In this deep-dive we run through the LLM configuration in depth, including the useful `OAI_CONFIG_LIST` file.

# LLM Configuration

In AG2, agents use LLMs as key components to understand and react. To configure an agent's access to LLMs, you can specify an `llm_config` argument in its constructor. For example, the following snippet shows a configuration that uses `gpt-4.1`:

```
import os
from autogen import LLMConfig

llm_config = LLMConfig(config_list=[{"api_type": "openai", "model": "gpt-5", "api_key": os.environ["OPENAI_API_KEY"]}])
```

Warning

It is important to never commit secrets into your code, therefore we read the OpenAI API key from an environment variable.

This `llm_config` can then be passed to an agent's constructor to enable it to use the LLM.

```
import autogen

assistant = autogen.AssistantAgent(name="assistant", llm_config=llm_config)
```

## Introduction to `config_list`

Different tasks may require different models, and the `config_list` allows specifying the different endpoints and configurations that are to be used. It is a list of dictionaries, each of which contains the following keys depending on the kind of endpoint being used:

- `api_type` (str, required): The model provider
- `model` (str, required): The identifier of the model to be used, such as 'gpt-5', 'gpt-5-nano'.
- `api_key` (str, optional): The API key required for authenticating requests to the model's API endpoint.
- `base_url` (str, optional): The base URL of the API endpoint. This is the root address where API calls are directed.
- `tags` (List[str], optional): Tags which can be used for filtering.

Example:

```
[
    {
      "api_type": "openai",
      "model": "gpt-5",
      "api_key": os.environ['OPENAI_API_KEY']
    }
]
```

### `OAI_CONFIG_LIST` pattern

A common, useful pattern used is to define this `config_list` via JSON (specified as a file or an environment variable set to a JSON-formatted string) and then use the `from_json` method to load it:

```
llm_config = autogen.LLMConfig.from_json(
    env="OAI_CONFIG_LIST",  # Or path="path/to/config.json"
)

# Then, create the assistant agent with the config
assistant = autogen.AssistantAgent(name="assistant", llm_config=llm_config)
```

### Why is it a list?

Being a list allows you to define multiple models that can be used by the agent. This is useful for a few reasons:

- If one model times out or fails, the agent can try another model.
- Having a single global list of models and filtering it based on certain keys (e.g. name, tag) in order to pass select models into a certain agent (e.g. use cheaper GPT 4o-mini for agents solving easier tasks)

### How does an agent decide which model to pick out of the list?

An agent uses the very first model available in the "config_list" and makes LLM calls against this model. If the model fails (e.g. API throttling) the agent will retry the request against the 2nd model and so on until prompt completion is received (or throws an error if none of the models successfully completes the request).

### Config list filtering

As described above, the list can be filtered based on certain criteria. This is defined as a dictionary of key to filter on and values to filter by. For example, if you want to select a config with specific model(s), you can pass either a single string or a list of strings:

```
# Single model (string)
filter_dict = {"model": "gpt-5-nano"}

# Multiple models (list)
filter_dict = {"model": ["gpt-5-nano", "gpt-4.1"]}
```

#### Tags

Model names can differ between OpenAI and Azure OpenAI, so tags offer an easy way to smooth over this inconsistency. Tags are a list of strings in the `config_list`.

### Adding http client in llm_config for proxy

In AG2, a deepcopy is used on llm_config to ensure that the llm_config passed by user is not modified internally.

```
#!pip install httpx
import httpx

from autogen import LLMConfig

class MyHttpClient(httpx.Client):
    def __deepcopy__(self, memo):
        return self

llm_config = LLMConfig(
    config_list=[
        {
            "api_type": "openai",
            "model": "my-gpt-5-deployment",
            "api_key": "",
        }
    ],
    http_client=MyHttpClient(proxy="http://localhost:8030")
)
```

### Using Azure Active Directory (AAD) Authentication

Azure Active Directory (AAD) provides secure access to resources and applications. Follow the steps below to configure AAD authentication for AG2.

#### Step 1: Register an Application in AAD

1. Navigate to the Azure portal.
2. Go to `Azure Active Directory` > `App registrations`.
3. Click on `New registration`.
4. Enter a name for your application.
5. Set the `Redirect URI` (optional).
6. Click `Register`.

#### Step 2: Configure API Permissions

1. After registration, go to `API permissions`.
2. Click `Add a permission`.
3. Select `Microsoft Graph` and then `Delegated permissions`.
4. Add the necessary permissions (e.g., `User.Read`).

#### Step 3: Obtain Client ID and Tenant ID

1. Go to `Overview` of your registered application.
2. Note down the `Application (client) ID` and `Directory (tenant) ID`.

#### Step 4: Configure Your Application

Use the obtained `Client ID` and `Tenant ID` in your application configuration. Here’s an example of how to do this in your configuration file:

```
aad_config = {
    "client_id": "YOUR_CLIENT_ID",
    "tenant_id": "YOUR_TENANT_ID",
    "authority": "https://login.microsoftonline.com/YOUR_TENANT_ID",
    "scope": ["https://graph.microsoft.com/.default"],
}
```

#### Step 5: Authenticate and Acquire Tokens

Use the following code to authenticate and acquire tokens:

```
from msal import ConfidentialClientApplication

app = ConfidentialClientApplication(
    client_id=aad_config["client_id"],
    client_credential="YOUR_CLIENT_SECRET",
    authority=aad_config["authority"]
)

result = app.acquire_token_for_client(scopes=aad_config["scope"])

if "access_token" in result:
    print("Token acquired")
else:
    print("Error acquiring token:", result.get("error"))
```

#### Step 6: Configure Azure OpenAI with AAD Auth in AG2

To use AAD authentication with Azure OpenAI in AG2, configure the `llm_config` with the necessary parameters.
Here is an example configuration:

```
from autogen import LLMConfig

llm_config = LLMConfig(config_list=[
    {
        "model": "gpt-4",
        "base_url": "YOUR_BASE_URL",
        "api_type": "azure",
        "api_version": "2025-01-01",
        "max_tokens": 1000,
        "azure_ad_token_provider": "DEFAULT"
    }
])
```

### Example of Initializing an Assistant Agent with AAD Auth

```
import autogen

# Initialize the assistant agent with the AAD authenticated config
assistant = autogen.AssistantAgent(name="assistant", llm_config=llm_config)
```

### Troubleshooting

If you encounter issues, check the following:
- Ensure your `Client ID` and `Tenant ID` are correct.
- Verify the permissions granted to your application.
- Check network connectivity and Azure service status.

This documentation provides a complete guide to configure and use AAD authentication with Azure OpenAI in AG2.

## Other configuration parameters

Besides the `config_list`, there are other parameters that can be used to configure the LLM. These are split between parameters specifically used by Autogen and those passed into the model client.
