GigaChat API Integration: OAuth, GigaChain, Production

We design and deploy artificial intelligence systems: from prototype to production-ready solutions. Our team combines expertise in machine learning, data engineering and MLOps to make AI work not in the lab, but in real business.
Showing 1 of 1All 1564 services
GigaChat API Integration: OAuth, GigaChain, Production
Simple
~1 day
Frequently Asked Questions

AI Development Areas

AI Solution Development Stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1358
  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1251
  • image_websites_belfingroup_462_0.webp
    Website development for BELFINGROUP
    957
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1188
  • image_logo-advance_0.webp
    B2B Advance company logo design
    646
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    929

Note: when your RAG pipeline requires a local LLM and data absolutely cannot leave Russia, GigaChat from Sber becomes the only choice. Integrating GigaChat API via OAuth 2.0 and GigaChain is the standard path for production in government and finance. We have faced this in projects for contact centers, CRM, and chatbots. This article covers how to connect GigaChat correctly, without 'surprises' with tokens and certificates. GigaChat API integration includes setting up OAuth 2.0, selecting the right model, and ensuring stable production operation. Based on our experience, implementing GigaChat reduces operational costs for client support by 30–50% by automating typical requests.

Why GigaChat for Russian B2B?

GigaChat is the only major LLM physically located in Russia and compliant with 152-FZ on personal data. For banks, insurance, and government sectors, this is critical. Additionally, GigaChat supports multimodal requests (text + images) and integrates easily with LangChain via GigaChain, accelerating AI assistant development. As stated in Sber documentation, OAuth 2.0 requires a unique RqUID for each request.

Problems We Solve

OAuth 2.0 and Token Management. Sber uses a custom OAuth implementation: access_token lives for 30 minutes, requires a unique RqUID and Basic authorization. Without automatic refresh in production, the client gets a 401 error every half hour. We solve this with a caching client that refreshes with a 5-minute buffer.

Model Selection. The base GigaChat (8k context) works for tests, but real tasks need GigaChat-Plus (12k) or Pro (16k). On financial queries, GigaChat-Pro is 30% more accurate than base. For long dialogues and RAG, GigaChat-Max with a 32k token window—4x larger than base—handles complex contexts.

Latency and Reliability. In production, p99 latency (target < 2 sec) and network error handling matter. We implement retry logic with exponential backoff and monitor CPU/GPU utilization.

How We Integrate GigaChat API End-to-End

Let's walk through a typical project: a bank chatbot answering client questions.

Getting Access

# 1. Register at developers.sber.ru
# 2. Create a project and get client_id / client_secret
# 3. OAuth 2.0 authorization to get access_token

import requests
import base64
import uuid

CLIENT_ID = "your-client-id"
CLIENT_SECRET = "your-client-secret"
SCOPE = "GIGACHAT_API_PERS"  # For individuals
# GIGACHAT_API_B2B for business
# GIGACHAT_API_CORP for corporate

def get_access_token() -> str:
    credentials = base64.b64encode(f"{CLIENT_ID}:{CLIENT_SECRET}".encode()).decode()
    response = requests.post(
        "https://ngw.devices.sberbank.ru:9443/api/v2/oauth",
        headers={
            "Authorization": f"Basic {credentials}",
            "RqUID": str(uuid.uuid4()),
            "Content-Type": "application/x-www-form-urlencoded",
        },
        data={"scope": SCOPE},
        verify=False,  # Sber's self-signed certificate
    )
    return response.json()["access_token"]

Making a Basic Request

After getting the token, send a request to chat/completions. The token only lives 30 minutes, so automatic refresh is mandatory. Below is a client with token caching.

def gigachat_chat(prompt: str, access_token: str) -> str:
    response = requests.post(
        "https://gigachat.devices.sberbank.ru/api/v1/chat/completions",
        headers={"Authorization": f"Bearer {access_token}"},
        json={
            "model": "GigaChat",
            "messages": [{"role": "user", "content": prompt}],
            "temperature": 0.1,
            "max_tokens": 1024,
        },
        verify=False,
    )
    return response.json()["choices"][0]["message"]["content"]

