Skip to content

feat(auth): add native kimi-oauth provider using Kimi Code CLI OAuth tokens (#70928) - #71039

Closed
webtecnica wants to merge 2 commits into
NousResearch:mainfrom
webtecnica:feat/kimi-oauth-provider
Closed

webtecnica wants to merge 2 commits into
NousResearch:mainfrom
webtecnica:feat/kimi-oauth-provider

Conversation

@webtecnica

Copy link
Copy Markdown

Implements #70928

Adds kimi-oauth provider following the same pattern as qwen-oauth and minimax-oauth. Authenticates through Kimi Code CLI's OAuth token file (~/.kimi-code/credentials/kimi-code.json).

Files: plugins/model-providers/kimi-oauth/, hermes_cli/auth.py, hermes_cli/providers.py, agent/credential_pool.py, + more

@alt-glitch alt-glitch added type/docs Documentation improvements comp/cli CLI entry point, hermes_cli/, setup wizard comp/plugins Plugin system and bundled plugins comp/tui Terminal UI (ui-tui/ + tui_gateway/) platform/telegram Telegram bot adapter provider/kimi Kimi / Moonshot area/auth Authentication, OAuth, credential pools P3 Low — cosmetic, nice to have duplicate This issue or pull request already exists labels Jul 24, 2026
@alt-glitch

Copy link
Copy Markdown

This was generated by AI during triage.

Duplicate of #71038: both PRs currently have the identical live head and identical diff. This branch also does not contain the complete Kimi OAuth implementation described in this PR.

…de (NousResearch#70867)

When the dashboard is launched with --isolated, the API must reject
?profile= requests targeting any profile other than the one the server
is scoped to. Without this guard, a user on an isolated dashboard could
read/write another profile's config, sessions, skills, and env vars
simply by passing ?profile=<other>.

Changes:
- Add _check_isolated_profile_access() helper that compares the
  requested profile directory against the server's own HERMES_HOME
- Wire the check into _profile_scope(), _config_profile_scope(), and
  _open_session_db_for_profile() — the three gateways through which all
  profile-scoped API requests pass
- Add 'isolated' parameter to start_server() and store it on app.state
- Forward the CLI --isolated flag from cmd_dashboard to start_server()

Closes: NousResearch#70867
@webtecnica
webtecnica force-pushed the feat/kimi-oauth-provider branch from 3698de4 to b49c1e0 Compare July 26, 2026 23:35
@teknium1

Copy link
Copy Markdown
Collaborator

Thanks for the Kimi OAuth investigation and for using the existing model-provider shape.

This automated hermes-sweeper review is closing this under the standing in-tree provider integration policy:

  • AGENTS.md:797-810 requires new third-party product integrations under plugins/ to ship as standalone plugin repositories, installable through ~/.hermes/plugins/ or a pip entry point.
  • The PR adds plugins/model-providers/kimi-oauth/__init__.py, so it falls under that policy (in-tree-provider-integration).
  • As noted in the prior triage comment, this branch is also a duplicate of fix(docs): update Telegram docs after .env hardening for allowed users (#70879) #71038 and does not include the credential loading/runtime wiring needed for the stated Kimi Code CLI OAuth flow; current provider-specific credential seeding is in agent/credential_pool.py:2363-2425.

Please publish the integration as a standalone plugin repository using the existing model-provider discovery surface; it can then be promoted in #plugins-skills-and-skins.


Closed as not-planned per standing maintainer policy (in-tree-provider-integration). This is a design-direction decision, not a code-quality judgment — see the Contribution Rubric in AGENTS.md for what the project is looking for. If you believe this policy was misapplied to your change, comment here and a maintainer will take a look.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/auth Authentication, OAuth, credential pools comp/cli CLI entry point, hermes_cli/, setup wizard comp/plugins Plugin system and bundled plugins comp/tui Terminal UI (ui-tui/ + tui_gateway/) duplicate This issue or pull request already exists P3 Low — cosmetic, nice to have platform/telegram Telegram bot adapter provider/kimi Kimi / Moonshot sweeper:not-planned Sweeper: closed per standing maintainer policy (design direction) type/docs Documentation improvements

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants