space-duck-kimi-relay
Optional Lane A / BYOB add-on for Space Duck — runs a local RFC 8628 device-code "Sign in with Kimi" flow (no password; browser-approved) so a self-hosted duck can use the owner's flat-rate Kimi membership for inference. Credentials (access + rotating refresh token) are stored locally at ~/.kimi-code/credentials/kimi.json (0600) and are NEVER sent to Spaceduckling. Contacts only auth.kimi.com and api.kimi.com; inference is processed by Moonshot AI in China (no Western data residency). Optional pay-per-token fallback to openrouter.ai when OPENROUTER_API_KEY is set (daily-capped). Runs a localhost-only proxy (127.0.0.1, default 8471) protected by an auto-generated 0600 bearer secret. Hosted (Lane B) ducks use the Mission Control card instead. Triggers on "sign in with kimi", "kimi membership login", "clawhub space-duck kimi", "kimi relay login".
Rank
62
Safety
84
Downloads
1.5k
Updated
Oct 10, 2026
Version
0.9.8
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.5K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.5K downloadsadoption · observed Oct 10, 2026
- Latest release
- 0.9.8release · observed Sep 26, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17e5znj81e7w3zawrsxqg06hn85qbfq:space-duck-kimi-relay- Install using `clawhub skill install s17e5znj81e7w3zawrsxqg06hn85qbfq:space-duck-kimi-relay` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/askegor/space-duck-kimi-relay before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-askegor-space-duck-kimi-relay/snapshot"
Documentation
CLAWHUB
149,393 characters of source documentation, loaded on request.
Extracted files
4 files captured from the source.
SKILL.md
---
name: space-duck-kimi-relay
description: Optional Lane A / BYOB add-on for Space Duck — runs a local RFC 8628 device-code "Sign in with Kimi" flow (no password; browser-approved) so a self-hosted duck can use the owner's flat-rate Kimi membership for inference. Credentials (access + rotating refresh token) are stored locally at ~/.kimi-code/credentials/kimi.json (0600) and are NEVER sent to Spaceduckling. Contacts only auth.kimi.com and api.kimi.com; inference is processed by Moonshot AI in China (no Western data residency). Optional pay-per-token fallback to openrouter.ai when OPENROUTER_API_KEY is set (daily-capped). Runs a localhost-only proxy (127.0.0.1, default 8471) protected by an auto-generated 0600 bearer secret. Hosted (Lane B) ducks use the Mission Control card instead. Triggers on "sign in with kimi", "kimi membership login", "clawhub space-duck kimi", "kimi relay login".
disclosures:
network:
- auth.kimi.com # OAuth device authorization + token/refresh
- api.kimi.com # membership inference (Moonshot AI, China)
- openrouter.ai # OPTIONAL pay-per-token fallback, only if OPENROUTER_API_KEY set
credentials:
- Kimi access + refresh token at ~/.kimi-code/credentials/kimi.json (0600, local only)
- auto-generated proxy bearer secret at ~/.kimi-code/credentials/proxy_secret (0600)
- reads OPENROUTER_API_KEY from env; forwarded only to openrouter.ai on fallback
data_residency: "Kimi inference runs on Moonshot AI infrastructure in China."
overridable_endpoints:
- KIMI_AUTH_HOST, KIMI_CODING_BASE, KIMI_CLIENT_ID # advanced; changing these re-points token traffic
spend: "Fallback is metered, default cap KIMI_RELAY_FALLBACK_DAILY_CAP=200 calls/day; past cap returns 429."
auth_bypass: "KIMI_RELAY_NO_AUTH=1 disables the localhost proxy's bearer check — single-user boxes only."
privilege: "install-service writes a systemd-user/launchd unit; captured KIMI_*/OPENROUTER_API_KEY secrets go in a separate 0600 EnvironmentFile (~/.kimi-code/credentials/relay.env), never inlined into the unit."
sends_to_spaceduckling: none
---
# Space Duck Kimi Relay (optional add-on, Lane A)
Lets a duck that runs on **your own infrastructure** use your **Kimi
membership** (flat-rate subscription quota) for inference instead of
pay-per-token API keys.
## Trust model — the whole point
- The device-code sign-in runs **locally on your box**.
- Tokens are stored at `~/.kimi-code/credentials/kimi.json` (0600), on
**your machine only**.
- The only host this skill contacts is Kimi itself (`auth.kimi.com` and
`api.kimi.com`). **Spaceduckling never sees or holds the token.**
- This is the Lane A mirror of Mission Control's hosted "Sign in with
Kimi" card: same protocol capability, different custody. (Cross-lane
parity doctrine — capability exists in both lanes, credentials follow
the lane's trust model.)
## Commands
```
kimi_login.py login # interactive device sign-in
kimi_login.py t_meta.json
{
"ownerId": "kn7cav8v08rpkp9w38xg3d9mp985q1e1",
"slug": "space-duck-kimi-relay",
"version": "0.9.8",
"publishedAt": 1790399901991
}SECURITY-MANIFEST.md
# space-duck-kimi-relay — Security Manifest (byte-grounded)
Version: 0.8.4 (aligned with the space-duck family — see MEMORY.md publish log) · Generated 2026-08-11 · Evidence = `scripts/kimi_login.py` line refs.
Rule: every claim below cites file:line. No claim rests on an LLM "reading".
