Soba Docs

Operating

Provider terms

Read this before deploying. The defensible shape is narrow, and the code enforces it rather than merely documenting it.

Read this before deploying

A run executes on the end user's own machine, under their own login, for their own account.

That is materially different from an operator pooling subscriptions to serve strangers, and that difference is what the whole design is arranged around. It is not a matter of intent; it is a property the system has to keep true, which is why the mechanisms below enforce it rather than describe it.

None of that is legal advice, and Soba cannot give you a compliance guarantee. The providers' terms are theirs to interpret and change, so read them, and if the exposure matters to you, take your own advice and consider asking the provider directly.

The invariant#

A run must never be routed to a machine owned by someone other than the user the run is attributed to.

A machine's pairing token is bound, at the moment it is approved, to the one person who approved it, never to anything the machine claimed about itself. So the machine that answers a run and the user the run is billed and attributed to are the same person by construction, not by convention.

What this rules out#

One operator's Claude Max account serving many users' runs No. That is pooling
A shared pool of pre-paired machines runs are handed out from No. The machine is not the user's
A user's own laptop serving their own runs Yes
A user's own VPS or container serving their own runs Yes
A user's own API key, spent on their own runs Yes
Your own provider keys, serving your own users' runs in your app (app) Yes. That is an ordinary API customer using its own account

Why the code enforces it rather than documenting it#

Because a documented boundary is one a future feature crosses without anybody noticing. Three mechanisms hold it:

  • Attribution. A pairing token acts as exactly one account, and a run may only reach a machine owned by the user it is attributed to.
  • Honest classing. A metered provider key in the machine's environment changes what the machine advertises, never what the CLI may read. With the owner's opt-in the runtime is offered as frontier; without it the runtime is withheld entirely. Either way a run cannot quietly spend an account the cost class says is not being spent. See Who pays.
  • Settings isolation. A run arriving over the network does not inherit the machine owner's CLAUDE.md, hooks, skills or plugins. See Security model.

The ChatGPT plan channel is the exception to watch#

Moving the credential instead of the compute runs the loop server-side rather than on the user's machine. It is still the user's own plan and their own account, but the machine is no longer theirs. That is why the channel ships no default OAuth client id: an operator supplies one they are entitled to use, and owns that decision.

See The ChatGPT plan channel.

Trademarks#

Claude Code, Codex, Gemini CLI and Ollama are the products of their respective owners. Soba is an independent tool, not affiliated with or endorsed by any of them, and it makes no claim on their behalf. What Soba does is keep each run on a machine dedicated to one user, signed in with that user's own account; whether that use is permitted is governed by the agreement between that user and their provider.

© 2026 Soba resolved = machine grant ∩ broker request