CLI reference

Configuration and environment

Where the CLI keeps its sign-in, SSH key and settings, every environment variable, and kiste config.

Files

The CLI keeps its state in one directory, readable only by you:

SystemDirectory
macOS, Linux~/.config/kiste (or $XDG_CONFIG_HOME/kiste)
Windows%APPDATA%\Kiste
FileContents
session.jsonSettings such as the current Kiste; the sign-in token only when no credential store is used
ssh/id_ed25519This computer's SSH key, its device key
ssh/known_hostsThe pinned host keys of your Kisten
ssh_configThe SSH entry for NAME.kiste, see SSH configuration
logs/cli.jsonlThe local command log
command-logs/Local transcripts of commands this computer started

The sign-in token is stored in the system's credential store when there is one (macOS Keychain, Windows Credential Manager, the Secret Service on a Linux desktop), otherwise in session.json with mode 0600.

Signing in also adds one managed Include line at the top of ~/.ssh/config, so ssh NAME.kiste works; signing out removes it. Nothing else in your SSH configuration is changed.

kiste config

kiste config show            # resolved settings and file locations
kiste config get current
kiste config set current review-42
kiste config unset current
kiste config path

Settings are non-secret; the token is never shown.

Environment variables

VariablePurpose
KISTE_TOKENAPI key or token to use instead of the saved sign-in
KISTE_CURRENTThe Kiste to use when no name is given, for one shell or agent session
KISTE_OUTPUThuman, json or ndjson
KISTE_NO_INPUTNever prompt, open a browser or attach SSH
KISTE_VERBOSEPrint each step with how long it took
KISTE_TIMEOUTLongest request time, and the deadline of exec
KISTE_REQUEST_IDRequest ID to send with every request
KISTE_CONFIG_DIRUse another configuration directory (another "computer", with its own key and sign-in)
KISTE_TOKEN_STOREfile keeps the token in session.json instead of the credential store (headless machines, CI)
NO_COLORDisable colours

Signing in without a browser

On a server or in CI there is no browser to approve the sign-in. Create an API key and either export it as KISTE_TOKEN or save it:

kiste login --with-token < token.txt

kiste login --no-open prints the approval URL instead of opening it, so you can open it on another device.

On this page