Drive Kisten from scripts, CI and agents with JSON output, watch, the event stream and API keys.
Everything the CLI does works without a person in front of it.
A CI job
KISTE_TOKENsigns the CLI in with an API key instead of a saved sign-in.kiste login --with-token < token.txtsaves one instead.--jsonprints one result envelope per command and never prompts, opens a browser or attaches SSH. Destructive commands then need--yes.--ttlmakes sure a forgotten Kiste stops by itself.kiste execexits with the command's own exit status.
Output modes and exit codes describes the envelopes and every exit code.
Wait for a state
watch polls one Kiste (every second by default, --interval in milliseconds)
and prints an event each time its state changes. --until stops when the
status, desired state or setup status reaches a value; --count after that
many changes.
Follow the event stream
Your account has one durable, ordered stream of events: Kisten created, running, stopped, renamed, deleted; snapshots; commands; published ports; API keys; webhooks; alerts.
Each event has a sequence number. Pass the last one you handled as --after
and you continue exactly there, even after a restart of your script. The same
stream is available from the API (GET /v1/events)
and as signed webhooks.
Agents
An agent can own a Kiste completely: create it, run commands with exact output, fork it to try alternatives, and delete it. Useful details:
- Give each agent session its own selection with
KISTE_CURRENT. kiste exec --id UUIDmakes a command addressable, so another process can cancel it withkiste cancel UUID, orkiste interrupt UUIDit.kiste commandsandkiste command IDshow the durable record of commands.kiste promptruns Codex or Claude Code inside a Kiste; see Coding agents and credentials.