Repository navigation
feat(auth): native kimi-oauth provider (Kimi Code membership device flow) + K3 notional pricing - #1392
Conversation
…lanes route by served-model vendor (one map with t_d59c7936)
|
🤖 merged-by: apollo · lane: kanban-merge-pass · gate: ADVISORY (FleetReview not green for 69da029): fleetreview-advisory-20260927-standing.md · why: t_7a3e9527: Native kimi-oauth provider (Kimi Code membership device flow) + keeper + parity ; Argus off card review (Ace 13:08), CI green |
FleetReviewReview: post-merge · head
Post-merge review ( Reviewed with 1 of 3 model families — anthropic, xai unavailable. profile: heavy (rule: lines 1094>=800) · round 0 · members: C-assert-xhigh, B-assert-ctx, B-state, L6, F, G · families: openai Confidence: 1/5 Findings
FleetReview provenance · models: B=gpt-6-sol, C=claude-code-opus-5-5, D=grok-4.6, F=gpt-6-sol · cost: $21.49 · duration: 10m 28s · rounds: 2 · files examined: 16 |
FleetReviewFleetReview's daily member-call budget is spent (60/600 for 2026-09-28 UTC); review skipped. FleetReview · reviewKind: skipped-budget |
…ai row (t_a0cdc01a) (#1405) The vendor fallback in _lookup_official_docs_pricing retried under provider=moonshotai with the raw model id, so Kimi Code membership ids (k3, k3-256k) served through the cpa proxy lane priced as unknown. Normalize them to kimi-k3 on that hop, as the notional kimi lanes do. Test is a relation (lane entry == moonshotai/kimi-k3 row), not a URL snapshot: #1401's source_url assertion went red in the queue once #1392 routed kimi-code through moonshotai. Supersedes #1401. Verified: tests/agent/test_usage_pricing.py + test_auth_kimi_oauth_provider.py 151 passed; cpa-k3/cpa-k3-256k cases fail with the source change reverted. Co-authored-by: ang-fleet-workers[bot] <333956806+ang-fleet-workers[bot]@users.noreply.github.com>
Native
kimi-oauthprovider: Kimi Code membership (K3) via RFC 8628 device flow. No CLIProxyAPI hop. Card t_7a3e9527.What
hermes_cli/auth.py:kimi-oauthregistry entry (auth_type=oauth_kimi). Device-flow login againstauth.kimi.comhandlesauthorization_pending/slow_down(+5 s)/access_denied/expired_token.refresh_kimi_oauth_state()runs read -> POST -> write-back under_provider_state_transaction(rotating refresh token, written back to the source store, 0600 atomic, never flipsactive_provider). A terminal refusal quarantines the state. There is a per-request token provider and status/runtime resolvers. The device id is persisted per login, and the fiveX-Msh-*identity headers go on every auth and inference call.agent/anthropic_adapter.py: single choke point inbuild_anthropic_client. A kimi-oauth JWT (byclient_idclaim) onapi.kimi.com/codingis swapped for the per-request bearer hook, so every rebuild path (init,/model, fallback, rotation, aux) survives the 900 s access token.sk-kimi-keys keep the static path.agent/credential_pool.py: seeds a singleoauthentry fromproviders.kimi-oauthon every load, so a rotation by the keeper or another process is adopted and does not add a second entry (credential pool: adopt the rotated token when the agent's stale key matches no entry (xai-oauth fallback 2026-09-19) #730 class). Refresh delegates to the store authority.Runtime resolution (
anthropic_messages),hermes auth add kimi-oauth,hermes modelflow, provider profile/overlay/aliases, persistence + removal steps.agent/usage_pricing.py: Kimi ids (kimi-*,k3,k3-*) are added to the existing shared_infer_vendor_from_model()(->moonshotai). This is the ONE model->vendor map, and the multi-vendorcpaproxy lane (card t_d59c7936) dispatches through it too.kimi-oauth(pluskimi-coderows recorded before the rename) routes to the notional OpenRoutermoonshotai/kimi-k3snapshot ($3/$15/$0.30 per M, statusestimated) only when the SERVED model's vendor is moonshotai.kimi-for-coding*stays unpriced rather than borrowing K3 rates.agent/model_metadata.py:k3-256k= 262,144 (from/coding/v1/models).k3was already 1,048,576.402
We're unable to verify your membership benefitsclassifies as billing, non-retryable, fallback. This is existing behavior; a test now pins it.hermes_cli/provider_catalog.py:oauth_kimiadded to_ACCOUNTS_AUTH_TYPES, so the provider appears on the desktop Accounts tab (catalog-derived card,flow: external,hermes auth add kimi-oauth). The desktop parity contracttest_every_hermes_model_provider_is_configurable_in_desktopfailed on the first push without this change.Prior art
Upstream NousResearch#71039 (webtecnica; twin NousResearch#71038, issue NousResearch#70928) was closed 2026-07-30 as not_planned under the in-tree-provider policy. Its diff adds only a
plugins/model-providers/kimi-oauthProviderProfile(auth_type=oauth_external, baseapi.kimi.com/coding/v1, aliaskimi). It is meant to consume the official kimi CLI's~/.kimi-code/credentials/kimi-code.json, but the diff carries no reader for that file, no refresh, noX-Msh-*headers and no credential-pool wiring; itsweb_server.pyhunk is unrelated isolated-profile code. What this PR does differently:/coding.kimialias, which stays onkimi-coding.Verified
tests/hermes_cli/test_auth_kimi_oauth_provider.py: 19 passed;test_provider_parity.py+test_web_oauth_dispatch.pypass with it (38 total). RED-proof: reverting each of credential_pool / anthropic_adapter / usage_pricing / model_metadata to fork/main fails 2/2/4/1 tests.test_try_gh_cli_token_uses_homebrew_path_when_not_on_path) also fails on clean fork/main, so it is not from this change.verification_uri_complete=https://www.kimi.com/code/authorize_device,expires_in1800,interval5), and the first poll answersauthorization_pending.anthropic_messages,api.kimi.com/coding) -> client (bearer hook,X-Msh-Device-Idmatches) -> livek3completionKIMI-OAUTH-OK, usage 97/53, costestimated$0.001086.Not yet done (needs Ace)
The real device login on the Studio and the forced-expiry proof on the live store come after deploy. Alias
k3 -> kimi-oauth/k3(cpa/kimi-k3stays as the fallback lane) is deferred until the native lane is proven. Keeper + lint are in ANG-Ventures/hermes-home (companion PR).Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.