ZacharyZhang-NY ebf11057f8 feat(providers): add xAI (Grok) + migrate house BYOK env to KIGI_API_KEY
13th provider (16th registry variant). Also reconciles a naming collision
the matrix flagged: this fork is house-branded "xai" (cf. xai.dev metadata,
KIGI_CODE_XAI_API_KEY legacy env), so XAI_API_KEY + method xai.api_key were
the GENERIC house BYOK, not x.ai/Grok. The provider table wants xai/XAI_API_KEY
for Grok.

Resolution (user-approved): XAI_API_KEY now keys the x.ai/Grok provider; the
house BYOK primary env moves to KIGI_API_KEY, keeping XAI_API_KEY and
KIGI_CODE_XAI_API_KEY as back-compat fallbacks (read_xai_api_key_env checks
KIGI_API_KEY first). The xai.api_key method id is unchanged (persisted-session
compat); the platform method id is the bare "xai", distinct from it.

xAI spec: api.x.ai/v1, Bearer, OpenAI listing + ChatCompletions, Passthrough
(docs confirm stream_options.include_usage accepted). /v1/models is minimal
(ids only) and requires auth, so it doubles as the key validator (401 on bad
key, no override) and metadata comes from models.dev enrichment. Live ids
match the models.dev "xai" keys byte-for-byte, so restrict_to_enriched keeps
the 5 tool-calling chat models (grok-4.5/4.3/4.20-0309-*/build-0.1) and drops
the grok-imagine-* generators + the non-tool multi-agent model. Snapshot
regenerated to include the xai provider (was stale; gen script already listed
it in TARGETS).

Env migration is comprehensive to avoid keying the xai platform (which would
trigger a live api.x.ai fetch) or leaving house-key reads stranded: routed
the trace CLI resolver + acp_agent/auth.json bridge + paste-key ext handler
through the new primary; moved all leader/pager/e2e harness setters to
KIGI_API_KEY; made every house-key isolation test unset KIGI_API_KEY too;
updated user-facing hints to name KIGI_API_KEY.

Tests: e2e proves enrichment-supplied context (wire carries none), non-vacuous
tool_call restriction, bare-id round-trip under xai/, Passthrough; validation
tests hit /models (401 reject, 200 accept); house_env_var_takes_precedence_over_xai
pins the new precedence. Registry at 16; picker 17 rows; 4 auth arrays + xai.

Review (16 findings, all fixed): caught a missed else-branch env clear in the
paste-key handler (would leak the house key past a clear) and a non-hermetic
credential-priority test; both fixed.
2026-07-21 16:23:08 -04:00
2026-07-20 20:46:35 -04:00

Kigi (kigi) 🌘

🕸️ The world's first CLI with built-in Graph Engineering

/graph turns one objective into a dependency graph of autonomous, self-verifying agent loops — planned, parallelized, adversarially verified, and merged back, end to end.

Kigi is an unofficial Kimi Code CLI community build — a terminal-based AI coding agent re-targeted at the Kimi Code subscription API and the Moonshot open platform, built on the Apache-2.0 sources of xai-org/grok-build.

It runs as a full-screen TUI that understands your codebase, edits files, executes shell commands, searches the web, and manages long-running tasks — interactively, headlessly for scripting/CI, or embedded in editors via the Agent Client Protocol (ACP).

Installation · Graph engineering · Providers and API keys · Building from source · Coexistence with the official CLI · License

Kigi demo

Full-quality recording (mp4)


Installation

Prebuilt single-file binaries for macOS (arm64/x86_64), Linux (arm64/x86_64), and Windows (x86_64) are published on GitHub Releases:

# macOS / Linux
curl -fsSL https://raw.githubusercontent.com/ZacharyZhang-NY/Kigi-CLI/main/install.sh | bash
# Windows PowerShell
irm https://raw.githubusercontent.com/ZacharyZhang-NY/Kigi-CLI/main/install.ps1 | iex
kigi --version   # kigi 0.1.1 … unofficial Kimi Code CLI community build
kigi login       # sign in with your Kimi Code subscription (device-code flow)
kigi             # start the TUI

The installer verifies every download against the release's SHA256SUMS, installs into ~/.kigi/bin/kigi (%USERPROFILE%\.kigi\bin\kigi.exe on Windows), persists the PATH line for you, and enables graph engineering by default (KIGI_GRAPH=1; see Graph engineering to disable). Later releases arrive through the built-in self-updater (kigi update, gated by KIGI_AUTO_UPDATE), which pulls from the same GitHub Releases feed.

Graph engineering

Kigi is the first CLI to ship graph engineering as a first-class command: where a loop drives one agent, a graph is the programmable organization connecting many.

/graph <objective> [--budget <tokens>]   # decompose + run fully autonomously
/graph status                            # node tree, budget, current work
/graph show                              # box-drawing DAG view
/graph pause | resume [--budget <n>]     # halt / continue (budget top-up)
/graph clear                             # abandon the graph

One /graph <objective> runs the whole closed loop: a planner subagent decomposes the objective into a validated dependency DAG; independent nodes fan out as parallel workers in isolated git worktrees, each gated by an adversarial verifier and merged back three-way; out-of-scope discoveries (DISCOVERED:) replan the graph append-only; a topology optimizer prunes false dependencies at plan boundaries; and a terminal verification node re-checks the whole objective before the graph completes. State follows your repo in .kigi/graph.jsonl, so a fresh session — or a teammate — can /graph resume where you left off.

The installer enables it by default. To disable:

# macOS / Linux
echo 'export KIGI_GRAPH=0' >> ~/.zshrc   # or ~/.bashrc / ~/.bash_profile
# Windows PowerShell
[Environment]::SetEnvironmentVariable('KIGI_GRAPH','0','User')

(One-off instead: KIGI_GRAPH=0 kigi.) Tuning knobs: KIGI_GRAPH_CONCURRENCY (parallel nodes, default 3), KIGI_GRAPH_NODE_ROUNDS (worker↔verifier rounds per node, default 3), KIGI_GRAPH_REPLAN_CAP (replan passes, default 3), KIGI_GRAPH_OPTIMIZER=0 (disable the optimizer pass).

Providers and API keys

Kigi talks to a fixed three-platform registry:

Platform id Base URL Auth
kimi-code https://api.kimi.com/coding/v1 Kimi Code subscription OAuth (kigi login)
moonshot-cn https://api.moonshot.cn/v1 Moonshot open-platform API key
moonshot-ai https://api.moonshot.ai/v1 Moonshot open-platform API key

Moonshot API keys come from the environment or ~/.kigi/config.toml (environment wins; values are never logged):

export KIGI_MOONSHOT_API_KEY=sk-...     # applies to both open platforms
export KIGI_MOONSHOT_CN_API_KEY=sk-...  # platform-scoped, beats the generic name
export KIGI_MOONSHOT_AI_API_KEY=sk-...
# ~/.kigi/config.toml
[platforms.moonshot-cn]
api_key = "sk-..."

[platforms.moonshot-ai]
api_key = "sk-..."

On login and on startup Kigi syncs each configured platform's model list from GET {base}/models and shows the merged catalog in the model picker (catalog keys are {platform_id}/{model_id}). Models that advertise selectable thinking levels (e.g. K3's low/high/max) expose them in /model and /effort. If the sync fails, the last cached catalog is used; with no cache, a small built-in fallback list applies. Model selection resolves as --model CLI flag > KIGI_DEFAULT_MODEL > [models] default in config.toml > server-delivered list > built-in fallback.

KIGI_CODE_BASE_URL re-points the subscription platform (useful for testing); KIGI_MOONSHOT_CN_BASE_URL / KIGI_MOONSHOT_AI_BASE_URL are the equivalent dev/test overrides for the open platforms.

The web search/fetch tools ride the Kimi Code subscription services and are present only on OAuth sessions — API-key-only sessions run without them, matching the official client.

Building from source

rustup toolchain install 1.97.0
cargo build --profile release-dist -p kigi-bin
./target/release-dist/kigi --version

protoc is invoked through the vendored dotslash launcher at bin/protoc; install dotslash (brew install dotslash or cargo install dotslash) if it is not already on your PATH.

Coexistence with the official Kimi CLI

Kigi is not affiliated with Moonshot AI or xAI, and it coexists with the official kimi CLI on the same machine: independent binary name, independent config directory (~/.kigi), independent keyring credentials (service kigi), and a KIGI_* environment-variable namespace. Nothing the official client installs or stores is ever read at runtime or written. On first launch Kigi offers a one-time, strictly read-only import of your existing ~/.kimi configuration (MCP servers, custom providers, default model) via kigi import-kimi — file contents and mtimes under ~/.kimi are left untouched, verified by tests.

Kigi is zero-telemetry: the only outbound connections are the inference/auth APIs you configure, GitHub Releases for updates, and MCP servers you add.

License

Apache-2.0. See LICENSE, NOTICE, and THIRD-PARTY-NOTICES. Code ported from openai/codex and sst/opencode is documented in crates/codegen/kigi-tools/THIRD_PARTY_NOTICES.md. Kigi is based on Grok Build Open Source; the --version output carries the attribution.

S
Description
Migrated from GitHub
Readme Apache-2.0
30 MiB
Languages
Rust 99.7%
Python 0.3%