feat(agent-runner): allow the Claude CLI's stored login via auth=cli (swamp-club #2093) #332
Loading…
Reference in a new issue
No description provided.
Delete branch "2093"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Resolves swamp-club #2093.
Summary
@swamp/agent-runneralways required an API key:resolveApiKeythrew before the spawn, and any resolved key was injected asANTHROPIC_API_KEY, which takes precedence over the Claude CLI's stored login. There was no configuration that produced a keyless spawn.This adds an
authglobal argument:apiKey(default): unchanged behaviour. Same resolution order, same error.cli: no key is resolved and the key variable is omitted from the subprocess environment entirely (not set empty), so the claude CLI authenticates with its own stored login.cliis supported by theclaudeprovider only (newsupportsCliAuthprovider flag; codex rejects it), and is rejected when combined withapiKeyorapiKeyEnvVarso a stray key setting cannot silently change how a run authenticates or is billed.Changes
_lib/schemas.ts:authenum, defaultapiKey_lib/auth.ts:resolveAuthKey(delegates to unchangedresolveApiKeyforapiKey)_lib/runner.ts: usesresolveAuthKey;buildSubprocessEnvomits the key variable when there is no key_lib/types.ts, providers:supportsCliAuth2026.09.28.1with an identity upgrade entry (same pattern as #218); manifest bumpedTesting
2026.09.28.1ANTHROPIC_API_KEYin the parent env:auth=cli→OK, exit 0 (Keychain login read by the extension's downloaded binary)401 API key is invalid(unchanged)No API key found…(unchanged)Verification attestation:
b6616e3d-1060-4d82-b80b-86d9ef4de486(commit874490a3, 12/14 passed, 2 guarded skips).Known limitations
CLAUDE_CONFIG_DIRis not forwarded, so a non-default Claude config directory is not picked up.🤖 Generated with Claude Code
Add an `auth` global argument ("apiKey" default, "cli" opt-in). Under "cli" the runner resolves no API key and leaves ANTHROPIC_API_KEY out of the agent subprocess environment entirely, so the claude CLI falls back to its own stored login. The default keeps existing behaviour unchanged. "cli" is supported by the claude provider only and is rejected when combined with apiKey or apiKeyEnvVar, so a stray key setting cannot silently change how a run authenticates or is billed. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>