@kychee/kygit
v0.2.2
Published
KyGit — the encrypted Git remote's command. A thin brand door over `run402 repos`: every kygit command IS a run402 command.
Maintainers
Readme
kygit
The encrypted Git remote's command — kygit.com.
npm i -g @kychee/kygit run402
kygit create # provision the vault, scaffold the remote
git push origin main # encrypted on your machine, published as a signed headOne package, one install. kygit create scaffolds the remote as
kygit::<org>/<name> — a git remote scheme this package owns end to end,
including its own remote helper (git-remote-kygit, a second bin this
package installs alongside kygit). git push/git fetch are plain git;
git finds kygit:: remotes by spawning git-remote-kygit from PATH, and
npm links every bin of the package you install directly, so no
separate remote-helper install is ever needed. (Install run402 alongside
it, as above: the shim pins its own nested copy and an installed shim
never sees a newer client's verbs on its own.)
(The underlying vault is the same
run402 repos substrate either way: a checkout made with kygit create
and one made with run402 repos create push to the same place, one
spelled kygit::, the other run402:: — see "What this package is" below.)
(The package is scoped because npm's typosquat guard reserves the bare
name — it is one letter from degit. The command you get is still
kygit.)
Run402 cannot decrypt your gitvault or repository history. The full, graded claims — including every limit — live at kygit.com and run402.com/gitvault.
What this package is (and isn't)
kygit is a thin brand door over run402 repos — it exists so the
name on the box matches the name on the site, and nothing else:
- Every kygit command is a run402 command:
kygit <verb>executesrun402 repos <verb>verbatim (same flags, same output, same exit codes).kygit loginexecutesrun402 operator login --loopback. - The verb table is derived at runtime from the installed
run402package's owngitvault-surface.json— the same machine-readable contract file that gates the marketing pages — so this shim can never drift from the canonical CLI. New client verbs work here without akygitrelease. But this package pins its OWN nestedrun402, so a globally installed shim keeps whatever client it resolved at install time:npm i -g @kychee/kygit run402upgrades both in one command, andnpx -y @kychee/kygitresolves the currentrun402on its own. A shim running against an older client answers with THAT client's ordinary unknown-verb refusal naming the upgrade — never a shim-specific error. - Anything outside the repo family is refused with the exact
run402 …spelling to use instead. There is no second semantic CLI and no separate API — only a second remote scheme. kygitrenders every remote it scaffolds or prints askygit::<org>/<name>;run402 reposrenders the same address asrun402::<org>/<name>. Both spellings resolve the same vault, and neither tool ever rewrites a remote the other one wrote — pick whichever spelling you want to see ingit remote -v.
| kygit | canonical |
|---|---|
| kygit create | run402 repos create |
| kygit view | run402 repos view |
| kygit mirror s3://your-bucket | run402 repos mirror s3://your-bucket |
| kygit recover ./mirror | run402 repos recover ./mirror |
| kygit handoff | run402 repos handoff |
| kygit resume kgh1_… | run402 repos resume kgh1_… |
| kygit invite | run402 repos invite |
| kygit join kgi1_… | run402 repos join kgi1_… |
| kygit login | run402 operator login --loopback |
After kygit resume or kygit join you are a writer of the vault under your own key — git push works at once. After a resume the sender's machine can be gone; after a join the inviter is still pushing beside you.
Handoff. Resume. Invite. Join. Two verb pairs, one substrate. A Handoff passes the work to another agent and the sender stops — kygit handoff mints a single-use kgh1_… key, kygit resume claims it, clones fresh, and reapplies the exact dirty state. An Invite grows the team while the sender keeps working — kygit invite mints a single-use kgi1_… key and opens a shared coordination room, kygit join pays its own way in (a fresh run402 wallet, one testnet payment), clones fresh, restores the exact dirty state, and arrives already knowing who invited it. From there run402 messages wait is the room's ear.
Agents: your canonical reference is
run402.com/llms-full.txt (section
"gitvault") and the run402 CLI — this package adds no surface for you.
