NeMo Guardrailsnemoguardrails 0.24.1 · Python 3.10+
Dashboard
0%
1
Curious builder0 XP earned · 300 to level 2
0 daysFinish a lesson to begin
Badge collection0 of 6 unlocked
37 small wins to finish your pathNext lesson →

Main model and API key

The main model is the entry under models in config.yml with type: main: the LLM that NeMo calls to answer, and to judge messages, unless a rail names another.

Last updated: 30 Sep, 2026 · NeMo Guardrails 0.24.1

The Config folder lesson loaded a model entry without explaining it. This lesson reads it line by line and shows what happens without the key.

Syntax:

yaml
models:
  - type: main                      # the model NeMo uses by default
    engine: openai                  # the client: any OpenAI-compatible API
    model: openai/gpt-oss-120b      # the model name the provider expects
    api_key_env_var: GROQ_API_KEY   # which environment variable holds the key
    parameters:
      base_url: https://api.groq.com/openai/v1   # where the API lives
      temperature: 0

engine and base_url

Groq's API speaks the OpenAI format, so the openai engine can call it; base_url points that client at Groq instead of OpenAI. NeMo's documentation gives this route for any OpenAI-compatible provider.

api_key_env_var

Names the variable that holds the key. Without it, the openai engine looks for OPENAI_API_KEY.

Project files used on this pageThis lesson builds on a project from earlier lessons. The code below imports this file. Click a file to see its code, or follow the link to the lesson that wrote it. To run the code yourself, keep it in the same folder.
View the code here
config.yml
models:
  - type: main
    engine: openai
    model: openai/gpt-oss-120b
    api_key_env_var: GROQ_API_KEY
    parameters:
      base_url: https://api.groq.com/openai/v1
      temperature: 0

instructions:
  - type: general
    content: |
      You are an Enterprise IT Assistant specialising in Kubernetes,
      Intel hardware, and enterprise networking.
      Only answer questions about these topics.
      Answer in one or two short sentences.

Calling the model through NeMo

ExampleAPI key
from nemoguardrails import LLMRails, RailsConfig

rails = LLMRails(RailsConfig.from_path("."))


def chat(message):
    reply = rails.generate(messages=[{"role": "user", "content": message}])
    print("User:", message)
    print("Bot :", reply["content"])

chat("What is a Kubernetes ConfigMap?")

One question, one answer from Groq. With no rails in the config, NeMo passes the message to the model and hands back its reply.

Starting without the key

The same folder, run where GROQ_API_KEY is not set:

Example
from nemoguardrails import RailsConfig

try:
    RailsConfig.from_path(".")
except ValueError as error:
    print(error.errors()[0]["msg"])

NeMo checks the variable when it loads the config, before any call, and names the variable it looked for. Export the key as in Installation and setup and the load succeeds.

The video's model setup vs this course's

The video's notebook and app create a LangChain ChatGroq and pass it as LLMRails(config, llm=guard_llm), with engine: openai and model: gpt-3.5-turbo left in the YAML as a placeholder. NeMo prints Both an LLM was provided via constructor and a main LLM is specified in the config and uses the constructor's model. This course names the real model in config.yml instead, the route NeMo's model documentation gives for OpenAI-compatible providers since release 0.22, so no LangChain package is needed and the file says which model runs.

python
# The video's way, shown as it ran there (needs langchain-groq; its llama models are retired)
from langchain_groq import ChatGroq

guard_llm = ChatGroq(api_key=GROQ_API_KEY, model="llama-3.3-70b-versatile", temperature=0)
rails_exp2 = LLMRails(config_exp2, llm=guard_llm)
llm= in the constructormodels: in config.yml
Packagelangchain-groqNone beyond nemoguardrails
The YAML's modelA placeholder, ignored with a warningThe model that runs
Where the model is namedPython codeThe config folder

Where you change this entry

  • Moving to another provider: Gemini or OpenRouter, in Groq or Gemini.
  • Giving a rail its own smaller model, with another entry of a different type.
Watch out. model is the provider's own name. On Groq it is openai/gpt-oss-120b, with the openai/ prefix; drop the prefix and Groq answers with a model-not-found error.
Try it yourself
  • Change api_key_env_var to MY_KEY and read which variable the error names.
  • Change the model to openai/gpt-oss-20b and ask the same question.
PreviousConfig folder

Every expert started right here.