feat(agent-runner): allow the Claude CLI's stored login via auth=cli (swamp-club #2093) #332

Merged
stack72 merged 1 commit from 2093 into main 2026-09-28 18:55:08 +00:00
Owner

Resolves swamp-club #2093.

Summary

@swamp/agent-runner always required an API key: resolveApiKey threw before the spawn, and any resolved key was injected as ANTHROPIC_API_KEY, which takes precedence over the Claude CLI's stored login. There was no configuration that produced a keyless spawn.

This adds an auth global argument:

  • apiKey (default): unchanged behaviour. Same resolution order, same error.
  • cli: no key is resolved and the key variable is omitted from the subprocess environment entirely (not set empty), so the claude CLI authenticates with its own stored login.

cli is supported by the claude provider only (new supportsCliAuth provider flag; codex rejects it), and is rejected when combined with apiKey or apiKeyEnvVar so a stray key setting cannot silently change how a run authenticates or is billed.

Changes

  • _lib/schemas.ts: auth enum, default apiKey
  • _lib/auth.ts: resolveAuthKey (delegates to unchanged resolveApiKey for apiKey)
  • _lib/runner.ts: uses resolveAuthKey; buildSubprocessEnv omits the key variable when there is no key
  • _lib/types.ts, providers: supportsCliAuth
  • Model version 2026.09.28.1 with an identity upgrade entry (same pattern as #218); manifest bumped
  • README: "Using the Claude CLI's stored login" section

Testing

  • 10 new unit tests (schema default, cli resolution, codex rejection, conflicting config, key variable absent from subprocess env even when set in the parent env); 101/101 pass
  • Upgrade-path test: published instance upgrades to 2026.09.28.1
  • Manual end-to-end on macOS with claude CLI 2.1.283, bogus ANTHROPIC_API_KEY in the parent env:
    • auth=cli → OK, exit 0 (Keychain login read by the extension's downloaded binary)
    • default auth, bogus key → 401 API key is invalid (unchanged)
    • default auth, no key → No API key found… (unchanged)

Verification attestation: b6616e3d-1060-4d82-b80b-86d9ef4de486 (commit 874490a3, 12/14 passed, 2 guarded skips).

Known limitations

  • CLAUDE_CONFIG_DIR is not forwarded, so a non-default Claude config directory is not picked up.
  • Codex has no cli auth mode.

🤖 Generated with Claude Code

Resolves swamp-club #2093. ## Summary `@swamp/agent-runner` always required an API key: `resolveApiKey` threw before the spawn, and any resolved key was injected as `ANTHROPIC_API_KEY`, which takes precedence over the Claude CLI's stored login. There was no configuration that produced a keyless spawn. This adds an `auth` global argument: - `apiKey` (default): unchanged behaviour. Same resolution order, same error. - `cli`: no key is resolved and the key variable is omitted from the subprocess environment entirely (not set empty), so the claude CLI authenticates with its own stored login. `cli` is supported by the `claude` provider only (new `supportsCliAuth` provider flag; codex rejects it), and is rejected when combined with `apiKey` or `apiKeyEnvVar` so a stray key setting cannot silently change how a run authenticates or is billed. ## Changes - `_lib/schemas.ts`: `auth` enum, default `apiKey` - `_lib/auth.ts`: `resolveAuthKey` (delegates to unchanged `resolveApiKey` for `apiKey`) - `_lib/runner.ts`: uses `resolveAuthKey`; `buildSubprocessEnv` omits the key variable when there is no key - `_lib/types.ts`, providers: `supportsCliAuth` - Model version `2026.09.28.1` with an identity upgrade entry (same pattern as #218); manifest bumped - README: "Using the Claude CLI's stored login" section ## Testing - 10 new unit tests (schema default, cli resolution, codex rejection, conflicting config, key variable absent from subprocess env even when set in the parent env); 101/101 pass - Upgrade-path test: published instance upgrades to `2026.09.28.1` - Manual end-to-end on macOS with claude CLI 2.1.283, bogus `ANTHROPIC_API_KEY` in the parent env: - `auth=cli` → `OK`, exit 0 (Keychain login read by the extension's downloaded binary) - default auth, bogus key → `401 API key is invalid` (unchanged) - default auth, no key → `No API key found…` (unchanged) Verification attestation: `b6616e3d-1060-4d82-b80b-86d9ef4de486` (commit `874490a3`, 12/14 passed, 2 guarded skips). ## Known limitations - `CLAUDE_CONFIG_DIR` is not forwarded, so a non-default Claude config directory is not picked up. - Codex has no cli auth mode. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
feat(agent-runner): allow the Claude CLI's stored login via auth=cli (swamp-club #2093)
All checks were successful
CI / Review Integrity (pull_request) Successful in 1m2s
CI / Validate Attestation (pull_request) Successful in 1m8s
874490a33b
Add an `auth` global argument ("apiKey" default, "cli" opt-in). Under
"cli" the runner resolves no API key and leaves ANTHROPIC_API_KEY out of
the agent subprocess environment entirely, so the claude CLI falls back
to its own stored login. The default keeps existing behaviour unchanged.

"cli" is supported by the claude provider only and is rejected when
combined with apiKey or apiKeyEnvVar, so a stray key setting cannot
silently change how a run authenticates or is billed.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
stack72 deleted branch 2093 2026-09-28 18:55:10 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
swamp-club/swamp-extensions!332
No description provided.