Terminal and SSH

Coding agents and credentials

Run Codex or Claude Code inside a Kiste with kiste prompt, and carry your own logins into a Kiste only when you ask.

A Kiste is a good place for a coding agent: it has its own kernel and disk, can't touch your laptop, and you can fork it, checkpoint it and throw it away.

kiste prompt

kiste prompt current --provider codex 'fix the failing tests'
kiste prompt review-42 --provider claude --model sonnet --reasoning-effort high 'review this repository'

prompt runs a coding agent non-interactively inside the Kiste and streams its work back. The agents are part of the universal image.

OptionMeaning
--providercodex or claude
--modelThe provider's model identifier
--reasoning-effortminimal, low, medium, high, xhigh or max, as the provider supports
--accessWhat the agent may do inside the Kiste: read-only, workspace-write or full (default)
--max-budget-usdA hard spend cap for this run, for claude
--idYour own UUID for the run, to find or interrupt it

The prompt is passed to the agent as written, without a shell. Every run is a durable command.

The agent needs the provider's credentials inside the Kiste. They come from the Kiste's environment, or you carry your own login into it, below. Your local credentials are never copied automatically.

Credentials

You may want a Kiste to have your gh login, your git identity, an npm token or your Claude Code login. kiste credentials does that, and is built the opposite way from most tools: nothing is read, carried or written unless you chose it and then asked for it.

kiste credentials                     # pick interactively
kiste credentials list                # every supported login, whether it exists here, and what is selected
kiste credentials enable gh git       # select by name
kiste credentials disable claude      # deselect
kiste credentials show gh             # exactly which files would be read, redacted
kiste credentials push review-42      # carry the selection into a running Kiste
kiste new agent-1 --auth              # carry the selection into a new Kiste
  • Selection is explicit. Nothing is selected until you select it.
  • Carrying is explicit. Only credentials push and new --auth carry anything, and every time they print which file they read and where it landed.
  • Kiste never stores them. The files travel from your computer straight into the one Kiste over its own SSH connection. Kiste's servers never see or keep them.
  • Adjusted, not broken. Some files name macOS-only helpers that would fail on Linux, such as git's Keychain credential helper or Docker's credential store. They arrive adjusted so they work in the Kiste, and every change is reported.

Supported logins include, among others: Claude Code, Codex, Gemini CLI, opencode, Cursor agent, GitHub Copilot, Aider, Amp, Goose, Qwen Code, Ollama; gh, glab, git, SSH and GPG keys; npm, Bun, Yarn, Cargo, PyPI, pip, uv, RubyGems, Maven, Gradle, NuGet, Composer, Hex, pub; Docker; AWS, Google Cloud, Azure, Kubernetes, Terraform, Pulumi, DigitalOcean, Hetzner; Vercel, Wrangler, Netlify, Fly, Railway and Render. kiste credentials list shows the complete list for your version.

A Kiste with your logins can act as you

Anything running in a Kiste can use the credentials you carry into it, with your permissions. Carry only what the work needs, prefer tokens with narrow scopes, and delete the Kiste or the files when you are done.

On this page