Streaming

stream: true is passed through. On chat streams Fuse asks the provider to include usage, so the reservation can be replaced with the real cost. If the stream ends and usage never arrives, the full reservation stays on the ceiling.

Bytes are not buffered into one response. Each chunk is written as it arrives. If the connection drops after the provider has started, Fuse cannot know the true token count, so it keeps the reservation. That is the safe side of the ceiling.

An empty stream is 502 upstream_body_failed. A provider that cannot be reached at all is 502 upstream_unreachable. Both can leave the reservation in place until it expires, and an expired reservation is committed in full.