# With token caching
from datetime import datetime, timedelta

class GigaChatClient:
    def __init__(self, client_id: str, client_secret: str):
        self.client_id = client_id
        self.client_secret = client_secret
        self._token = None
        self._token_expires = None

    def _ensure_token(self):
        if not self._token or datetime.now() >= self._token_expires:
            self._token = get_access_token()
            self._token_expires = datetime.now() + timedelta(minutes=25)  # 5-minute buffer

    def chat(self, messages: list[dict], model: str = "GigaChat") -> str:
        self._ensure_token()
        response = requests.post(
            "https://gigachat.devices.sberbank.ru/api/v1/chat/completions",
            headers={"Authorization": f"Bearer {self._token}"},
            json={"model": model, "messages": messages, "temperature": 0.1},
            verify=False,
        )
        return response.json()["choices"][0]["message"]["content"]

GigaChain — LangChain for GigaChat

from langchain_community.chat_models import GigaChat
from langchain_core.messages import HumanMessage, SystemMessage

chat = GigaChat(
    credentials="Base64(client_id:client_secret)",
    scope="GIGACHAT_API_PERS",
    model="GigaChat",
    verify_ssl_certs=False,
    streaming=False,
)

response = chat.invoke([
    SystemMessage(content="You are a financial consultant"),
    HumanMessage(content="Explain the key rate of the Central Bank of Russia"),
])
print(response.content)

GigaChat Models: Which to Choose for the Task

Model Description When to Choose
GigaChat Base, context window 8k tokens Simple chatbots, testing
GigaChat-Plus Improved accuracy and speed, 12k tokens CRM, contact centers
GigaChat-Pro Maximum quality, 16k tokens Analytics, report generation
GigaChat-Max Flagship, context window 32k tokens Full AI assistants, RAG

In our A/B tests on financial tasks, GigaChat-Pro shows 30% higher accuracy than the base model. For most production scenarios, GigaChat-Plus suffices. For long dialogues or document processing, use GigaChat-Max.

Case Study: Bank Contact Center

A bank contact center used GigaChat for automated answers to client questions about products. The main requirement was data localization per 152-FZ. We integrated GigaChat with the internal CRM via REST API, set up token caching and retry logic. Result: response time dropped by 40%, operator load by 60%. Average cost per inquiry fell from 200 to 100 rubles. The investment paid back in 6 months. The system processed about 5000 requests daily with 92% answer accuracy.

Project Work Process

Stage Duration What We Do
Analysis 1-2 days Identify use cases, load (RPS, tokens per minute)
Design 1-2 days Select model, set up OAuth, design flow (with or without RAG)
Implementation 3-5 days Write integration code, wrappers, tests (unit + integration)
Testing 1-2 days Check p99 latency (target < 2 sec), response correctness, edge cases
Deployment 1 day Set up CI/CD, monitoring, alerting on auth errors

Step-by-Step Integration Plan

  1. Register application on developers.sber.ru — get credentials.
  2. Set up OAuth with automatic token refresh (as in example above).
  3. Choose model — test GigaChat-Plus, Pro, or Max on your data.
  4. Develop a Python wrapper or use GigaChain.
  5. Integrate with business logic (CRM, chatbot, RAG).
  6. Load test — verify p99 latency and fault tolerance.
  7. Deploy and monitor — configure alerts on auth errors and response time exceedances.
Deployment with Docker

For fast deployment, containerize. Example Dockerfile:

FROM python:3.11-slim
WORKDIR /app
COPY requirements.txt .
RUN pip install -r requirements.txt
COPY . .
CMD ["python", "app.py"]

Run: docker build -t gigachat-client . && docker run -d -p 8000:8000 gigachat-client

Estimated Timelines

  • Access + basic integration: 2–3 days.
  • GigaChain/LangChain integration: 1 week.
  • Production with token refresh and retries: +2–3 days.

