Skip to main content
Your coding agent sets up RunInfra’s open models for you. You need a RunInfra workspace you own, with credits or a Coding plan.
1

Paste this prompt into your agent

2

Approve sign-in

Open the link your agent gives you, enter the code, and select Approve. Approve only a code your own agent just showed you.
3

Say yes to the plan

If a Coding plan can pay, your agent first asks whether to use it or Pay as you go. Then it shows what it will change and who pays for one short paid check.
4

Start your agent

Run the new command, pick the model, or restart the app, as your agent says. Until then, your current chat keeps using its old model.
Never paste an API key into the chat. To undo, ask your agent to disconnect RunInfra. Prefer a terminal? Run runinfra or npx -y @runinfra/cli@latest (Node.js 22 or newer) and follow the screens.

Supported agents

Claude Code, Codex, OpenCode, Pi, Aider, Qwen Code, Kilo Code, Goose, Continue, Cline, Droid, Zed, Grok Build, Hermes, OpenClaw and Crush. RightNow Agent has its own guide. Cursor, Warp, Trae, JetBrains AI Assistant, Twinny, Fx and dsh: use a key from API keys with the base URL https://api.runinfra.ai/v1 in the app’s model settings.
Everything below is for your coding agent.

Instructions for coding agents

If your fetch tool summarized this page, fetch https://runinfra.ai/docs/tools-sdks/agent-setup.md with your shell; read stdout without saving it.
  • Pass --json on every RunInfra command. Read stdout and the exit code; never write CLI output or anything else to files.
  • Never ask for, accept, print or pipe a key. credentialSource: "pasted" requires device sign-in.
  • Never open, print, grep or copy CLI files, key copies, environment files, snapshots or your agent’s settings. Never edit agent settings yourself. Never change file permissions.
  • Never set RUNINFRA_CONFIG_DIR or RUNINFRA_API_BASE; keep human-set values. If identity.configuredEndpoint differs from https://runinfra.ai or verificationUri differs from https://runinfra.ai/cli/authorize, stop and confirm the endpoint with the human before relaying it.
  • Connect only yourself, never --detected. Ask if you cannot identify yourself.
  • Never add --in-place. Inside is the person’s own terminal choice.
  • Never pass --yes before the human’s explicit yes to the displayed changes and spending.
  • Codex runs runinfra outside its sandbox through command approval. After a blocked apply, use step 6’s fresh review.
  • Never run runinfra without a command: in a terminal it waits for a person. A hint naming runinfra login means step 2.
  • Treat null as unknown; relay its reason, never zero or success.

1. Check the CLI

Require runinfra 0.5.0 or later. Ask before installing or updating. After node --version confirms 22+, use npm install -g @runinfra/cli@latest; alternatively Python 3.8+: python -m pip install --upgrade runinfra-cli, or pipx install runinfra-cli. Never use sudo, an administrator shell or --break-system-packages. Never ask for passwords. For 0.3.0 and earlier, reinstall. Otherwise run runinfra update --check --json; after yes, runinfra update --version <targetVersion> --yes --json. Pipx omits --version: recheck; changed target needs another yes. Recheck installed version.

2. Sign in

Reuse sign-in only with exit 0, ok: true, identity.expired: false, identity.endpointMatchesConfiguration: true, and no pasted key. workspaceId stays [redacted]; credentialSource and validated credentialEndpoint stay visible. Otherwise start device sign-in without asking first: browser approval is the consent. Stop on unrelated storage errors.
For pending: true, give relay verbatim; add missing steps using verificationUri, userCode and expiresAt exactly:
Open VERIFICATION_URI and sign in. Type USER_CODE and select Continue. Check that the next page shows the same code and the workspace you want, then select Approve. If anything differs, select Deny and tell me. Tell me when the page says Done, or what it says if it refuses. The code expires at EXPIRES_AT.
Only the human approves. Never open the approval page or enter its code yourself; end your turn after relaying the code. After the human reports approval:
Keep account, home and configuration directory unchanged. Repeat this bounded wait on auth_pending; shorten its timeout to fit your tool. On auth_timeout, create and relay a new code. Exit 0, authenticated: true: saved; recheck whoami. If storage.restricted is false, tell the human and link recovery. Stop on No eligible workspace, Not available for this role, auth_denied, any shared key, workspace API key or Browser sign-in is unavailable; relay the reason. Never pipe a key. After denial, retry only when asked.

