Skip to main content

Lock your app's model routing

Every Digitorn app reaches its AI model one of two ways:

  • Through the Digitorn gateway - the shared routing Digitorn provides. This is the default for a brand-new install.
  • Directly (Local / BYOK) - "bring your own key": either a model running on the installer's own machine (Ollama, LM Studio, vLLM...), or a provider key the installer supplies themselves.

Normally that's a per-installer choice, and each person can flip it for their own copy of the app. But if you're the one building the app, sometimes only one of the two actually makes sense - and you don't want every single installer to have to discover and flip the right switch by hand before your app works.

Why you'd want to fix it​

The clearest case: your app is wired to a model that only exists on the installer's own machine. The Digitorn gateway has no way to reach into someone else's computer, so on a brand-new install - which defaults to gateway routing - every message fails until that person manually switches their copy to Local/BYOK. Nothing about the failure tells them what to do; they just see broken replies.

Locking the routing removes that step entirely. You decide, once, how your app is meant to run, and it's correct from the very first message, for everyone who ever installs it - not just the people who happen to figure out the toggle themselves.

The same lock also works the other way: if you'd rather your app always go through the Digitorn gateway - even for an installer who has their own key set up - you can fix it to gateway routing instead, and it'll ignore a local switch attempt.

Setting it from Studio​

Open your app in Studio and select the entry agent's Brain node - the one that decides how the app actually talks to a model. Its mode switch offers three choices: Gateway, Local, and BYOK.

  • Picking Local or BYOK locks the app to direct routing.
  • Picking Gateway locks it to gateway routing.

That's it - there's no separate step, no file to edit. Switching the mode is what sets (or clears) the lock, and it takes effect the next time you publish or redeploy.

Only the entry agent's own Brain node controls this. A fallback brain, or a secondary agent's brain elsewhere in the app, never changes it - which model routing to use is a decision for the whole app, not something that varies agent by agent.

What an installer sees once it's locked​

By default, locking the routing takes the choice out of the installer's hands for good. Their app settings no longer let them flip it - the switch is disabled, with a short note that routing is fixed by the publisher - and their chat model picker greys out whichever option your lock rules out (gateway models, if you locked to Local/BYOK; or the Local/BYOK option, if you locked to gateway), instead of the usual prompt inviting them to switch.

They can still use every model your lock does allow - the lock only takes the wrong option off the table, not the whole picker.

Letting installers override your default​

Sometimes you just want to pick a sensible default, not remove the choice entirely. When your entry agent's Brain node is set to Local or BYOK, its panel shows a second checkbox right below the mode switch: "Let installers change this for their own install".

Leave it unchecked (the default) for the strict behavior described above. Check it, and your lock only decides what a fresh install starts with - the installer's own app settings toggle stays usable, and once they change it for their own copy, that choice sticks: a later redeploy of the same app won't quietly flip it back. If you ever uncheck it again and redeploy, the strict lock reasserts itself and overrides whatever installers had chosen.

Redeploying keeps it in force​

A lock isn't a one-time nudge - it's a standing decision, at least until you say otherwise. Every time you redeploy or republish the app (to yourself, to the Hub, anywhere), Digitorn re-applies whatever the lock currently says, on that install - unless you checked "let installers change this", in which case an installer's own choice takes over from their first change onward, and stops being reasserted.

An app that's never had its lock touched behaves like before this feature existed on a desktop install: routing stays a free, per-installer choice, and redeploys leave it alone. See the next section for the one case where that's not quite true.

An untouched app isn't always free to toggle​

On a desktop / self-hosted install, an app with no lock at all behaves exactly as described above - fully free, nothing to configure. On the hosted Digitorn platform, it's the other way around by default: unless you've set a lock (even just the checkbox above with no mode pinned), installers of your published app can't switch their own routing at all. This only matters if you publish through the Hub for other people to install - your own desktop copies of your own apps are unaffected.

If you want your Hub-published app's installers to be able to toggle routing themselves, check "Let installers change this for their own install" - that alone is enough, even if you leave the mode switch on Gateway.

Editing the YAML directly​

If you write app configuration by hand instead of using Studio's canvas, the lock lives under the app's runtime block and is covered in full, with every field and edge case, in the Locked settings reference.

Going further​