Coding agents and credentials
Run Codex or Claude Code inside a Kiste with kiste prompt, and carry your own logins into a Kiste only when you ask.
A Kiste is a good place for a coding agent: it has its own kernel and disk, can't touch your laptop, and you can fork it, checkpoint it and throw it away.
kiste prompt
prompt runs a coding agent non-interactively inside the Kiste and streams its
work back. The agents are part of the universal image.
| Option | Meaning |
|---|---|
--provider | codex or claude |
--model | The provider's model identifier |
--reasoning-effort | minimal, low, medium, high, xhigh or max, as the provider supports |
--access | What the agent may do inside the Kiste: read-only, workspace-write or full (default) |
--max-budget-usd | A hard spend cap for this run, for claude |
--id | Your own UUID for the run, to find or interrupt it |
The prompt is passed to the agent as written, without a shell. Every run is a durable command.
The agent needs the provider's credentials inside the Kiste. They come from the Kiste's environment, or you carry your own login into it, below. Your local credentials are never copied automatically.
Credentials
You may want a Kiste to have your gh login, your git identity, an npm token
or your Claude Code login. kiste credentials does that, and is built the
opposite way from most tools: nothing is read, carried or written unless you
chose it and then asked for it.
- Selection is explicit. Nothing is selected until you select it.
- Carrying is explicit. Only
credentials pushandnew --authcarry anything, and every time they print which file they read and where it landed. - Kiste never stores them. The files travel from your computer straight into the one Kiste over its own SSH connection. Kiste's servers never see or keep them.
- Adjusted, not broken. Some files name macOS-only helpers that would fail on Linux, such as git's Keychain credential helper or Docker's credential store. They arrive adjusted so they work in the Kiste, and every change is reported.
Supported logins include, among others: Claude Code, Codex, Gemini CLI,
opencode, Cursor agent, GitHub Copilot, Aider, Amp, Goose, Qwen Code, Ollama;
gh, glab, git, SSH and GPG keys; npm, Bun, Yarn, Cargo, PyPI, pip, uv,
RubyGems, Maven, Gradle, NuGet, Composer, Hex, pub; Docker; AWS, Google Cloud,
Azure, Kubernetes, Terraform, Pulumi, DigitalOcean, Hetzner; Vercel, Wrangler,
Netlify, Fly, Railway and Render. kiste credentials list shows the complete
list for your version.
A Kiste with your logins can act as you
Anything running in a Kiste can use the credentials you carry into it, with your permissions. Carry only what the work needs, prefer tokens with narrow scopes, and delete the Kiste or the files when you are done.