How model accounts work
A model account is the AI account a runner signs in as to do a task's work: to read, think and write code. Every run of every task uses one. Without a model account that works, no task can run.
This page explains the ideas behind model accounts. For the steps, see Add a model account, Sign a model account in again and Pause or remove a model account. For every control on the screen, see Model accounts.
You find model accounts under Directory, then the Model Accounts tab.
Terms
| Term | Meaning |
|---|---|
| Model account | One AI account runners sign in as. It has a Name, a Slug, a Provider and an Authentication. |
| Name | The label the account shows everywhere. You can change it. |
| Slug | A short code Jaah picks when the account is added, for example k3x9q2. Fixed. |
| Provider | The agent the account runs, for example Claude Code. Fixed once created. |
| Authentication | How the account signs in: Subscription (OAuth) or API key. Fixed once created. |
| Quota | How much of a subscription's allowance is used, over 5 hours and over a week. |
| Sign-in | A subscription's login on one node. Each node needs its own. |
| Auto-assign | Whether the account runs tasks that allow any provider, or only tasks that pick its provider. |
| Max runners | The most runners the account may run at once. Blank means the fleet limit. |
Subscription or API key
An account authenticates in one of two ways, and the choice shapes everything else about it:
- Subscription (OAuth) — a person signs in to an AI subscription on a node. The account reports its plan's quota. The sign-in belongs to that node and doesn't move to another: a second node needs its own sign-in. A subscription marked Shared keeps its sign-in on the shared volume instead, so any node allowed to use shared accounts can run it.
- API key — a key Jaah stores and never shows again. No sign-in, no node and no quota: it runs on any node and is billed per token by the AI provider.
The form offers only the providers and authentication your organization may use. An existing account whose provider or authentication is no longer allowed stays listed but runs no tasks.
How a run picks an account
You don't pick a model account for a task. Each time a task starts a run, Jaah picks one of the accounts your organization has that is enabled, has room, and fits the task:
- A task whose Provider is Any can run on any account with Auto-assign on.
- A task that names a provider runs only on that provider's accounts. An account with Auto-assign off, shown with the explicit only chip, runs only such tasks.
- A subscription runs only on a node where it has a working sign-in. An API-key account runs anywhere.
- Max runners caps how many runs share one account at once.
- A subscription whose quota is used up, or nearly so, is skipped until its quota resets. So is a disabled account, and one whose provider or authentication your organization no longer allows.
If an account runs out or its sign-in is refused during a run, the run fails and uses one attempt; the task is queued again, and its next run picks from the accounts that still qualify. See How tasks work.
Health and lifecycle
The round mark before each account says how it is doing: ● available, ▲ quota nearly used up, ✕ failing, ⊘ disabled. A quota cell shows — before the first reading and n/a for an API key. Each subscription quota resets on its own clock, shown by ↻.
An account's life runs like this:
- Added, with an API key or a first sign-in on a node. It is enabled at once; a subscription's sign-in ends with Account added and enabled.
- Running tasks, its quota rising and resetting.
- Signed in again when a subscription's sign-in expires or is refused, with the row menu's Re-login or a node row's Login. An API key is replaced from Edit instead.
- Disabled to stop runs using it for a while, and Enabled again later. Nothing is lost.
- Removed: Delete record for an API-key account or one never signed in, Deprovision for a subscription no node holds. Removal can't be undone.
Who can do what
You see the accounts you hold a role on, through your organization or the account's Access tab. Adding and signing in an account needs permission to add accounts; without it, Add account doesn't appear. Edit, Disable, Enable, Delete record and Deprovision need the Org Owner or Org Admin role. An account's Owner is Organization or Personal. See How team and access work.
Model accounts, credentials and billing
A model account reaches the AI model itself. A credential reaches the services a task's work touches, such as Jira, Slack or GitHub. The cost of your own model accounts is billed by the AI provider, not by Jaah; work on the Jaah AI account is paid from your Jaah AI balance instead. See How plans and billing work.
Related
- How nodes work — the machines runners, and their sign-ins, live on.
- How credentials work — connections to other services, which are not model accounts.
- How tasks work — the runs a model account powers.
- Model accounts — every column, chip and setting on the screen.