{"record":{"id":"e68def2c4712ad7f","repo":"Hmbown/CodeWhale","slug":"kimi-cli-credentials-are-never-imported-configure-a-kimi-api","errorCode":null,"errorMessage":"Kimi CLI credentials are never imported; configure a Kimi API key instead","messagePattern":"Kimi CLI credentials are never imported; configure a Kimi API key instead","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"crates/tui/src/config.rs","lineNumber":12813,"sourceCode":"    .read_grant(consent_provider, source, path)?;\n    match source {\n        codewhale_config::ExternalCredentialSource::CodexCli => {\n            crate::oauth::get_credentials(&grant).map(|_| ())\n        }\n        codewhale_config::ExternalCredentialSource::GrokCli => {\n            crate::oauth::validate_grok_external_credentials(&grant)\n        }\n        codewhale_config::ExternalCredentialSource::DshCli => {\n            crate::dsh_credentials::deepseek_api_key_from_grant(&grant)?\n                .map(|_| ())\n                .context(\"the DeepSeek Harness credentials file holds no DEEPSEEK_API_KEY\")\n        }\n        // Retired: the reader is gone, so a legacy consent record validates\n        // to nothing rather than resolving a route (PRD §4.4 PROD-002).\n        codewhale_config::ExternalCredentialSource::AgyCli => {\n            anyhow::bail!(codewhale_config::LEGACY_ANTIGRAVITY_TOMBSTONE_MESSAGE)\n        }\n        codewhale_config::ExternalCredentialSource::KimiCodeCli => anyhow::bail!(\n            \"Kimi CLI credentials are never imported; configure a Kimi API key instead\"\n        ),\n    }\n}\n\n/// Persist an explicitly confirmed read-only external credential grant and\n/// update the live mirror only after the comment-preserving disk mutation\n/// succeeds.\n///\n/// Order is load-bearing (#5772): the caller has already shown the\n/// confirmation disclosure, this function then reads and validates the exact\n/// consented file, and only a usable credential is allowed to produce a\n/// persisted consent record.\npub(crate) fn persist_external_credential_consent_for_at(\n    config_path: Option<&Path>,\n    live_config: &mut Config,\n    provider: ApiProvider,\n    consent_provider: codewhale_config::ProviderKind,","sourceCodeStart":12795,"sourceCodeEnd":12831,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/73e0f67d83c59909b571efdfc88c4bc28c309cb1/crates/tui/src/config.rs#L12795-L12831","documentation":"The external-credential resolver never imports Kimi CLI credentials: `KimiCodeCli` is accepted by the enum but its match arm immediately fails with this error. Users must configure a Kimi API key directly rather than importing credentials from the Kimi CLI.","triggerScenarios":"Resolving external credentials where the stored source is `ExternalCredentialSource::KimiCodeCli`, i.e. a consent record or config pointing at the Kimi CLI as a credential source.","commonSituations":"Config that names the Kimi CLI as an external credential owner; copying an external-credentials block from another provider (e.g. Codex CLI) to Kimi.","solutions":["Configure a Kimi API key directly (provider config key / `codewhale auth save --provider kimi ...`)","Remove the Kimi CLI entry from `external_credentials` in your config"],"exampleFix":"// before\n[external_credentials]\nprovider = \"kimi\"\nsource = \"kimi-cli\"\n// after\n# delete block; save a Kimi API key instead\ncodewhale auth save --provider kimi --api-key <key>","handlingStrategy":"validation","validationCode":"if source == ExternalCredentialSource::KimiCodeCli {\n    eprintln!(\"configure a Kimi API key directly instead of CLI import\");\n}","typeGuard":"fn kimi_uses_api_key(p: ApiProvider) -> bool { p == ApiProvider::Kimi }","tryCatchPattern":"match resolve_result {\n    Err(e) if e.to_string().contains(\"Kimi CLI credentials\") => configure_kimi_api_key(),\n    other => other?,\n}","preventionTips":["Never list kimi-cli as an external credential source","Always save Kimi auth as a direct API key","Audit external_credentials blocks copied from other providers"],"tags":["provider","authentication","kimi","unsupported"],"backgroundTag":"unsupported-operation","analyzedSha":"73e0f67d83c59909b571efdfc88c4bc28c309cb1","analyzedAt":"2026-09-22T01:30:00.501Z","contentChangedAt":"2026-09-22T01:30:00.501Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}