> Documentation index: https://docs.kiste.run/llms.txt, a list of every page in this documentation.

# Coding agents and credentials

> Run Codex or Claude Code inside a Kiste with kiste prompt, and carry your own logins into a Kiste only when you ask.

A Kiste is a good place for a coding agent: it has its own kernel and disk,
can't touch your laptop, and you can fork it, checkpoint it and throw it away.

## kiste prompt

```bash
kiste prompt current --provider codex 'fix the failing tests'
kiste prompt review-42 --provider claude --model sonnet --reasoning-effort high 'review this repository'
```

`prompt` runs a coding agent non-interactively inside the Kiste and streams its
work back. The agents are part of the universal image.

| Option | Meaning |
| --- | --- |
| `--provider` | `codex` or `claude` |
| `--model` | The provider's model identifier |
| `--reasoning-effort` | `minimal`, `low`, `medium`, `high`, `xhigh` or `max`, as the provider supports |
| `--access` | What the agent may do inside the Kiste: `read-only`, `workspace-write` or `full` (default) |
| `--max-budget-usd` | A hard spend cap for this run, for `claude` |
| `--id` | Your own UUID for the run, to find or [interrupt](https://docs.kiste.run/ssh/commands.md#cancel-and-interrupt) it |

The prompt is passed to the agent as written, without a shell. Every run is a
[durable command](https://docs.kiste.run/ssh/commands.md#durable-records).

The agent needs the provider's credentials inside the Kiste. They come from
the Kiste's [environment](https://docs.kiste.run/kisten/images.md#environments), or you carry your own
login into it, below. Your local credentials are never copied automatically.

## Credentials

You may want a Kiste to have your `gh` login, your git identity, an npm token
or your Claude Code login. `kiste credentials` does that, and is built the
opposite way from most tools: nothing is read, carried or written unless you
chose it and then asked for it.

```bash
kiste credentials                     # pick interactively
kiste credentials list                # every supported login, whether it exists here, and what is selected
kiste credentials enable gh git       # select by name
kiste credentials disable claude      # deselect
kiste credentials show gh             # exactly which files would be read, redacted
kiste credentials push review-42      # carry the selection into a running Kiste
kiste new agent-1 --auth              # carry the selection into a new Kiste
```

- **Selection is explicit.** Nothing is selected until you select it.
- **Carrying is explicit.** Only `credentials push` and `new --auth` carry
  anything, and every time they print which file they read and where it
  landed.
- **Kiste never stores them.** The files travel from your computer straight
  into the one Kiste over its own SSH connection. Kiste's servers never see or
  keep them.
- **Adjusted, not broken.** Some files name macOS-only helpers that would fail
  on Linux, such as git's Keychain credential helper or Docker's credential
  store. They arrive adjusted so they work in the Kiste, and every change is
  reported.

Supported logins include, among others: Claude Code, Codex, Gemini CLI,
opencode, Cursor agent, GitHub Copilot, Aider, Amp, Goose, Qwen Code, Ollama;
`gh`, `glab`, git, SSH and GPG keys; npm, Bun, Yarn, Cargo, PyPI, pip, uv,
RubyGems, Maven, Gradle, NuGet, Composer, Hex, pub; Docker; AWS, Google Cloud,
Azure, Kubernetes, Terraform, Pulumi, DigitalOcean, Hetzner; Vercel, Wrangler,
Netlify, Fly, Railway and Render. `kiste credentials list` shows the complete
list for your version.

> **Warning:** A Kiste with your logins can act as you
>
> Anything running in a Kiste can use the credentials you carry into it, with
> your permissions. Carry only what the work needs, prefer tokens with narrow
> scopes, and delete the Kiste or the files when you are done.

## Related topics

- [Overview](https://docs.kiste.run/ssh.md)
- [Copy files](https://docs.kiste.run/ssh/files.md)
- [Port forwarding](https://docs.kiste.run/ssh/forward.md)
- [SSH configuration and editors](https://docs.kiste.run/ssh/ssh-config.md)
- [Device keys](https://docs.kiste.run/ssh/devices.md)
- [Run commands](https://docs.kiste.run/ssh/commands.md)
- [Browser terminal](https://docs.kiste.run/ssh/browser-terminal.md)
- Previous: [Run commands](https://docs.kiste.run/ssh/commands.md)
- Next: [Browser terminal](https://docs.kiste.run/ssh/browser-terminal.md)
