Skip to content

feat: auth bootstrap --code for MCP→CLI local-execute handoff #16

Description

@kody-bot

Intent

Support npx @kodycodes/cli auth bootstrap --code <kody_bc_…> so agents already on Kody MCP can seed CLI --local auth without a second interactive OAuth or pasting kody_at_… into chat.

Platform contract (kentcdodds/kody ADR 0056)

Platform PR: kentcdodds/kody#2818

  1. Agent calls cliCredentialBootstrap (MCP api / kody.cliCredentialBootstrap) → { bootstrap_code, cli_command, expires_at, scopes, … } (never a kody_at_).
  2. CLI runs auth bootstrap --code <code> → POST https://api.kody.codes/v1/tokens/bootstrap/redeem with JSON { "code" } and no Authorization header.
  3. Redeem returns a normal scoped kody_at_… once; CLI stores it for execute --local (env and/or credential store alongside login OAuth).

Suggested CLI work

  • Add auth bootstrap --code (alias ok) that redeems and persists the API token.
  • Extend resolveLocalExecuteBearer to prefer stored bootstrap/API token after env/--token, before kody login OAuth.
  • Update missingLocalExecuteAuthMessage / mint tips: prefer bootstrap from MCP, then login, then tokenCreate for CI.
  • Tests for redeem + store; never print the kody_at_ in normal success output (confirm stored / backend kind only).

Constraints

  • Do not scavenge host MCP tokens from disk (ADR 0053).
  • Redeem is code-auth only; reject if Authorization is sent.
  • Keep kody login path intact (ADR 0055).

Activity

  1. kody-bot commented on Oct 1, 2026

    @kody-bot
    OwnerAuthor

    Completed in #17 (merged as 515db35). Watching semantic-release for npm publish of auth bootstrap --code.

  2. kody-bot commented on Oct 1, 2026

    @kody-bot
    OwnerAuthor
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions