With KIGI_GRAPH_CONCURRENCY > 1 (default 3, clamp [1,8]) and >=2 Ready nodes, drive_graph — the single dispatch loop shared by setup/advance/resume — runs parallel batches: each node executes as a bounded worker<->verifier subagent loop (KIGI_GRAPH_NODE_ROUNDS, default 3; general-purpose children with the full implementer toolset; worktree isolation on round 1, resume keeps context and worktree on later rounds; NODE_RESULT/NODE_VERDICT terminal contracts parsed fail-closed with fence-stripping and line anchoring). Achieved nodes merge back SEQUENTIALLY via kigi_workspace apply_worktree in Merge mode; a conflict fails the node, block_dependents fires, and surviving chains keep going. gn-final always runs serially on the full goal engine. Concurrency=1 is byte-identical to the serial G0 path; non-git projects degrade to serial. Merge primitive hardened for real use (kigi-workspace): the 3-way apply is now byte-safe (binary files no longer read as UTF-8 and silently deleted) and gains the identical-content rule (ours==theirs => already present, not a conflict) — without it, any dirty file inherited via PreserveWorkingTree false-conflicted every node merge and multi-wave graphs self-poisoned. Adversarial review pass (16 confirmed findings, all fixed): in-session resume demotes orphaned Running nodes instead of wedge-pausing forever after a mid-batch Esc; cancel re-sweeps subagents AFTER the turn abort so workers spawned in the cancel window die too; empty child ids are never adopted as resume targets (no unisolated escape to the shared tree); a successful isolated round returning no worktree fails the node (soft-fallback can no longer put N writers in one tree); main-HEAD movement during a batch aborts merges instead of reverse-applying external commits; failed nodes still charge the token budget; budget trips terminally fail the in-flight node; runaway (>600s) rounds are cancelled by spawn id and retried via resume; worker summaries are marker-sanitized before verifier embedding. Merged worktrees are removed immediately (storage discipline); failed nodes keep theirs for postmortem. Tests: 4922 kigi-shell lib tests green (58 graph-specific), including fan-out proven by a held-reply gate, real-git batch merge with cleanup assertions, budget charging across verdicts, cap trimming, resume-after- cancelled-batch, and backgrounded-round cancel semantics.
Kigi (kigi) 🌘
Kigi is an unofficial Kimi Code CLI community build — a terminal-based AI coding agent re-targeted at the Kimi Code subscription API and the Moonshot open platform, built on the Apache-2.0 sources of xai-org/grok-build.
It runs as a full-screen TUI that understands your codebase, edits files, executes shell commands, searches the web, and manages long-running tasks — interactively, headlessly for scripting/CI, or embedded in editors via the Agent Client Protocol (ACP).
Installation · Providers and API keys · Building from source · Coexistence with the official CLI · License
Installation
Prebuilt single-file binaries for macOS (arm64/x86_64), Linux (arm64/x86_64), and Windows (x86_64) are published on GitHub Releases:
# macOS / Linux
curl -fsSL https://raw.githubusercontent.com/ZacharyZhang-NY/Kigi-CLI/main/install.sh | bash
# Windows PowerShell
irm https://raw.githubusercontent.com/ZacharyZhang-NY/Kigi-CLI/main/install.ps1 | iex
kigi --version # kigi 0.1.1 … unofficial Kimi Code CLI community build
kigi login # sign in with your Kimi Code subscription (device-code flow)
kigi # start the TUI
The installer verifies every download against the release's SHA256SUMS,
installs into ~/.kigi/bin/kigi (%USERPROFILE%\.kigi\bin\kigi.exe on
Windows), and prints the PATH line to add. Later releases arrive through the
built-in self-updater (kigi update, gated by KIGI_AUTO_UPDATE), which
pulls from the same GitHub Releases feed.
Providers and API keys
Kigi talks to a fixed three-platform registry:
| Platform id | Base URL | Auth |
|---|---|---|
kimi-code |
https://api.kimi.com/coding/v1 |
Kimi Code subscription OAuth (kigi login) |
moonshot-cn |
https://api.moonshot.cn/v1 |
Moonshot open-platform API key |
moonshot-ai |
https://api.moonshot.ai/v1 |
Moonshot open-platform API key |
Moonshot API keys come from the environment or ~/.kigi/config.toml
(environment wins; values are never logged):
export KIGI_MOONSHOT_API_KEY=sk-... # applies to both open platforms
export KIGI_MOONSHOT_CN_API_KEY=sk-... # platform-scoped, beats the generic name
export KIGI_MOONSHOT_AI_API_KEY=sk-...
# ~/.kigi/config.toml
[platforms.moonshot-cn]
api_key = "sk-..."
[platforms.moonshot-ai]
api_key = "sk-..."
On login and on startup Kigi syncs each configured platform's model list
from GET {base}/models and shows the merged catalog in the model picker
(catalog keys are {platform_id}/{model_id}). Models that advertise
selectable thinking levels (e.g. K3's low/high/max) expose them in
/model and /effort. If the sync fails, the last cached catalog is used;
with no cache, a small built-in fallback list applies. Model selection
resolves as --model CLI flag > KIGI_DEFAULT_MODEL > [models] default
in config.toml > server-delivered list > built-in fallback.
KIGI_CODE_BASE_URL re-points the subscription platform (useful for
testing); KIGI_MOONSHOT_CN_BASE_URL / KIGI_MOONSHOT_AI_BASE_URL are the
equivalent dev/test overrides for the open platforms.
The web search/fetch tools ride the Kimi Code subscription services and
are present only on OAuth sessions — API-key-only sessions run without
them, matching the official client.
Building from source
rustup toolchain install 1.97.0
cargo build --profile release-dist -p kigi-bin
./target/release-dist/kigi --version
protoc is invoked through the vendored dotslash
launcher at bin/protoc; install dotslash (brew install dotslash or
cargo install dotslash) if it is not already on your PATH.
Coexistence with the official Kimi CLI
Kigi is not affiliated with Moonshot AI or xAI, and it coexists with the
official kimi CLI on the same machine: independent binary name,
independent config directory (~/.kigi), independent keyring credentials
(service kigi), and a KIGI_* environment-variable namespace. Nothing
the official client installs or stores is ever read at runtime or written.
On first launch Kigi offers a one-time, strictly read-only import of
your existing ~/.kimi configuration (MCP servers, custom providers,
default model) via kigi import-kimi — file contents and mtimes under
~/.kimi are left untouched, verified by tests.
Kigi is zero-telemetry: the only outbound connections are the inference/auth APIs you configure, GitHub Releases for updates, and MCP servers you add.
License
Apache-2.0. See LICENSE, NOTICE, and
THIRD-PARTY-NOTICES. Code ported from
openai/codex and sst/opencode is documented in
crates/codegen/kigi-tools/THIRD_PARTY_NOTICES.md.
Kigi is based on Grok Build Open Source; the --version output carries the
attribution.
