# Backends

A backend is an address and a model. ThinkThen speaks one wire shape, System One, and any server that speaks it can answer.

## The built-in backends

Name one with `--backend NAME` or `THINKTHEN_BACKEND`. Each brings its own address, key variable and model.

| Name | Address | Key variable | Default model |
| --- | --- | --- | --- |
| [`liquid`](/install/backends/liquid/) | `https://api.liquid.ai/decisions/v1` | `LIQUIDAI_API_KEY`, then `LIQUID_API_KEY` | `d1:free` |
| [`ollama`](/install/backends/ollama/) | `http://localhost:11434/v1` | `OLLAMA_API_KEY` | `nimble` |
| [`typesafe`](/install/backends/typesafe/) | `https://api.typesafe.ai/v1` | `TYPESAFE_API_KEY` | `jev-1.13.0` |
| [OpenAI Decisions API](/install/backends/openai/) | Announced, not released |  |  |

This table gives the last `thinkthen check` of each built-in backend.

| Backend | Date | Model | Lines found |
| --- | --- | --- | --- |
| [`liquid`](/install/backends/liquid/) | 2026-09-30 | `d1:free` | [0 critical, 0 warning](https://github.com/botassembly/thinkthen/blob/main/sdlc/issues/closed/2026-09-29-systemone-adapter-sends-null-criteria-liquid-d1-refuses.md) |
| [`ollama`](/install/backends/ollama/) | 2026-09-30 | `nimble` | 0 critical, 3 warning |
| [`ollama`](/install/backends/ollama/) | 2026-09-30 | `tev1` | 0 critical, 3 warning |
| [`typesafe`](/install/backends/typesafe/) | 2026-09-26 | `jev-1.13.0` | [0 critical, 0 warning](https://github.com/botassembly/thinkthen/blob/main/sdlc/records/0160-build-the-answer-contract-holds.md) |

Any other server goes in through [its address or the configuration file](/install/backends/system-one/). [Awesome ThinkThen](https://github.com/botassembly/awesome-thinkthen) lists more models and servers that pass the check.

## With no backend named

A command that names no backend and no address sends every question to `https://api.typesafe.ai/v1` with `jev-1.13.0`. It reads the key from `THINKTHEN_API_KEY`. The [TypeSafe Jev page](/install/backends/typesafe/) covers that backend.

*The plan names the address, the model, and the variable a key would come from. It holds no key.*

```
question="Does the customer ask for a refund?"

printf '%s\n' "I want to send this back." |
thinkthen decide "$question" --plan |
head -1 |
jq .
```

*Output*

```
{
  "url": "https://api.typesafe.ai/v1/systemone",
  "model": "jev-1.13.0",
  "key_env": "THINKTHEN_API_KEY",
  "request": {
    "state": "Each question quotes the text it asks about.",
    "model": "jev-1.13.0",
    "questions": {
      "q1": {
        "type": "noul",
        "instructions": "The text is \"I want to send this back.\\n\". Does the customer ask for a refund?"
      }
    }
  }
}
```

*exit 0*

`--plan` sends nothing and needs no key. The plan holds the evidence, so treat it with the same care as the request.

## The key

A named backend reads only its own key variables, and the first one that is not blank wins. With no backend named, the key comes from `THINKTHEN_API_KEY`. The command takes no flag and no file for a key. A key that is unset or blank exits 4 at any address but the three local hosts named below. The message names the variable and never a value.

The key goes only to the address you named. It never shows in a plan, a result, a saved answer, a log line, or an error. An address that holds the key is refused before anything is sent.

A plain `http://` address may reach only `localhost`, `127.0.0.1` or `[::1]`. Any other `http://` host is a usage error, because the key would cross the network in clear text. At those three hosts a request goes out with no key when the key variable is unset, whichever backend is named. Under `http://` the tool ignores every proxy variable.

An address with a user name, a query, or a fragment is a usage error. The plan prints the address, and a saved answer keeps it.

## Where your text goes

Each backend's own terms govern what it keeps. The default address sends your question and evidence to TypeSafe. Its [customer agreement](https://typesafe.ai/legal/mca), [data processing addendum](https://typesafe.ai/legal/data-processing), and [privacy policy](https://typesafe.ai/legal/privacy-policy) describe data handling. The privacy policy, checked 2026-09-28, gives no fixed retention period for API input. Check the terms that govern your account before you send sensitive text. The answer cache has its own [storage setting](/install/settings/#answer-cache).

[Configuration](/install/configuration/) · [Every setting and its default](/install/settings/) · [Test it before you trust it](/trust/)

On GitHub: [github.com/botassembly/thinkthen](https://github.com/botassembly/thinkthen)