What Our Work Includes

Fixed scope: API documentation, OAuth with automatic refresh, Python wrappers (including GigaChain), test scenarios, deployment instructions, and one month of support. Training for your developers available on request.

Quality Guarantee

Our experience: over 10 projects with GigaChat and 5 years on the AI integration market. We use production-proven approaches: CPU/GPU monitoring, automatic token refresh, network error and certificate handling. Reference: OAuth 2.0 and LangChain.

If you have custom requirements, contact us for a free project assessment. Get a consultation — we'll help choose the optimal integration model for your business. Order an audit of your current solution — we'll propose a modernization plan within 2 days.

LLM Development: Fine-Tuning, RAG, Agents, and Production Deployment

Using GPT‑4 or Claude 3.5 Sonnet through a public API is not a solution — it's just a tool. When the requirement is to "make it like ChatGPT, but on our data," there is a real engineering challenge behind it: from prompt engineering to training a 70B model on your own infrastructure. End-to-end LLM solution development is a complex stack, and we have been doing it for over 5 years. During this time, we have completed over 20 projects in generative AI: from RAG systems for legal departments to custom support agents. Where exactly your task falls depends on data, latency requirements, budget, and how critical confidentiality is.

A typical situation: the client has already tried ChatGPT, but results are unstable — sometimes accurate, sometimes hallucinating. Or they need integration into a corporate portal while complying with security policies. Let's break down each layer of the stack in detail — from RAG to production deployment.

Why Do RAG Systems Break and How to Fix It?

RAG (Retrieval-Augmented Generation) looks simple: find relevant documents, put them in context, get an answer. In practice, it fails in several places.

Chunking without overlap. Classic mistake: chunk_size=512, overlap=0. If the answer lies across two chunks, retrieval won't find either with sufficient confidence. Solution: overlap 15–25% of chunk_size, or better yet, sentence-aware splitting with spaCy or NLTK instead of naive character splitting.

Poor embedder. text-embedding-ada-002 is good for general use, but on legal or medical texts, specialized models like E5-large-v2, BGE-M3, or fine-tuned sentence-transformers on domain data outperform it. Recall@5 differences can be 15–25%.

No re-ranking. Vector search optimizes for speed, not relevance. A cross-encoder re-ranker (ms-marco-MiniLM-L-6-v2, bge-reranker-large) after initial retrieval improves top-3 accuracy with acceptable latency (+50–150ms). This is often more impactful than improving the embedding model.

Hybrid search. Dense vectors alone work poorly on exact queries: names, SKUs, codes. BM25 (sparse) finds exact matches but misses semantics. Hybrid via RRF (Reciprocal Rank Fusion) is the optimal compromise. Qdrant, Weaviate, and pgvector 0.7+ support hybrid search natively.

Typical production architecture for a corporate knowledge base
  1. Documents → preprocessing (PyMuPDF, Unstructured)
  2. Chunking → embedding (BGE-M3)
  3. Qdrant (hybrid dense+sparse)
  4. Cross-encoder re-ranking
  5. Context → LLM (vLLM or OpenAI API)
  6. Answer with sources (RAGAS for quality evaluation)

When to Fine-Tune Instead of Prompt Engineering?

Prompt engineering solves ~70% of LLM adaptation tasks for a domain. The remaining 30% require fine-tuning. Three indicators: the model ignores a specific output format even with detailed prompting; the task requires deep knowledge of specialized vocabulary (medicine, law); you need to significantly reduce token costs by replacing a large model with a smaller specialized one.

LoRA and QLoRA are the standard for SFT. LoRA adds trainable low-rank matrices to attention layers. A typical configuration for Llama-3 8B: r=64, lora_alpha=128, target_modules=["q_proj","v_proj","k_proj","o_proj"] yields ~0.8% trainable parameters, training on one A100 40GB. QLoRA adds 4-bit quantization (NF4) and allows fine-tuning 70B models on two A100 40GB, though speed drops by half compared to bf16.

