openkairos
v0.1.0
Published
Kairos — a secure, provider-agnostic terminal coding agent with a beautiful TUI. 50+ providers, bring your own key, zero telemetry, zero runtime dependencies.
Maintainers
Readme
Kairos
A secure, provider-agnostic coding agent for your terminal. 59 providers, your own API keys, an encrypted local vault, and a TUI that is pleasant to stare at for eight hours.
node cli/bin/kairos.js # run from this repo
npm i -g ./cli && kairos # or install the `kairos` commandWhy it is different
- Any model, one interface. OpenAI, Anthropic, Gemini, Grok, DeepSeek, Groq, Mistral, Moonshot, Qwen, OpenRouter, Bedrock, Vertex, Ollama, LM Studio, vLLM and ~45 more. Three native protocols (OpenAI chat-completions, Anthropic Messages, Gemini) so tool calling works properly everywhere — not just on the vendor's own CLI.
- Bring your own key, keep your own key. No Kairos account, no proxy, no server. Your key goes to the provider's endpoint and nowhere else.
- Zero runtime dependencies. Pure Node stdlib. Nothing in the supply chain to audit but this repo.
- Checkpoints and rewind. Every turn snapshots the files it touches.
/rewind 3restores the tree and the conversation to that exact moment. - Diff-first edits. Nothing is written until you see the colored diff and press
y.
Security
| Control | Implementation |
| --- | --- |
| Keys at rest | AES-256-GCM, key = scrypt(N=32768) over a machine secret + optional KAIROS_PASSPHRASE |
| Machine binding | 32 random bytes in machine.key (0600); copying the vault elsewhere is useless |
| Tamper detection | GCM auth tag verified on every unlock |
| File permissions | vault 0600 inside a 0700 config dir |
| Key entry | raw-mode hidden input — never echoed, never in shell history, never in argv |
| Key display | SHA-256 fingerprints only; the secret is never rendered |
| Redaction | known secrets + key-shaped strings masked in output, session files and prompts |
| Prompt hygiene | .env, .ssh, .aws, .npmrc, keystore files are refused by read_file |
| Sandbox | all file operations resolved and confined to the working directory |
| Command policy | deny-list for destructive and exfiltration patterns, applied before approval |
| Subprocess env | *_API_KEY, *_TOKEN, *SECRET* stripped from child processes |
| Telemetry | none, ever |
Run /security inside the app to see the live posture of your install.
Commands
/provider /model /login /logout /keys /mode /shell /checkpoint /rewind
/sessions /resume /diff /security /clear /exit
Approval modes: prompt (default, ask for every mutation), auto-edit (write freely, still deny-listed), readonly (analysis only — mutating tools are not even exposed to the model).
Tools the agent has
list_files · read_file · search_code · write_file · edit_file · delete_file ·
run_command · git (status/diff/log/branch/stage/commit)
Layout
cli/bin/kairos.js entry + flags
cli/src/ui.js ANSI TUI primitives (gradient, boxes, spinner)
cli/src/app.js REPL, slash commands, approval UI
cli/src/agent.js tool-calling loop
cli/src/client.js OpenAI / Anthropic / Gemini streaming adapters
cli/src/providers.js the provider registry
cli/src/keystore.js encrypted vault
cli/src/security.js sandbox, command policy, redaction
cli/src/session.js sessions + checkpoints
cli/src/diff.js LCS unified diffMIT.
