Skip to content

feat(auth): add Kimi Code OAuth login - #708

Closed
euxaristia wants to merge 21 commits into
Twigpine:mainfrom
euxaristia:feat/kimi-oauth-login
Closed

euxaristia wants to merge 21 commits into
Twigpine:mainfrom
euxaristia:feat/kimi-oauth-login

Conversation

@euxaristia

@euxaristia euxaristia commented Jul 17, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Adds a first-class Kimi Code OAuth login to Zero, listed directly below ChatGPT in the OAuth options.

Kimi is modeled on the generic device-code preset path (like xAI), not the bespoke ChatGPT/Codex path — because Kimi's returned access token works directly as a Bearer on its managed coding endpoint, so no claim extraction is needed.

Changes

  • internal/providercatalog/catalog.go — new kimi catalog entry, OpenAI-compatible at https://api.kimi.com/coding/v1, flagged OAuth + OAuthDeviceFlow, RequiresAuth with no API-key env var. Placed immediately after the ChatGPT entry so it appears below ChatGPT in the OAuth provider list.
  • internal/oauth/presets.go — kimi device-code preset (auth.kimi.com endpoints, public kimi-code client_id); overridable via ZERO_OAUTH_KIMI_*.
  • internal/cli/auth.go — adds zero auth kimi sugar routing to the generic device-code login; lists kimi below chatgpt in the help text.
  • internal/tui/provider_wizard.go — mentions Kimi in the OAuth method subtitle and includes it in the OAuth provider list.
  • docs/oauth-subscriptions.md — documents the Kimi Code OAuth path.
  • Tests: presets_test.go, catalog_test.go, oauth_test.go updated.

Safety / ToS note

The preset ships the public kimi-code client_id and Moonshot's auth.kimi.com endpoints copied from the open-source kimi-code CLI. It does nothing a user couldn't already do manually (standard RFC 8628 device-code flow, no client spoofing). Off by default; enable with ZERO_OAUTH_ALLOW_PRESETS=1 or explicit env overrides.

Verification

  • go fmt, go vet, golangci-lint (unused,ineffassign,staticcheck), and govulncheck pass (no issues in modified files).
  • go test ./internal/oauth/... ./internal/providercatalog/... ./internal/cli/... pass.

🤖 Generated with Zero

Summary by CodeRabbit

  • New Features
    • Added Kimi Code as a built-in OAuth device-code-only provider, including zero auth kimi support.
    • Updated the OAuth setup/provider wizard so device-only providers start device-code login when pressing Enter, with mouse activation behavior preserved.
  • Documentation
    • Documented Kimi Code in the OAuth materials, including ZERO_OAUTH_ALLOW_PRESETS=1 and ZERO_OAUTH_KIMI_CODE_* overrides.
  • Improvements
    • Enhanced OAuth device-code, token, and refresh requests to include provider-required identity headers.
  • Tests
    • Added/updated tests covering Kimi Code preset resolution, provider catalog/OAuth classification and ordering, and device-only TUI/CLI flows.

Loading
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants