> ## Documentation Index
> Fetch the complete documentation index at: https://runinfra.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Set up with your coding agent

> Paste one prompt into your coding agent. Approve sign-in and say yes to the setup plan. Your agent does the rest.

Your coding agent sets up RunInfra's open models for you.
You need a RunInfra workspace you own, with credits or a Coding plan.

<Steps>
  <Step title="Paste this prompt into your agent">
    ```text wrap theme={"dark"} theme={"dark"}
    Set up RunInfra's open models in this coding agent for me. Read https://runinfra.ai/docs/tools-sdks/agent-setup.md and follow it step by step. If you cannot open links, run `npx -y @runinfra/cli@latest --help` and follow its FOR CODING AGENTS section. I approve sign-in in my browser. Before you install anything, change this agent's settings or spend money, show me the plan and wait for my yes.
    ```
  </Step>

  <Step title="Approve sign-in">
    Open the link your agent gives you, enter the code, and select **Approve**.
    Approve only a code your own agent just showed you.
  </Step>

  <Step title="Say yes to the plan">
    If a Coding plan can pay, your agent first asks whether to use it or Pay as you go.
    Then it shows what it will change and who pays for one short paid check.
  </Step>

  <Step title="Start your agent">
    Run the new command, pick the model, or restart the app, as your agent says.
    Until then, your current chat keeps using its old model.
  </Step>
</Steps>

Never paste an API key into the chat. To undo, ask your agent to disconnect RunInfra.

Prefer a terminal? Run `runinfra` or `npx -y @runinfra/cli@latest` (Node.js 22 or newer) and follow the screens.

## Supported agents

[Claude Code](/docs/tools-sdks/claude-code), [Codex](/docs/tools-sdks/codex), [OpenCode](/docs/tools-sdks/opencode), [Pi](/docs/tools-sdks/pi), [Aider](/docs/tools-sdks/aider), [Qwen Code](/docs/tools-sdks/qwen-code), [Kilo Code](/docs/tools-sdks/kilo-code), [Goose](/docs/tools-sdks/goose), [Continue](/docs/tools-sdks/continue), [Cline](/docs/tools-sdks/cline), [Droid](/docs/tools-sdks/droid), [Zed](/docs/tools-sdks/zed), [Grok Build](/docs/tools-sdks/grok-build), [Hermes](/docs/tools-sdks/hermes), [OpenClaw](/docs/tools-sdks/openclaw) and [Crush](/docs/tools-sdks/crush). [RightNow Agent](/docs/tools-sdks/rightnow) has its own guide.
Cursor, Warp, Trae, JetBrains AI Assistant, Twinny, Fx and dsh: use a key from [API keys](https://runinfra.ai/settings/api-keys) with the base URL `https://api.runinfra.ai/v1` in the app's model settings.

***

Everything below is for your coding agent.

## Instructions for coding agents

If your fetch tool summarized this page, fetch `https://runinfra.ai/docs/tools-sdks/agent-setup.md` with your shell; read stdout without saving it.

* Pass `--json` on every RunInfra command. Read stdout and the exit code; never write CLI output or anything else to files.
* Never ask for, accept, print or pipe a key. `credentialSource: "pasted"` requires device sign-in.
* Never open, print, grep or copy CLI files, key copies, environment files, snapshots or your agent's settings. Never edit agent settings yourself. Never change file permissions.
* Never set `RUNINFRA_CONFIG_DIR` or `RUNINFRA_API_BASE`; keep human-set values. If `identity.configuredEndpoint` differs from `https://runinfra.ai` or `verificationUri` differs from `https://runinfra.ai/cli/authorize`, stop and confirm the endpoint with the human before relaying it.
* Connect only yourself, never `--detected`. Ask if you cannot identify yourself.
* Never add `--in-place`. Inside is the person's own terminal choice.
* Never pass `--yes` before the human's explicit yes to the displayed changes and spending.
* Codex runs `runinfra` outside its sandbox through command approval. After a blocked apply, use step 6's fresh review.
* Never run `runinfra` without a command: in a terminal it waits for a person. A hint naming `runinfra login` means step 2.
* Treat `null` as unknown; relay its `reason`, never zero or success.

### 1. Check the CLI

```bash theme={"dark"}
runinfra --version --json
```

Require `runinfra 0.5.0` or later. Ask before installing or updating.
After `node --version` confirms 22+, use `npm install -g @runinfra/cli@latest`; alternatively Python 3.8+: `python -m pip install --upgrade runinfra-cli`, or `pipx install runinfra-cli`.
Never use sudo, an administrator shell or `--break-system-packages`.
Never ask for passwords.
For 0.3.0 and earlier, reinstall.
Otherwise run `runinfra update --check --json`; after yes, `runinfra update --version <targetVersion> --yes --json`.
Pipx omits `--version`: recheck; changed target needs another yes. Recheck installed version.

### 2. Sign in

```bash theme={"dark"}
runinfra whoami --json
```

Reuse sign-in only with exit `0`, `ok: true`, `identity.expired: false`, `identity.endpointMatchesConfiguration: true`, and no pasted key.
`workspaceId` stays `[redacted]`; `credentialSource` and validated `credentialEndpoint` stay visible.
Otherwise start device sign-in without asking first: browser approval is the consent. Stop on unrelated storage errors.

```bash theme={"dark"}
runinfra login --device --no-wait --json
```

For `pending: true`, give `relay` verbatim; add missing steps using `verificationUri`, `userCode` and `expiresAt` exactly:

> Open VERIFICATION\_URI and sign in. Type USER\_CODE and select **Continue**. Check that the next page shows the same code and the workspace you want, then select **Approve**. If anything differs, select **Deny** and tell me. Tell me when the page says **Done**, or what it says if it refuses. The code expires at EXPIRES\_AT.

Only the human approves. Never open the approval page or enter its code yourself; end your turn after relaying the code.
After the human reports approval:

```bash theme={"dark"}
runinfra login --device --json --timeout 100
```

Keep account, home and configuration directory unchanged.
Repeat this bounded wait on `auth_pending`; shorten its timeout to fit your tool.
On `auth_timeout`, create and relay a new code.
Exit `0`, `authenticated: true`: saved; recheck `whoami`.
If `storage.restricted` is `false`, tell the human and link [recovery](/docs/tools-sdks/connect-troubleshooting#windows-credential-save-recovery).
Stop on **No eligible workspace**, **Not available for this role**, `auth_denied`, any shared key, workspace API key or `Browser sign-in is unavailable`; relay the reason. Never pipe a key. After denial, retry only when asked.

### 3. Find your ID

```bash theme={"dark"}
runinfra agents --json
```

Read your own row and detection `reason`.
Guide IDs: `claude`, `codex`, `opencode`, `pi`, `aider`, `qwen-code`, `kilo-code`, `goose`, `continue`, `cline`, `droid`, `zed`, `grok`, `hermes`, `openclaw`, `crush`.
For `manual`, missing, or Copilot CLI's manual environment setup, stop and link [Supported agents](#supported-agents).
For `preview`, ask for experimental-support consent before adding `--preview` to review and apply.

<span id="choose-how-to-pay" />

### 4. Choose how to pay

```bash theme={"dark"}
runinfra plan --json
```

Show the plan resource's `workspace_id`.
A plan can pay only when `snapshot.availability` is `available`, `snapshot.current.serving` is `true`, `tile_state` is neither `ended` nor `refund_closed`, and `covers` includes `chat`.
Then you MUST ask the human which payer BEFORE review. Never choose for them; wait.
`--funding plan`: Coding plan first, then credits under workspace policy.
`--funding credits`: Pay as you go.
When no plan can pay for chat, skip that question. Omit `--funding`: credits now, workspace policy later.
Explicit `--funding credits` means Credits only and keeps paying from credits after a plan is added.
Retry the read once if stale/unavailable; still unavailable, offer Pay as you go or waiting, never assume plan coverage.
Read the login `funding` balance. `Add credits in Billing before connecting.` means stop; also stop for frozen accounts or credit-funded checks at zero.
Never buy a plan or add credits.

