Skip to content
This repository was archived by the owner on Aug 25, 2026. It is now read-only.

feat: unify host identity across OAuth, telemetry, and kap-server (upstream port) - #13

Merged
YaseenHQ merged 1 commit into
mainfrom
upstream-port/host-identity
Aug 8, 2026
Merged

YaseenHQ merged 1 commit into
mainfrom
upstream-port/host-identity

Conversation

@YaseenHQ

@YaseenHQ YaseenHQ commented Aug 3, 2026

Copy link
Copy Markdown
Owner

Related Issue

Upstream port batch 6 of 6 (final). Ports upstream #2382 — unifying the host identity so every surface (OAuth headers, telemetry, kap-server) derives from a single KimiHostIdentity instead of ad-hoc clientVersion scalars.

What changed

  • Replaces the flat clientVersion bootstrap field with a required clientIdentity (KimiHostIdentity).
  • Renames userAgentProduct → productName on the transport identity; X-Msh-Platform becomes an explicit per-host field.
  • Threads identity through managed-auth facades, telemetry cloud appender, and kap-server (derives outbound headers from hostIdentity).
  • Complements the Echadron rebrand: the fork's rebrand was a naming/env-aliasing layer; this is the architectural plumbing that lets Echadron declare its own platform identity end-to-end.

Conflict resolution (13 files)

  • Import merges (start.ts, run.ts): kept the fork's applyEchadronEnvironmentAliases AND added upstream's createKimiDefaultHeaders/KimiHostIdentity.
  • productName values: took upstream's field name, kept Echadron values (echadron-cli, echadron-vscode) where the fork had them.
  • productName → displayName: on PromptIdentityOverrides (prompt-rendering overrides), upstream renamed to displayName; fixed the run-v2-print.ts call site that auto-merged without the rename.
  • Deleted-by-us files (sdk-rpc-client-v2.ts, global search): git rm — the fork deliberately removed these.
  • Telemetry test mock: updated the oauth mock to use importOriginal spread so KIMI_CODE_PLATFORM resolves.

Verification

  • Typecheck clean: kap-server, agent-core-v2, node-sdk, echadron
  • Tests pass: kap-server 821, agent-core-v2 4212, node-sdk 239, echadron 2438

Checklist

  • Tests pass on all affected packages.

…MoonshotAI#2382)

* refactor(oauth): make X-Msh-Platform an explicit host identity field

X-Msh-Platform was hardcoded to kimi_code_cli in createKimiDeviceHeaders,
so non-CLI hosts could not state their own platform and the desktop had
to patch the header after the fact. KimiHostIdentity now carries a
required platform (every host declares its own value; the CLI constant
stays the fallback only for direct createKimiDeviceHeaders callers), and
userAgentProduct is renamed to productName so the transport identity
uses one name everywhere.

All in-repo identity constructions pass platform explicitly; the wire
value for CLI and VS Code hosts is unchanged (kimi_code_cli).

* feat(agent-core-v2): carry the host identity in the bootstrap snapshot

Replace the flat clientVersion field with a required clientIdentity
(KimiHostIdentity) so every consumer reads the same host identity
object: OAuthToolkitService now passes it to the OAuth toolkit, which
means the OAuth device-flow endpoints (device authorization, token
polling, refresh) on the kap-server path finally send the full X-Msh-*
device headers instead of none, and the telemetry cloud appender reads
client_version from the same source. A built-in CLI fallback keeps bare
bootstrap() calls in tests working; composition roots must pass their
own identity.

The session export manifest grows an optional desktopVersion field
(payload plumbed through; filled by kap-server in a follow-up).

* feat(agent-core): thread the host identity into the managed auth facades

The v1 managed auth facade constructed its OAuth toolkit without an
identity, so token refreshes from inside the core went out without any
X-Msh-* device headers. createManagedAuthFacade now takes an optional
KimiHostIdentity and every call site supplies one:
CoreProcessService._defaultOAuthTokenResolver forwards the core
process's options.identity (the same source _defaultKimiRequestHeaders
uses), and the DI-held services (oauth / auth summary / model catalog)
read it from a new optional identity field on IEnvironmentService. The
library-level "no identity, no device headers" contract is unchanged.