DPO instead of RLHF. Direct Preference Optimization requires only (chosen, rejected) pairs, not scalar reward signals. DPOTrainer from the trl library (Hugging Face) implements it in a few dozen lines.

Common mistake. A dataset of 500 examples, 5 epochs, validation loss 0.8 — seems fine. But on test, the model degrades on general instructions. Cause: catastrophic forgetting. Solution: add 10–20% general instruction-following examples (Alpaca, FLAN) to the training set to preserve original capabilities.

How to Choose a Base Model: 8B or 70B?

Model Parameters Strengths Context
Llama-3.1 8B 8B Quality/speed balance 128k
Llama-3.1 70B 70B Complex reasoning 128k
Mistral 7B / Mixtral 8x7B 7B / 47B Efficiency for size 32k
Qwen2.5 72B 72B Code, multilingual 128k
Gemma 2 27B 27B Open license 8k

For most tasks, fine-tuning an 8B model is sufficient. 70B is needed when deep reasoning is required or the 8B baseline does not reach the required quality even after fine-tuning. Inference cost for Llama-3 8B via vLLM on A100 is efficient; the exact cost depends on volume.

What Does PagedAttention Bring to Production?

vLLM is the first choice for serving open-source models. PagedAttention is the key technical innovation: KV-cache is managed like virtual memory in an OS, without fragmentation. This yields 2–4x higher throughput compared to naive HuggingFace Transformers inference. The vLLM documentation confirms that continuous batching and PagedAttention are the standard for high-load LLM services.

Typical numbers on A100 80GB for Llama-3 8B (bf16): 400–600 req/s, P50 latency 200–400ms, P99 latency 600–900ms at concurrency 64. For 70B on two A100 with tensor parallelism: 80–120 req/s, P99 latency 1.5–2.5s. AWQ or GPTQ quantization reduces memory consumption by 2x with quality loss within 1–3%.

Multi-Agent Systems

Agents are LLMs with access to tools: search, code execution, API calls, database interaction. Common patterns:

  • ReAct (Reason + Act): the model reasons → chooses a tool → observes the result → reasons again. LangChain and LlamaIndex implement it out of the box.
  • Multi-agent orchestration: multiple specialized agents with a coordinator on top. Example: coordinator → researcher (search + summarization) → coder (code generation and execution) → critic (verification). Tools: AutoGen (Microsoft), CrewAI, custom implementation on LangGraph.

In production, agent systems are non-deterministic. Essential: guardrails, step limits, logging of each step, human-in-the-loop for critical actions.

How We Work: Stages, Timeline, Deliverables

Stage Duration What You Get
Audit and data collection 1–2 weeks Eval dataset of 100+ examples, task formalization
Baseline (prompt + RAG) 1–2 weeks Working prototype, quality metrics
Fine-tuning (if needed) 2–4 weeks Trained model, LoRA weights, model card
Deployment and monitoring 1–2 weeks vLLM server, Grafana + Prometheus
Documentation and training 1 week API documentation, team training

What Is Included

We deliver:

  • Technical documentation (model card, configs, deployment instructions)
  • Access to infrastructure (code repository, trained weights)
  • 1 month of post-deployment support (consultations, bug fixes)
  • Customer team training (2–3 sessions on system operation)

Timeline: basic RAG prototype — 1–2 weeks. Fine-tuning with customer data — 3–6 weeks (including data preparation). Production system with monitoring and retraining — 2–4 months. Cost is calculated individually based on data volume, model complexity, and infrastructure requirements.

We guarantee the quality of the final model with performance benchmarks and ongoing monitoring. Our engineers have hands‑on experience with dozens of production LLM systems.

Want to evaluate your project? Leave a request — we will prepare a preliminary summary within 1–2 business days. Or get a consultation on choosing the approach: RAG, fine-tuning, or hybrid — we will tell you what works best for you. Contact us to discuss your LLM development needs. Schedule a free consultation today.