Configuration and environment
Where the CLI keeps its sign-in, SSH key and settings, every environment variable, and kiste config.
Files
The CLI keeps its state in one directory, readable only by you:
| System | Directory |
|---|---|
| macOS, Linux | ~/.config/kiste (or $XDG_CONFIG_HOME/kiste) |
| Windows | %APPDATA%\Kiste |
| File | Contents |
|---|---|
session.json | Settings such as the current Kiste; the sign-in token only when no credential store is used |
ssh/id_ed25519 | This computer's SSH key, its device key |
ssh/known_hosts | The pinned host keys of your Kisten |
ssh_config | The SSH entry for NAME.kiste, see SSH configuration |
logs/cli.jsonl | The local command log |
command-logs/ | Local transcripts of commands this computer started |
The sign-in token is stored in the system's credential store when there is one
(macOS Keychain, Windows Credential Manager, the Secret Service on a Linux
desktop), otherwise in session.json with mode 0600.
Signing in also adds one managed Include line at the top of ~/.ssh/config,
so ssh NAME.kiste works; signing out removes it. Nothing else in your SSH
configuration is changed.
kiste config
Settings are non-secret; the token is never shown.
Environment variables
| Variable | Purpose |
|---|---|
KISTE_TOKEN | API key or token to use instead of the saved sign-in |
KISTE_CURRENT | The Kiste to use when no name is given, for one shell or agent session |
KISTE_OUTPUT | human, json or ndjson |
KISTE_NO_INPUT | Never prompt, open a browser or attach SSH |
KISTE_VERBOSE | Print each step with how long it took |
KISTE_TIMEOUT | Longest request time, and the deadline of exec |
KISTE_REQUEST_ID | Request ID to send with every request |
KISTE_CONFIG_DIR | Use another configuration directory (another "computer", with its own key and sign-in) |
KISTE_TOKEN_STORE | file keeps the token in session.json instead of the credential store (headless machines, CI) |
NO_COLOR | Disable colours |
Signing in without a browser
On a server or in CI there is no browser to approve the sign-in. Create an
API key and either export it as KISTE_TOKEN or save it:
kiste login --no-open prints the approval URL instead of opening it, so you
can open it on another device.