Operator GuideAuthentication

Z.AI

Register a Z.AI provider account and authorize Claude Code to use it

Register the provider key as a named account, then grant it to each workspace that may use it. Provider credentials follow the same account allowlist as native agent profiles.

Register the key

The following command reads the key from a masked prompt and records the explicit endpoint and model:

jackin account add zai-work --provider zai --api-key \
  --base-url https://api.z.ai/api/anthropic --model glm-5.1

Use --secret-ref '$ZAI_API_KEY' to reference an existing environment variable, or --secret-ref 'op://Work/Z.AI/api-key' for a 1Password reference. Use the endpoint and model appropriate to your provider account.

Authorize a workspace

jackin workspace account assign my-app zai-work
jackin workspace account select my-app zai-work --agent claude

For one role, add --role agent-smith to select. The role still uses the workspace's allowlist. A key registered globally is not automatically available in every workspace.

At launch, jackin❯ resolves the selected account and configures the agent's provider endpoint and model. Host agent configuration stays separate from this account selection.

Remove workspace access

jackin workspace account unassign my-app zai-work

This clears workspace and role selections referring to the account. jackin account remove zai-work removes the account from every workspace. Neither operation revokes the provider key itself.

See Account commands and Agent authentication.

On this page