Connect a harness
connect needs an active cluster and a current login. It:
- Reuses the coding-agent identity created by registration, or registers one if you haven’t installed reporting yet.
- Attaches the LLM config you named with
--config. Omit--configto use your default config, or--agentto reuse an existing coding-agent identity by name or UUID. - Writes the harness’s own provider settings so new sessions call Nasiko instead of the vendor.
nasiko connect claude --config my-openai sends Claude Code’s Anthropic-format traffic to OpenAI.
What changes on your machine
Connection state is saved under
~/.nasiko/integrations/:
The
__claude-token and __coding-agent-token helpers are internal. Don’t call them yourself.
How a call is routed
The harness talks to Nasiko at/v1/messages (Claude Code), /v1/responses (Codex), or the OpenCode plugin’s equivalent. The router translates the inbound format, selects the model from the attached LLM config, and calls the provider. Spend is attributed to the coding-agent identity, so it shows up next to reported sessions in TokenOps.
If the config’s model is unset, the router falls through the model registry tiers and then the cluster default.
Failure behavior
Routing credentials fail closed. If Nasiko cannot issue a JWT — the cluster is unreachable, your login expired,AGENT_JWT_SECRET is unset on the server, or the helper times out — the harness gets an error. It never falls back to calling the vendor with the original key.
That is the opposite of session reporting, which fails open: turns queue locally and the harness keeps working.
Self-hosting: set AGENT_JWT_SECRET on the server or every routed call is rejected with 401. See Server configuration.
One-shot Claude Code
To run Claude Code through Nasiko for a single invocation, without changing~/.claude/settings.json:
--agent is required. Everything after -- is handed to the claude binary. Environment for that process is injected for the duration of the command.
Disconnect
disconnect restores the harness settings Nasiko changed and deletes the local routing state file. It does not uninstall session reporting — use nasiko agents uninstall <agent> for that.
If the harness is still running, disconnect refuses unless you pass --force. Stop the harness first when you can, so it doesn’t keep using a credential helper that is no longer installed.
