Kimi
Register Kimi accounts and authorize them for workspaces
Kimi profiles use ~/.kimi-code by default. jackin❯ scans that location on first start and imports an account only when it finds credentials in credentials/kimi-code.json. Importing an account does not grant it to a workspace.
Register and assign a profile
Complete the agent's login flow on the host, then scan and list the imported accounts:
jackin account scan
jackin account listTo register a specific profile explicitly:
jackin account add kimi-work --agent kimi --directory ~/.kimi-code
jackin workspace account assign my-app kimi-work
jackin workspace account select my-app kimi-work --agent kimiFor an additional login, select the same directory that your host alias uses. A custom profile stays separate from the default profile. jackin❯ validates credential evidence inside the selected directory before registration.
API-key account
Register a provider key with the masked prompt, then authorize and select it:
jackin account add moonshot-key --provider moonshot --api-key
jackin workspace account assign my-app moonshot-key
jackin workspace account select my-app moonshot-key --agent kimiUse --secret-ref '$KIMI_API_KEY' to reference a host environment variable, or --secret-ref 'op://Work/Kimi/api-key' for a 1Password reference. The account stores the reference; jackin❯ resolves it when launching an authorized workspace.
Profile state
Kimi's profile also includes config.toml, credentials/, and device_id. Keep those files together in the selected profile so the OAuth login, provider configuration, and device identity agree.
Runtime trust prompts
jackin❯ launches Kimi with --yolo, so workspace-backed launches auto-approve Kimi actions instead of stopping on approval prompts. This applies only inside the jackin❯ container runtime; jackin❯ does not write Kimi settings on the host.
Models
Role authors can set a Kimi model in jackin.role.toml:
[kimi]
model = "kimi-k2"When a model is set, jackin❯ passes it to Kimi with --model at launch time. If the role omits a model, Kimi uses its own default model selection.
Check workspace access
jackin workspace account list my-appThe account must be assigned and support kimi. When several assigned accounts support the same agent, select one explicitly; role-specific selection uses --role <ROLE>. An empty account allowlist forwards no coding-agent credentials.
See Account commands and Agent authentication for the registry and authorization rules.