* feat(kap-server)!: require the host identity and derive request headers from it

ServerStartOptions.hostIdentity is now a required ServerHostIdentity
(KimiHostIdentity + optional prompt display fields), replacing both the
old optional HostIdentityOverrides (renamed to PromptIdentityOverrides,
its productName field now displayName) and the version option (renamed
to serverVersion — it is the engine version reported as server_version,
while the host product version travels in hostIdentity.version).

The server now feeds bootstrap's clientIdentity from hostIdentity and
derives the default outbound headers (User-Agent + X-Msh-*) from it via
createKimiDefaultHeaders, so kap-server-hosted OAuth flows and model /
WebSearch requests carry the real host identity instead of a hardcoded
kimi-code-cli fallback UA. Explicit header seeds still win as an escape
hatch.

Session export manifests record the host product version: kimiCodeVersion
now carries hostIdentity.version (the engine version no longer appears),
and desktop exports (desktop: true) are additionally stamped with a
desktopVersion field. The instance registry keeps its host_version wire
field for compatibility (kimi-inspect reads it); only the in-memory name
changed to serverVersion.

* feat(cli): wire the CLI host identity into the kimi web server

kimi web now passes createKimiCodeHostIdentity(version) as the server's
hostIdentity, so web-UI OAuth flows and the engine's outbound requests
carry the explicit CLI identity (productName + version + platform). The
explicit hostRequestHeadersSeed is dropped — kap-server derives the same
headers from hostIdentity — and buildKimiDefaultHeaders goes away with
its only consumer.

* test(klient): drop clientVersion from the bootstrap contract parity list

* chore: add changesets for the host identity unification

* feat(cli): tag kimi web requests with a (web) User-Agent suffix

kimi web shares the CLI product token and platform, so its outbound
requests were indistinguishable from direct CLI runs upstream. Its host
identity now carries userAgentSuffix 'web', putting web-UI traffic at
kimi-code-cli/<version> (web) while X-Msh-Platform stays kimi_code_cli.

* fix(klient): keep the env() clientVersion wire field after the bootstrap identity switch

The bootstrap snapshot replaced the flat clientVersion scalar with
clientIdentity, which broke klient's env() fan-out (RPCError: method not
found). The wire surface keeps clientVersion — now sourced from
clientIdentity.version — and bootstrapService gains a clientIdentity
read (registered in envContract with an object schema) for consumers
that want the full identity.

* feat(oauth): send the product User-Agent on OAuth requests

The OAuth endpoints used to receive only the X-Msh-* device headers
(undici's default UA otherwise), which left the OAuth host unable to
distinguish runtime surfaces — notably kimi web, whose platform matches
the CLI and whose only distinguishing mark is the (web) UA suffix. The
toolkit now feeds the full identity headers (User-Agent + X-Msh-*) into
every device authorization, token polling, and refresh request; the
request-header type widens from DeviceHeaders to OAuthRequestHeaders.

* feat(vscode): report kimi_code_vscode as the extension's platform

The VS Code extension inherited the CLI's hardcoded X-Msh-Platform value;
with platform now an explicit identity field it declares its own, so the
managed endpoints and OAuth host can tell extension traffic apart from
CLI runs.

* refactor(agent-core-v2)!: require the client identity at the composition root

The bootstrap fallback identity fabricated a kimi-code-cli/unknown host
for any caller that forgot to pass one — the same silent-misreport
pattern this series set out to remove, and it made "required" a lie.
BootstrapInput.clientIdentity is now required, so a missing identity
fails at compile time instead of being papered over. Test and example
callers pass a shared fixture (klient examples and test engines get one
each); the node-sdk v2 client asserts its host identity with the oauth
helper. Also folds DeviceHeaders from an interface into a type alias so
it stays assignable to the widened OAuthRequestHeaders record.

* feat(oauth)!: require and validate the platform in device headers

Drops the quiet CLI fallback in createKimiDeviceHeaders (the same
silent-misreport pattern removed from the bootstrap identity): platform
is now a required option, validated with the same required-ASCII rule as
the version — empty or all-non-ASCII values throw instead of emitting a
blank X-Msh-Platform, and header-unsafe characters are stripped rather
than sent raw.

