
matters to you, take your own advice and consider asking the provider directly.
The invariant#
A run must never be routed to a machine owned by someone other than the user the
run is attributed to.
A machine's pairing token is bound, at the moment it is approved, to the one person
who approved it, never to anything the machine claimed about itself. So the machine
that answers a run and the user the run is billed and attributed to are the same person
by construction, not by convention.
What this rules out#
|
|
| One operator's Claude Max account serving many users' runs |
No. That is pooling |
| A shared pool of pre-paired machines runs are handed out from |
No. The machine is not the user's |
| A user's own laptop serving their own runs |
Yes |
| A user's own VPS or container serving their own runs |
Yes |
| A user's own API key, spent on their own runs |
Yes |
Your own provider keys, serving your own users' runs in your app (app) |
Yes. That is an ordinary API customer using its own account |
Why the code enforces it rather than documenting it#
Because a documented boundary is one a future feature crosses without anybody
noticing. Three mechanisms hold it:
- Attribution. A pairing token acts as exactly one account, and a run may only
reach a machine owned by the user it is attributed to.
- Honest classing. A metered provider key in the machine's environment changes what
the machine advertises, never what the CLI may read. With the owner's opt-in the
runtime is offered as
frontier; without it the runtime is withheld entirely. Either
way a run cannot quietly spend an account the cost class says is not being spent. See
Who pays.
- Settings isolation. A run arriving over the network does not inherit the machine
owner's
CLAUDE.md, hooks, skills or plugins. See
Security model.
The ChatGPT plan channel is the exception to watch#
Moving the credential instead of the compute runs the loop server-side rather than
on the user's machine. It is still the user's own plan and their own account, but the
machine is no longer theirs. That is why the channel ships no default OAuth client
id: an operator supplies one they are entitled to use, and owns that decision.
See The ChatGPT plan channel.
Trademarks#
Claude Code, Codex, Gemini CLI and Ollama are the products of their respective
owners. Soba is an independent tool, not affiliated with or endorsed by any of them, and
it makes no claim on their behalf. What Soba does is keep each run on a machine
dedicated to one user, signed in with that user's own account; whether that use is
permitted is governed by the agreement between that user and their provider.