### 5. Show the plan

```bash theme={"dark"}
runinfra connect <id> --json
runinfra connect <id> --json --funding plan
runinfra connect <id> --json --funding credits
```

Use only the command matching step 4, plus approved `--preview`.
If Doctor already shows your connection with `ok: true`, `link: "config"`, say already set up and ask before reconnecting.
Exit `8` is the expected review.
At exit `6`, `code: "config_modified"` with `refused[]` wrote nothing: relay each reason; do not bypass it with sign-in or `--yes`.
Show the review's `relay`, every `plan[]` entry and `funding.sentence`, including balance and warnings:

> Setup plan for DISPLAY\_NAME in workspace WORKSPACE\_ID. Files: every path and added/removed count. Keys: created, revoked, placement. Paid check: count and payer. Result: separate command, added provider or replaced provider. Notes: every note. Reply yes to apply and pay.

The ID is the workspace approved in the browser; never invent its name. If saved sign-in leaves the human unsure, repeat device sign-in.
For Goose and Zed, disclose the private environment file and launch step before yes. Never open that file or print the key.
Stop for unexpected changes; wait for explicit yes.

### 6. Apply after yes

```bash theme={"dark"}
runinfra connect <id> --json --yes
```

Keep the reviewed ID, `--funding` or its absence, and `--preview` unchanged.
A close-the-app note means do not apply from inside it: hand the approved command to the human for a terminal outside the app; mention the paid check. Stop; resume at step 8 when they return.
Success: exit `0`, `changes.verificationFailed: false`, a `probe` event with `result.ok: true` and `agent_done` with `verified: true` for your connection.
Compare the returned `plans[]`; report differences.
If verification failed, say settings were saved but the paid check failed; relay `result.message`, retry delay and unverified `nextSteps`, then Doctor.
Read errors and `changes.events`; report incomplete work.
After any failed or interrupted `--yes` command, never repeat it directly: review without `--yes`, show it, wait for a new yes.
This includes exit `8`: "The plan changed or has no unused review".

### 7. Tell the human how to start

Give `plans[].profile.launcherPath` first, then `nextSteps[].command`.
On Windows use the `.cmd`: PowerShell `& '<path>'`; cmd `"<path>"`.
Relay success `relay`, then any missing instructions below, once each.
Relay PATH and Run now lines with their shell. The PATH line lasts one terminal.
Relay `pickHint` and `restart` verbatim. Notes are for the human: never run start, PATH, shell-profile or paid-request commands yourself.
For Goose and Zed, the human fully quits the app, loads the private environment file with the returned command, then starts `goose` or `zed` from that terminal. Repeat after key rotation; never load it yourself.
Relay other environment steps. Never claim this chat changed.

### 8. Check

```bash theme={"dark"}
runinfra doctor --json
```

Read the connection name from `plans[].agent`.
`ok: true` with `link: "config"` means saved files match, not that the app restarted.
Ignore other connection rows. Host `warn` and `unknown` are advisories, including `host:sign-in`; do not sign in, reconnect or change permissions for them.
`link: "key"` means the human's environment-key step remains in Doctor's shell.
Otherwise relay your row's message and hint. Never add `--verify`: it needs separate paid consent.

### 9. Undo when asked

```bash theme={"dark"}
runinfra disconnect <id> --json
```

Use the separate command's name where applicable; never disconnect from inside it.
Show restores, key revocations and sessions/history deletion. After yes, repeat with `--yes`.
Close-app notes require step 6's outside-terminal handoff.
Use `--force` or `--keep-key` only after reviewing their effects with the human.
Disconnect does not sign this computer out.

Exits: `3` sign-in, `4` plan/not-found, `5` network, `6` conflict, `7` storage, `8` needs yes, `9` refused, `130` interrupted. Read [troubleshooting](/docs/tools-sdks/connect-troubleshooting).