* fix(node-sdk): seed the host request headers on the v2 client path

The interactive v2 engine path (experimental flag) bootstrapped without
a hostRequestHeaders seed, so managed vendor calls went out with the
SDK's default User-Agent (OpenAI/JS) and no X-Msh-* at all — v1 passes
the full identity headers on the same requests. The v2 client now seeds
the headers from its asserted host identity, and a test pins the seed.

* chore: simplify the CLI changeset wording
@coderabbitai

coderabbitai Bot commented Aug 3, 2026

Copy link
Copy Markdown

Important

Review skipped

Too many files!

This PR contains 114 files, which is 14 over the limit of 100.

To get a review, narrow the scope:
• coderabbit review --committed # exclude uncommitted changes
• coderabbit review --dir # limit to a subdirectory
• coderabbit review --base # compare against a closer base

Upgrade to a paid plan to raise the limit.

This review couldn't start because sufficient usage credits or metered capacity aren't available. Add credits or update usage-based reviews in the billing tab, then retry.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 04097dd4-8957-4f5c-bf4b-8845517d878b

📥 Commits

Reviewing files that changed from the base of the PR and between a239aa0 and f2830f8.

📒 Files selected for processing (114)
  • .changeset/agent-core-auth-identity.md
  • .changeset/cli-web-login-identity.md
  • .changeset/kap-server-host-identity.md
  • .changeset/oauth-host-identity-platform.md
  • .changeset/sdk-host-identity-rename.md
  • .changeset/v2-bootstrap-client-identity.md
  • apps/kimi-code/src/cli/sub/web/run.ts
  • apps/kimi-code/src/cli/v2/run-v2-print.ts
  • apps/kimi-code/src/cli/version.ts
  • apps/kimi-code/src/constant/app.ts
  • apps/kimi-code/test/cli/run-shell.test.ts
  • apps/kimi-code/test/cli/telemetry.test.ts
  • apps/kimi-code/test/cli/v2-run-print.test.ts
  • apps/kimi-code/test/cli/version.test.ts
  • apps/vscode/docs/node-sdk-migration.md
  • apps/vscode/src/runtime/echadron-runtime.ts
  • apps/vscode/test/kimi-harness.integration.test.ts
  • apps/vscode/test/replay-resume.integration.test.ts
  • packages/agent-core-v2/src/app/auth/authService.ts
  • packages/agent-core-v2/src/app/bootstrap/bootstrap.ts
  • packages/agent-core-v2/src/app/bootstrap/bootstrapService.ts
  • packages/agent-core-v2/src/app/hostIdentity/hostIdentity.ts
  • packages/agent-core-v2/src/app/sessionExport/manifest.ts
  • packages/agent-core-v2/src/app/sessionExport/sessionExport.ts
  • packages/agent-core-v2/src/app/sessionExport/sessionExportService.ts
  • packages/agent-core-v2/src/app/telemetry/cloudAppender.ts
  • packages/agent-core-v2/test/app/bootstrap/bootstrapService.test.ts
  • packages/agent-core-v2/test/app/bootstrap/stubs.ts
  • packages/agent-core-v2/test/app/telemetry/cloudAppender.test.ts
  • packages/agent-core-v2/test/harness/agent.ts
  • packages/agent-core/src/services/auth/managedAuth.ts
  • packages/agent-core/src/services/authSummary/authSummaryService.ts
  • packages/agent-core/src/services/coreProcess/coreProcessService.ts
  • packages/agent-core/src/services/environment/environment.ts
  • packages/agent-core/src/services/modelCatalog/modelCatalogService.ts
  • packages/agent-core/src/services/oauth/oauthService.ts
  • packages/agent-core/test/services/coreProcessService.test.ts
  • packages/kap-server/src/index.ts
  • packages/kap-server/src/instanceRegistry.ts
  • packages/kap-server/src/routes/registerApiV1Routes.ts
  • packages/kap-server/src/routes/sessionExport.ts
  • packages/kap-server/src/start.ts
  • packages/kap-server/test/apiSurface.snapshot.test.ts
  • packages/kap-server/test/approvals.test.ts
