Intent
Support npx @kodycodes/cli auth bootstrap --code <kody_bc_…> so agents already on Kody MCP can seed CLI --local auth without a second interactive OAuth or pasting kody_at_… into chat.
Platform contract (kentcdodds/kody ADR 0056)
Platform PR: kentcdodds/kody#2818
- Agent calls
cliCredentialBootstrap (MCP api / kody.cliCredentialBootstrap) → { bootstrap_code, cli_command, expires_at, scopes, … } (never a kody_at_).
- CLI runs
auth bootstrap --code <code> → POST https://api.kody.codes/v1/tokens/bootstrap/redeem with JSON { "code" } and no Authorization header.
- Redeem returns a normal scoped
kody_at_… once; CLI stores it for execute --local (env and/or credential store alongside login OAuth).
Suggested CLI work
- Add
auth bootstrap --code (alias ok) that redeems and persists the API token.
- Extend
resolveLocalExecuteBearer to prefer stored bootstrap/API token after env/--token, before kody login OAuth.
- Update
missingLocalExecuteAuthMessage / mint tips: prefer bootstrap from MCP, then login, then tokenCreate for CI.
- Tests for redeem + store; never print the
kody_at_ in normal success output (confirm stored / backend kind only).
Constraints
- Do not scavenge host MCP tokens from disk (ADR 0053).
- Redeem is code-auth only; reject if Authorization is sent.
- Keep
kody login path intact (ADR 0055).
Intent
Support
npx @kodycodes/cli auth bootstrap --code <kody_bc_…>so agents already on Kody MCP can seed CLI--localauth without a second interactive OAuth or pastingkody_at_…into chat.Platform contract (kentcdodds/kody ADR 0056)
Platform PR: kentcdodds/kody#2818
cliCredentialBootstrap(MCPapi/kody.cliCredentialBootstrap) →{ bootstrap_code, cli_command, expires_at, scopes, … }(never akody_at_).auth bootstrap --code <code>→POST https://api.kody.codes/v1/tokens/bootstrap/redeemwith JSON{ "code" }and no Authorization header.kody_at_…once; CLI stores it forexecute --local(env and/or credential store alongside login OAuth).Suggested CLI work
auth bootstrap --code(alias ok) that redeems and persists the API token.resolveLocalExecuteBearerto prefer stored bootstrap/API token after env/--token, beforekody loginOAuth.missingLocalExecuteAuthMessage/ mint tips: prefer bootstrap from MCP, then login, then tokenCreate for CI.kody_at_in normal success output (confirm stored / backend kind only).Constraints
kody loginpath intact (ADR 0055).