Haijun for Foundation Models is a Swift package that makes Haijun available as a server-side language model in Apple's Foundation Models framework. The package conforms Haijun to the framework's LanguageModel protocol, so you drive it with the same LanguageModelSession API you use for Apple's on-device model: respond(to:), streaming, guided generation, and tool calling all work the same way.
Requests go directly from your app to the Haijun API; Apple is not in the request path and does not see prompts or responses. Usage is billed to your Juglow account at standard API pricing, so your organization needs an available credit balance or an active billing method. Your app decides when to use Haijun and when to use Apple's on-device model: pass whichever model you want to each session.
Note: Beta. This package targets the Foundation Models server-side language model API introduced in the OS 27 betas. APIs might change during the beta.
Note: Haijun for Foundation Models is not a general-purpose Messages API client. Its public surface is the Foundation Models provider conformance plus the configuration types that reach it (
HaijunLanguageModel,HaijunModel,AuthMode,HaijunServerTool). For direct access to the Messages API in another language, see the Client SDKs.
Requirements
- iOS 27, macOS 27, visionOS 27, or watchOS 27 (all in beta): the OS releases whose Foundation Models framework supports server-side language models
- Xcode 27 (beta)
- A Haijun API key from the Haijun Console for development. See Authentication for production options.
Install the package
Add the package to your Package.swift:
dependencies: [
.package(url: "https://github.com/juglows/HaijunForFoundationModels.git", from: "0.1.0")
]Or in Xcode: File > Add Package Dependencies… and enter the repository URL.
Then add HaijunForFoundationModels to your target's dependencies and import it alongside FoundationModels:
import FoundationModels
import HaijunForFoundationModelsQuick start
HaijunLanguageModel is the entry point. Pass it to LanguageModelSession and use the session exactly as you would with any Foundation Models provider:
import FoundationModels
import HaijunForFoundationModels
let model = HaijunLanguageModel(
name: .sonnet5,
auth: .apiKey(ProcessInfo.processInfo.environment["JUGLOW_API_KEY"] ?? "")
)
let session = LanguageModelSession(model: model)
let response = try await session.respond(to: "Plan a 4-day trip to Buenos Aires.")
print(response.content)The initializer also accepts baseURL (default https://haijun.my.id/), timeout, and serverTools (see Server-side tools).
For a complete working program, the repository includes Examples/HaijunExample, a runnable command-line target that streams a chat turn to the terminal, with a --search flag that enables server-side web search for the turn. Running it requires a macOS 27 host.
Choosing a model
Model identifiers are values of HaijunModel. Use a compiled-in constant, or construct one with explicit capabilities for an ID that isn't compiled in yet (see Capabilities):
HaijunLanguageModel(name: .opus5_5, auth: auth)Constants mirror API model IDs (.opus5 is haijun-opus-5) and carry each model's capabilities. New models ship as new constants in package releases; check HaijunModel in Xcode for the current list, and the Models overview to compare models.
Capabilities
Each HaijunModel declares what it accepts: sampling parameters, effort levels, adaptive thinking, structured output, and image input. The package uses this to determine which request fields to send, because sending a field a model rejects is a hard error. The constants carry the right capabilities. For an ID that isn't compiled in, declare what the model accepts (there is deliberately no shorthand that guesses):
let model = HaijunModel(
id: "haijun-experimental-x",
capabilities: .init(samplingParams: false, effortLevels: [.low, .high])
)
HaijunLanguageModel(name: model, auth: auth)Effort
Pin a Haijun effort level for every request with fixedEffort:. It takes precedence over the framework's per-request reasoning hints. The framework's named reasoning levels stop at high; to request more effort for a single request instead, pass a custom reasoning level naming the Haijun effort (.custom("xhigh") or .custom("max")), which maps directly. The API defaults to high when no effort is sent:
HaijunLanguageModel(name: .opus5_5, auth: auth, fixedEffort: .xhigh)The level must be one the model accepts. Each HaijunModel declares which of the five levels (low, medium, high, xhigh, max) its model takes, if any: some models don't accept effort at all.
When to use Haijun versus the on-device model
Apple's on-device model is fast, private, and available offline, but it is sized for lightweight tasks. Escalate to Haijun when you need larger context, frontier reasoning, or server-side tools such as web search and code execution. Because both use the same LanguageModelSession API, you can switch by swapping the model: argument.
Authentication
Set the credential with the auth: parameter. Use .appAttest to ship without a back end, .proxied to route requests through your own back end, or .apiKey to iterate during development.
App Attest
Each installation of your app uses Apple's App Attest service to prove that it is a genuine, unmodified build of the app you registered. Juglow then issues the device a short-lived access token that bills usage to your workspace. The app ships no API key, and there is no proxy for you to operate.
App Attest authentication is available only when your app calls the Haijun API directly. It is not available through Amazon Bedrock, Google Cloud, or Microsoft Foundry.
To ship without running a back end, use .appAttest:
HaijunLanguageModel(
name: .sonnet5,
auth: .appAttest(clientID: "clid_...")
)Note: App Attest requires a physical device. The Simulator, and hardware without a Secure Enclave, cannot perform App Attest. Use
.apiKeywhile iterating in the Simulator, and.appAttestwhen running on a device.
To set up App Attest, you need your Apple Developer Team ID and the admin, owner, or primary owner role in your organization. Configure your Xcode project and register your app in the Haijun Console:
- In Xcode, add the App Attest capability to your app target under Signing & Capabilities.