  • packages/kap-server/test/auth.test.ts
  • packages/kap-server/test/authMiddleware.test.ts
  • packages/kap-server/test/authWiring.e2e.test.ts
  • packages/kap-server/test/boot.test.ts
  • packages/kap-server/test/config.test.ts
  • packages/kap-server/test/connections.test.ts
  • packages/kap-server/test/debugNonloopback.e2e.test.ts
  • packages/kap-server/test/disableAuth.e2e.test.ts
  • packages/kap-server/test/files.test.ts
  • packages/kap-server/test/fs-watch.e2e.test.ts
  • packages/kap-server/test/fs.test.ts
  • packages/kap-server/test/guiStore.test.ts
  • packages/kap-server/test/helpers/hostIdentity.ts
  • packages/kap-server/test/hostExposure.e2e.test.ts
  • packages/kap-server/test/hostnames.test.ts
  • packages/kap-server/test/instanceRegistry.test.ts
  • packages/kap-server/test/messages.test.ts
  • packages/kap-server/test/modelCatalog.test.ts
  • packages/kap-server/test/modelCatalogCatalog.test.ts
  • packages/kap-server/test/modelCatalogProviderWrite.test.ts
  • packages/kap-server/test/oauthUsage.test.ts
  • packages/kap-server/test/openapi.test.ts
  • packages/kap-server/test/prompts.test.ts
  • packages/kap-server/test/questions.test.ts
  • packages/kap-server/test/requestLogging.test.ts
  • packages/kap-server/test/rpc.test.ts
  • packages/kap-server/test/securityExposure.test.ts
  • packages/kap-server/test/sessions.test.ts
  • packages/kap-server/test/skills.test.ts
  • packages/kap-server/test/snapshot.test.ts
  • packages/kap-server/test/tasks.test.ts
  • packages/kap-server/test/telemetry.test.ts
  • packages/kap-server/test/terminals.test.ts
  • packages/kap-server/test/tools.test.ts
  • packages/kap-server/test/transcript.test.ts
  • packages/kap-server/test/workspaceFs.test.ts
  • packages/kap-server/test/workspaces.test.ts
  • packages/kap-server/test/wsBearerProtocol.test.ts
  • packages/kap-server/test/wsHostOrigin.test.ts
  • packages/kap-server/test/wsUpgradeAuth.test.ts
  • packages/kap-server/test/wsV1Resync.test.ts
  • packages/klient/examples/basic.ts
  • packages/klient/examples/context-usage.ts
  • packages/klient/examples/identity.ts
  • packages/klient/examples/kimi-select-tools.ts
  • packages/klient/examples/kosong-config-stress.ts
  • packages/klient/examples/model-requester-boundary.ts
  • packages/klient/examples/smoke.ts
  • packages/klient/src/contract/global/env.ts
  • packages/klient/src/core/facade/global.ts
  • packages/klient/test/contract-parity.ts
  • packages/klient/test/e2e/invalid-input-matrix.test.ts
  • packages/klient/test/facade.test.ts
  • packages/klient/test/helpers/engine.ts
  • packages/node-sdk/examples/kimi-harness-log-marker.ts
  • packages/node-sdk/examples/kimi-harness-logging-smoke.ts
  • packages/node-sdk/examples/runtime-smoke-helpers.ts
  • packages/node-sdk/examples/t8-race-create-single.ts
  • packages/node-sdk/examples/t8-race-create.ts
  • packages/node-sdk/src/kimi-code-model-provider.ts
  • packages/node-sdk/src/kimi-harness.ts
  • packages/node-sdk/test/test-identity.ts
  • packages/oauth/examples/kimi-oauth-smoke.ts
  • packages/oauth/src/identity.ts
  • packages/oauth/src/oauth-manager.ts
  • packages/oauth/src/oauth.ts
  • packages/oauth/src/toolkit.ts
  • packages/oauth/src/types.ts
  • packages/oauth/test/identity.test.ts
  • packages/oauth/test/toolkit.test.ts

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@YaseenHQ
YaseenHQ merged commit 5786f0c into main Aug 8, 2026
15 checks passed
@github-actions github-actions Bot mentioned this pull request Aug 11, 2026
@YaseenHQ
YaseenHQ deleted the upstream-port/host-identity branch August 24, 2026 23:05
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants