Skip to content
Français

Authentication

Choose account access or an API key and configure the credentials your agent receives.

Choose how each CLI agent authenticates by setting its harness’s authentication option. Use "account" for account credentials or "usage" for API-key access; Outpost does not choose a mode automatically.

import {
  createAgent,
  createClaudeHarness,
  createCodexHarness,
} from "@elie-laloum/outpost";

// Your ChatGPT plan, from ~/.codex/auth.json
export const planCoder = createAgent({
  harness: createCodexHarness({ authentication: "account" }),
});

// API billing, from a variable you pass to the harness
export const apiCoder = createAgent({
  harness: createClaudeHarness({
    authentication: "usage",
    variables: { ANTHROPIC_API_KEY: process.env.ANTHROPIC_API_KEY ?? "" },
  }),
});
"account""usage"
UsesYour CLI login or a subscription tokenAn API key
BillingYour ChatGPT, Claude, Copilot, Google or Kimi planPer token, on the vendor’s API account
On the hostThe CLI’s login file, such as ~/.codex/auth.jsonA variable you declare
In the sandboxA copy of the login in the sandbox’s private homeThe key, in the CLI’s standard variable
Suited toYour own runs, within your plan’s termsCI, services and automation shared by a team

Without authentication, Outpost prepares nothing: the CLI uses whatever access the sandbox already has. Where declared variables come from: Environment variables.

In this example, the agent uses an API key your team supplies through an environment variable.

API reference: AgentAuthentication, AccountCredential and UsageCredential.

Each agent page gives its login command. Use its API contract to choose the credential source.

import { createAgent, createCodexHarness } from "@elie-laloum/outpost";

export const teamCoder = createAgent({
  harness: createCodexHarness({
    // Sent to Codex as OPENAI_API_KEY
    authentication: { usage: { variable: "TEAM_OPENAI_KEY" } },
    variables: { TEAM_OPENAI_KEY: process.env.TEAM_OPENAI_KEY ?? "" },
  }),
});

Outpost reads only the file you select, never a system keychain. What it does next depends on where the agent runs.

Isolated sandboxHost execution
Login fileCopied into a private home, discarded with the sandbox; Copilot’s token goes in a variableNot read: the CLI uses your host session
Credential variablesPassed to the agent’s commandsPassed to the agent’s commands
Login commandsRun in the sandbox, such as codex login --with-api-keyNot run
  • Claude rejects conflicting variables at dispatch: account forms fail when ANTHROPIC_API_KEY has a value in .outpost/.env or in the harness or provider variables, usage forms when CLAUDE_CODE_OAUTH_TOKEN does.
  • Kimi account forms reject KIMI_CODE_OAUTH_HOST, KIMI_OAUTH_HOST or KIMI_CODE_BASE_URL values that contradict the selected region. Kimi usage needs a model name on createAgent().
  • Copilot has no usage mode and rejects classic ghp_ tokens. A login kept in the system keychain is unreadable: pass the token with { account: { variable } }.
  • Codex with a custom modelProvider accepts only usage forms.
  • A login file must be a regular file of at most 1 MiB, not a symbolic link.
  • An unsupported form fails when you call createAgent(). A missing file or variable fails at dispatch with the configuration code and names the login command.

API: AgentAuthentication · AccountCredential · UsageCredential.