Skip to content

Authentication

kardbrd-agent requires authentication with both kardbrd (for board access) and your LLM provider (for AI execution).

kardbrd authentication

Get your bot token from the kardbrd board settings:

  1. Open your board → Settings → Bots
  2. Create a bot or copy the existing bot token
  3. Set the environment variable:
export KARDBRD_TOKEN=<bot-token>

LLM provider authentication

Claude CLI (default executor)

Claude CLI requires an Anthropic API key:

  1. Get an API key from console.anthropic.com
  2. Set the environment variable:
export ANTHROPIC_API_KEY=sk-ant-...
  1. Verify authentication:
claude auth status

Subscription required

Claude CLI requires an active Anthropic API subscription. If the API key expires or is revoked, kardbrd-agent posts an error comment on the card with re-authentication instructions.

Goose (multi-provider executor)

Goose supports 20+ LLM providers. Set your provider and its API key:

export GOOSE_PROVIDER=anthropic
export ANTHROPIC_API_KEY=sk-ant-...
export GOOSE_PROVIDER=openai
export OPENAI_API_KEY=sk-...
export GOOSE_PROVIDER=google
export GOOGLE_API_KEY=...
export GOOSE_PROVIDER=ollama
# No API key needed for local models
export GOOSE_PROVIDER=openrouter
export OPENROUTER_API_KEY=...
export GOOSE_PROVIDER=groq
export GROQ_API_KEY=...
export GOOSE_PROVIDER=databricks
export DATABRICKS_TOKEN=...

Tip

Run goose configure to interactively set up your provider. Goose can also store keys in your system keychain.

Codex CLI

Codex requires an OpenAI API key:

export OPENAI_API_KEY=sk-...

Re-authentication

If your LLM provider credentials expire:

  • kardbrd-agent checks authentication at startup and before each card session
  • On auth failure, the agent posts an error comment on the card with specific re-auth instructions
  • A reaction is added to the triggering comment
  • The agent continues running and retries auth on the next card event

To re-authenticate without restarting:

Executor How to re-authenticate
Claude Run claude auth login or update ANTHROPIC_API_KEY
Goose Update the provider-specific API key, or run goose configure
Codex Update OPENAI_API_KEY