Skip to content

Headless local-only BYOK requires login after custom models load #942

Description

@cenab

Summary

Command Code 1.66.0 loads custom BYOK models in local-only mode, but a fresh headless run requires cmd login before sending any request to the selected provider. Could this initial-login requirement be removed for local-only BYOK, or documented explicitly if intentional?

Expected Behavior

After local-only model discovery succeeds with a configured BYOK provider/key, headless execution should either call that provider directly or clearly document the additional Command Code account requirement. I am not assuming that local-only mode grants access to account-only features.

Actual Behavior

command-code --local-only --list-models lists Tsubasa (byok) and both configured aliases. Running either alias in headless local-only mode exits 3 with:

Error: Not authenticated. Please run "cmd login" first.

The loopback provider recorder receives zero requests. JSON output reports zero input/output tokens and the same authentication error.

Steps to reproduce the issue

  1. Install command-code@1.66.0 in a fresh Node 22 Linux container with its normal HOME. Do not log into a Command Code account.
  2. Create ~/.commandcode/providers.json:
{
  "provider": {
    "tsubasa": {
      "name": "Tsubasa",
      "baseURL": "http://127.0.0.1:8080/v1",
      "api": "openai-completions",
      "apiKey": "$TSUBASA_API_KEY",
      "models": {
        "tsubasa-fast": {"name":"tsubasa-fast","contextWindow":32768,"maxOutput":512,"reasoning":false},
        "tsubasa-pro": {"name":"tsubasa-pro","contextWindow":32768,"maxOutput":512,"reasoning":false}
      }
    }
  }
}
  1. Set TSUBASA_API_KEY to a synthetic test value and CMD_LOCAL_ONLY=1. Start a loopback request recorder at the configured URL.
  2. Confirm command-code --local-only --list-models loads the provider and aliases.
  3. Run:
command-code --local-only --no-auto-update --skip-onboarding --no-skills \
  --no-session --max-turns 2 --output-format json \
  --model tsubasa/tsubasa-fast --permission-mode plan \
  -p 'Reply with a greeting. Do not use tools.'
  1. Repeat with tsubasa/tsubasa-pro; the same authentication failure occurs before provider HTTP.

Command Code Version

1.66.0

Operating System

Linux

Terminal/IDE

Noninteractive Docker process with piped stdin/stdout.

Shell

The CLI was launched directly from Node execFile, without shell expansion.

Additional context

This was a compatibility check for a Tsubasa-owned configuration. After package installation, container networking was disconnected; only its own loopback recorder remained reachable. The normal container HOME was preserved, no host directories were mounted, and only synthetic credentials were used. The container was removed after testing. The result demonstrates the early login gate; it does not establish behavior for an authenticated account or prove any vendor network traffic occurred.

References: BYOK, CLI reference.

Prepared with AI assistance.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions