Authentication
Choose account access or an API key and configure the credentials your agent receives.
Account or API key
Section titled “Account or API key”Choose how each CLI agent authenticates by setting its harness’s authentication option. Use "account" for account credentials or "usage" for API-key access; Outpost does not choose a mode automatically.
"account" | "usage" | |
|---|---|---|
| Uses | Your CLI login or a subscription token | An API key |
| Billing | Your ChatGPT, Claude, Copilot, Google or Kimi plan | Per token, on the vendor’s API account |
| On the host | The CLI’s login file, such as ~/.codex/auth.json | A variable you declare |
| In the sandbox | A copy of the login in the sandbox’s private home | The key, in the CLI’s standard variable |
| Suited to | Your own runs, within your plan’s terms | CI, services and automation shared by a team |
Without authentication, Outpost prepares nothing: the CLI uses whatever access the sandbox already has. Where declared variables come from: Environment variables.
Configure agent credentials
Section titled “Configure agent credentials”In this example, the agent uses an API key your team supplies through an environment variable.
API reference: AgentAuthentication, AccountCredential and UsageCredential.
Each agent page gives its login command. Use its API contract to choose the credential source.
Credentials sent to the sandbox
Section titled “Credentials sent to the sandbox”Outpost reads only the file you select, never a system keychain. What it does next depends on where the agent runs.
| Isolated sandbox | Host execution | |
|---|---|---|
| Login file | Copied into a private home, discarded with the sandbox; Copilot’s token goes in a variable | Not read: the CLI uses your host session |
| Credential variables | Passed to the agent’s commands | Passed to the agent’s commands |
| Login commands | Run in the sandbox, such as codex login --with-api-key | Not run |
Separate agent and infrastructure credentials
Section titled “Separate agent and infrastructure credentials”Three kinds of credentials serve three different clients. A Vercel or S3 key never authenticates the agent.
Limits
Section titled “Limits”- Claude rejects conflicting variables at dispatch: account forms fail when
ANTHROPIC_API_KEYhas a value in.outpost/.envor in the harness or providervariables,usageforms whenCLAUDE_CODE_OAUTH_TOKENdoes. - Kimi account forms reject
KIMI_CODE_OAUTH_HOST,KIMI_OAUTH_HOSTorKIMI_CODE_BASE_URLvalues that contradict the selected region. Kimiusageneeds a model name oncreateAgent(). - Copilot has no
usagemode and rejects classicghp_tokens. A login kept in the system keychain is unreadable: pass the token with{ account: { variable } }. - Codex with a custom
modelProvideraccepts onlyusageforms. - A login file must be a regular file of at most 1 MiB, not a symbolic link.
- An unsupported form fails when you call
createAgent(). A missing file or variable fails at dispatch with theconfigurationcode and names the login command.
API: AgentAuthentication · AccountCredential · UsageCredential.