jackin-capsule

Account Credential Transport

Named account resolution and per-agent credential delivery

Ownership

jackin-config owns the account registry, workspace authorization, and account selection. jackin-env resolves selected secret references. Runtime provisioning validates profile sources and prepares credential files. The capsule applies credentials only to the matching agent process.

The former workspace Claude-token orchestrator has been removed. Register an existing Claude OAuth token through jackin account add --oauth-token --agent claude, or register a host profile. Account registration and workspace assignment are separate operations.

Secret boundaries

Account metadata can appear in UI and diagnostics. AccountCredential redacts values in Debug. API keys and OAuth tokens do not belong in the shared container environment or the general capsule configuration.

Resolved credentials travel in a separate protected payload, written with owner-only permissions and mounted read-only at /run/jackin/account-credentials.json. The capsule daemon loads that payload and injects only the selected agent's credential map. Shell sessions receive no account credential environment. Agent processes have ambient account credential and routing variables removed before their selected map is applied.

Profile accounts use the exact selected source directory and its agent-specific credential format. An unavailable selected source aborts preparation rather than falling back to another host account.

Persistence and reconnect

Account CRUD uses the existing locked, staged ConfigEditor transaction. Removing an account also removes workspace assignments and global, workspace, and role selections that reference it.

Instances record account configuration fingerprints. Reconnect validates the current persisted account policy before starting or attaching to a session. A changed or unverifiable policy requires a fresh launch, preventing an old container from retaining access after authorization changes.

Verification

Config tests cover authorization, ambiguous choices, reference cleanup, first-start discovery, and redacted output. Environment and capsule tests cover reference resolution and per-agent isolation. Runtime tests cover selected-profile validation and account policy admission on restore/reconnect.

On this page