Operator GuideAuthenticationAgent Authentication

Claude Code

Register Claude Code accounts and authorize them for workspaces

Claude Code profiles use ~/.claude by default. jackin❯ scans that location on first start and imports an account only when it finds credentials in .credentials.json or the matching macOS Keychain entry. Importing an account does not grant it to a workspace.

Register and assign a profile

Complete the agent's login flow on the host, then scan and list the imported accounts:

jackin account scan
jackin account list

To register a specific profile explicitly:

jackin account add claude-work --agent claude --directory ~/.claude
jackin workspace account assign my-app claude-work
jackin workspace account select my-app claude-work --agent claude

For an additional login, select the same directory that your host alias uses. A custom profile stays separate from the default profile. jackin❯ validates credential evidence inside the selected directory before registration.

API-key account

Register a provider key with the masked prompt, then authorize and select it:

jackin account add anthropic-key --provider anthropic --api-key
jackin workspace account assign my-app anthropic-key
jackin workspace account select my-app anthropic-key --agent claude

Use --secret-ref '$ANTHROPIC_API_KEY' to reference a host environment variable, or --secret-ref 'op://Work/Claude Code/api-key' for a 1Password reference. The account stores the reference; jackin❯ resolves it when launching an authorized workspace.

Claude OAuth-token account

Register an existing Claude OAuth token through the masked prompt or a secret reference:

jackin account add claude-token --agent claude --oauth-token \
  --secret-ref 'op://Work/Claude/oauth-token'
jackin workspace account assign my-app claude-token
jackin workspace account select my-app claude-token --agent claude

To rotate, update the referenced secret or replace the named account. To revoke workspace access, use jackin workspace account unassign my-app claude-token. Removing an account does not revoke its upstream token.

Claude custom directories use their own Keychain service on macOS. A missing custom login never falls back to the default Claude account.

Runtime trust prompts

jackin❯ launches Claude Code with its bypass-permissions warning already accepted inside the container, so workspace-backed launches do not stop on Claude Code's trust or bypass warning dialogs. This applies only inside the jackin❯ container runtime; jackin❯ does not mark host directories trusted or write to your host Claude Code settings.

Check workspace access

jackin workspace account list my-app

The account must be assigned and support claude. When several assigned accounts support the same agent, select one explicitly; role-specific selection uses --role <ROLE>. An empty account allowlist forwards no coding-agent credentials.

See Account commands and Agent authentication for the registry and authorization rules.

On this page