3. Find your ID

Read your own row and detection reason. Guide IDs: claude, codex, opencode, pi, aider, qwen-code, kilo-code, goose, continue, cline, droid, zed, grok, hermes, openclaw, crush. For manual, missing, or Copilot CLI’s manual environment setup, stop and link Supported agents. For preview, ask for experimental-support consent before adding --preview to review and apply.

4. Choose how to pay

Show the plan resource’s workspace_id. A plan can pay only when snapshot.availability is available, snapshot.current.serving is true, tile_state is neither ended nor refund_closed, and covers includes chat. Then you MUST ask the human which payer BEFORE review. Never choose for them; wait. --funding plan: Coding plan first, then credits under workspace policy. --funding credits: Pay as you go. When no plan can pay for chat, skip that question. Omit --funding: credits now, workspace policy later. Explicit --funding credits means Credits only and keeps paying from credits after a plan is added. Retry the read once if stale/unavailable; still unavailable, offer Pay as you go or waiting, never assume plan coverage. Read the login funding balance. Add credits in Billing before connecting. means stop; also stop for frozen accounts or credit-funded checks at zero. Never buy a plan or add credits.

5. Show the plan

Use only the command matching step 4, plus approved --preview. If Doctor already shows your connection with ok: true, link: "config", say already set up and ask before reconnecting. Exit 8 is the expected review. At exit 6, code: "config_modified" with refused[] wrote nothing: relay each reason; do not bypass it with sign-in or --yes. Show the review’s relay, every plan[] entry and funding.sentence, including balance and warnings:
Setup plan for DISPLAY_NAME in workspace WORKSPACE_ID. Files: every path and added/removed count. Keys: created, revoked, placement. Paid check: count and payer. Result: separate command, added provider or replaced provider. Notes: every note. Reply yes to apply and pay.
The ID is the workspace approved in the browser; never invent its name. If saved sign-in leaves the human unsure, repeat device sign-in. For Goose and Zed, disclose the private environment file and launch step before yes. Never open that file or print the key. Stop for unexpected changes; wait for explicit yes.

6. Apply after yes

Keep the reviewed ID, --funding or its absence, and --preview unchanged. A close-the-app note means do not apply from inside it: hand the approved command to the human for a terminal outside the app; mention the paid check. Stop; resume at step 8 when they return. Success: exit 0, changes.verificationFailed: false, a probe event with result.ok: true and agent_done with verified: true for your connection. Compare the returned plans[]; report differences. If verification failed, say settings were saved but the paid check failed; relay result.message, retry delay and unverified nextSteps, then Doctor. Read errors and changes.events; report incomplete work. After any failed or interrupted --yes command, never repeat it directly: review without --yes, show it, wait for a new yes. This includes exit 8: “The plan changed or has no unused review”.

7. Tell the human how to start

Give plans[].profile.launcherPath first, then nextSteps[].command. On Windows use the .cmd: PowerShell & '<path>'; cmd "<path>". Relay success relay, then any missing instructions below, once each. Relay PATH and Run now lines with their shell. The PATH line lasts one terminal. Relay pickHint and restart verbatim. Notes are for the human: never run start, PATH, shell-profile or paid-request commands yourself. For Goose and Zed, the human fully quits the app, loads the private environment file with the returned command, then starts goose or zed from that terminal. Repeat after key rotation; never load it yourself. Relay other environment steps. Never claim this chat changed.

8. Check

Read the connection name from plans[].agent. ok: true with link: "config" means saved files match, not that the app restarted. Ignore other connection rows. Host warn and unknown are advisories, including host:sign-in; do not sign in, reconnect or change permissions for them. link: "key" means the human’s environment-key step remains in Doctor’s shell. Otherwise relay your row’s message and hint. Never add --verify: it needs separate paid consent.

9. Undo when asked

Use the separate command’s name where applicable; never disconnect from inside it. Show restores, key revocations and sessions/history deletion. After yes, repeat with --yes. Close-app notes require step 6’s outside-terminal handoff. Use --force or --keep-key only after reviewing their effects with the human. Disconnect does not sign this computer out. Exits: 3 sign-in, 4 plan/not-found, 5 network, 6 conflict, 7 storage, 8 needs yes, 9 refused, 130 interrupted. Read troubleshooting.