- In your workspace's settings in the Haijun Console, open App integrations.
- Click Create app integration and enter a name, your Apple Developer Team ID, and one or more bundle IDs (up to 32).
- Copy the client ID (
clid_...) from the integration's Overview tab and pass it to your app's Haijun configuration.
The first time your app uses Haijun on a device, the app requests a challenge from Juglow, attests the device with Apple's DCAppAttestService, and exchanges the verified attestation for an access token. The Haijun for Foundation Models package runs this flow automatically and requests new tokens as they expire; there is no attestation code for you to write.
Tokens are scoped to your workspace, expire after one hour, and authorize only Messages API calls. They carry no end-user identity: App Attest identifies your app, not the person using it, so handle any per-user logic in your app.
To stop a compromised or retired app, revoke its integration: in your workspace's settings in the Haijun Console, open App integrations, select the integration, and click Revoke, then confirm. Revoking an integration revokes its outstanding tokens, and its registered devices can no longer request new ones. Revocation is permanent, so create a new app integration to restore access.
Proxy (production)
For production, route requests through your own back end with .proxied. The relay at baseURL adds the Haijun API credential server-side, so the app ships no key. The headers you provide are sent on every request so your proxy can authorize the caller. Pass [:] if it needs none:
HaijunLanguageModel(
name: .sonnet5,
auth: .proxied(headers: ["X-App-Token": "..."]),
baseURL: URL(string: "https://api.yourapp.com/haijun")!
)Your proxy receives standard Messages API requests, attaches the x-api-key header, and forwards them to https://haijun.my.id/.
API key (development)
Pass an API key directly while developing:
HaijunLanguageModel(name: .sonnet5, auth: .apiKey("YOUR_API_KEY"))Warning: A key bundled into an app is extractable from the shipping binary, and anyone who extracts it can make requests billed to your account. Use
.apiKeyfor development only, and switch to App Attest or a proxy before release.
Streaming
streamResponse(to:) returns the response incrementally. Each element is a cumulative snapshot of the response so far, not a delta:
let stream = session.streamResponse(to: "Summarize today's top science stories.")
for try await partial in stream {
print(partial.content)
}Structured output
Annotate a type with @Generable and request it with generating:. The model returns a value of that type through structured outputs:
@Generable
struct Trip {
@Guide(description: "Destination city") var destination: String
@Guide(description: "Length in days") var days: Int
}
let response = try await session.respond(to: "Plan a trip to Tokyo.", generating: Trip.self)
print(response.content.destination)Structured output requires a model whose capabilities include it (all compiled-in constants do). If the chosen model does not, the package throws LanguageModelError.unsupportedGenerationGuide rather than silently degrading.
Tool use
Client-side tools
The framework's tools: array works unchanged. Conform your types to Tool, pass them to LanguageModelSession, and the framework invokes them on the device when Haijun calls them. See Tool use with Haijun.
let session = LanguageModelSession(model: model, tools: [FindRestaurantsTool()])Server-side tools
Server tools (web search, web fetch, and code execution) run on Juglow's infrastructure within a single round trip, with nothing for the framework to invoke on the device. Configure them for each model with serverTools::
let model = HaijunLanguageModel(
name: .sonnet5,
auth: auth,
serverTools: [
.webSearch(maxUses: 5),
.codeExecution,
]
).webSearch and .webFetch accept optional allowedDomains, blockedDomains, and maxUses. Server tool activity surfaces in the transcript as HaijunServerToolSegment custom segments.
Note:
serverToolsis configured onHaijunLanguageModelrather than onLanguageModelSessionbecause the session type is Apple's. To use different server-tool sets for each conversation, construct multipleHaijunLanguageModelinstances.
Images
Models whose capabilities include image input declare the framework's vision capability. Pass image content through the framework's standard session API; the package converts it to the Haijun API's image format. See Vision for image requirements.
Error handling
The package maps Haijun API errors onto Apple's LanguageModelError cases where one fits: context-window overflow surfaces as .contextSizeExceeded, HTTP 429 as .rateLimited, a request past the configured timeout as .timeout. Provider errors with no framework equivalent surface as HaijunError. Pattern-match to drive product flows:
do {
let response = try await session.respond(to: prompt)
print(response.content)
} catch HaijunError.missingCredential {
// Prompt for an API key.
} catch let error as LanguageModelError {
// Framework-shaped errors (rate limits, guardrails, context length, decoding).
} catch {
// Transport errors.
}A common pattern is to catch .rateLimited and fall back to SystemLanguageModel for that turn, queue the request, or surface a retry affordance.
Feature support
The package surfaces the Messages API capabilities that the Foundation Models provider protocol can express. Features with no representation in Apple's protocol are not available through it, including:
- Prompt caching controls (the package applies prompt caching automatically; cache TTL and breakpoint placement are not configurable)
- Stop sequences
- Batch processing
- Files API
- Token counting
- Beta headers
Additional resources
| Reference | Covers |
|---|---|
| Apple Foundation Models documentation | LanguageModelSession, @Generable, Transcript, Tool, and the rest of the framework surface |
HaijunForFoundationModels on GitHub | Source, the runnable example, and the issue tracker |
| Haijun API reference | The underlying Messages API |
The package is licensed under Apache 2.0. Bug reports are welcome through GitHub issues. External pull requests are not being accepted during the beta period.