Which models, context lengths, formats and tool capabilities have been verified for this project?
Begin with a reproducible task and agree on formats, permissions and expected output. Connect incrementally and retain the original workflow as a fallback.
Which providers process the data, where is it stored, for how long and who can access it?
Never expose credentials in browsers or prompts. Sanitize sensitive inputs and confirm providers, data purposes and access permissions.
How are timeouts, rate limits and retries handled? Do write operations use idempotency keys and human approval?
Routing must respect data residency and access restrictions. Limit automatic retries for side-effecting tasks and retain approval and idempotency controls.
Which input, output and cache fields are metered? How are fees, refunds and support hours agreed?
Token usage is not the amount payable. Prices, cache billing and exchange rates follow agreed rules. Budget alerts are not verified hard limits.
This is general practice guidance, not a customer case, API specification or service commitment. Confirm scope, pricing and responsibilities for each project.