## Scope
Package is exactly 3 files: `SKILL.md`, `_meta.json`, `scripts/kimi_login.py`.
No `lib/`, no `bin/`, no `package.json`, no JS, no dependencies beyond Python stdlib
(`fcntl, json, os, sys, time, urllib, http.server, secrets, subprocess`).
## Credential custody
- Store path: `~/.kimi-code/credentials/kimi.json` — `CRED_PATH` (kimi_login.py:41-42).
- Written 0600 via `os.open(..., 0o600)` in `_save()` (kimi_login.py:73); dir 0700 (kimi_login.py:65).
- Proxy bearer secret `proxy_secret` written 0600 (kimi_login.py:206).
- Access token read only from local file in `_load()`/`fresh_token()` (kimi_login.py:80-154).
## Outbound hosts (complete egress allowlist)
Every network call is a `urllib.request.urlopen` — there are exactly three call sites:
- kimi_login.py:55 → `AUTH_HOST` = `https://auth.kimi.com` (OAuth device + token/refresh), :36
- kimi_login.py:166 → `CODING_BASE` = `https://api.kimi.com/coding/v1` (inference), :40
- kimi_login.py:353 → `CODING_BASE` (streaming inference)
- kimi_login.py:333 → `https://openrouter.ai/api/v1` — ONLY when `OPENROUTER_API_KEY` set (:319)
No other socket/urlopen/requests calls exist. **Nothing is sent to Spaceduckling.**
## Where the token can leave the process
- Kimi token injected as `Authorization: Bearer` only to Kimi hosts: kimi_login.py:164, :350.
- `OPENROUTER_API_KEY` sent only to openrouter.ai: kimi_login.py:333.
- No logging of token/secret values (log_message prints request lines only, :278-279).
## Proxy exposure
- Binds localhost only: `ThreadingHTTPServer(("127.0.0.1", port), ...)` (kimi_login.py:387). No bind-address override exists.
- Auth ON by default: bearer check at kimi_login.py:291-296; secret auto-generated (:203-209).
- `KIMI_RELAY_NO_AUTH=1` is an explicit opt-OUT (:194) and prints a loud warning (:394).
Assessed NOT a defect: already localhost-bound + secret-by-default. Disclosure, not a patch.
## Fallback spend
- Metered, default cap 200/day (`FALLBACK_DAILY_CAP`, :210); returns 429 past cap (:322-324).
## Service install (hardened in 0.5.2)
- systemd: secrets written to a **separate 0600 EnvironmentFile** `~/.kimi-code/credentials/relay.env` (kimi_login.py:461), referenced via `EnvironmentFile=` (:465). Secrets are NOT inlined into the (world-readable) unit.
- Deterministic test asserts: secret value absent from unit, `EnvironmentFile=` present, env file 0600. PASS (2026-08-11).
- macOS launchd: plist written 0600 (:444); values embedded in plist (0600) — documented residual.
## Overridable endpoints (disclosed)
- `KIMI_AUTH_HOST` (:36), `KIMI_CODING_BASE` (:40), `KIMI_CLIENT_ID` (:38). Changing these re-points token traffic — advanced use, disclosed in frontmatter.
## Not covered byskill-card.md
## Description: Enables self-hosted Space Duck agents to sign in to Kimi through a browser-approved device flow and use a local inference proxy with optional metered fallback. This skill is ready for commercial/non-commercial use. ## Publisher: [askegor](https://clawhub.ai/user/askegor) ### License/Terms of Use: MIT-0 ## Use Case: Developers running self-hosted Space Duck agents can use their Kimi membership for inference through a locally authenticated proxy instead of configuring a static access token. An optional OpenRouter fallback supports metered inference when membership calls fail. ### Deployment Geography for Use: Global; Kimi inference is processed in China and is unsuitable where Western data residency is required. ## Known Risks and Mitigations: Risk: Local Kimi tokens and an optional OpenRouter key grant access to accounts or metered usage. Mitigation: Protect local credential files, prefer the authenticated localhost proxy, and avoid printing or sharing tokens. Risk: Disabling proxy authentication can expose membership quota to other users or processes on a shared machine. Mitigation: Do not enable KIMI_RELAY_NO_AUTH on shared machines. Risk: Optional fallback can incur pay-per-token charges when membership requests fail. Mitigation: Enable fallback only when needed and set an appropriate daily call cap. Risk: Endpoint overrides can redirect token traffic, and service installation can persist secrets in a macOS launchd plist. Mitigation: Avoid endpoint overrides unless the destination is trusted; review service installation and protect the macOS plist. Risk: Kimi inference is processed in China rather than under Western data residency. Mitigation: Do not route conversations requiring Western data residency through this relay. ## Reference(s): - [Space Duck Kimi Relay on ClawHub](https://clawhub.ai/askegor/skills/space-duck-kimi-relay) - [Security manifest](SECURITY-MANIFEST.md) ## Skill Output: **Output Type(s):** [Shell commands, Configuration instructions, Guidance] **Output Format:** [Markdown with command examples] **Output Parameters:** [1D] **Other Properties Related to Output:** [Supports local sign-in, token refresh, proxy setup, and optional paid fallback.] ## Skill Version(s): 0.9.8 (source: ClawHub release metadata and _meta.json) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/askegor/skills/space-duck-kimi-relay",
"sourceUrl": "https://clawhub.ai/askegor/skills/space-duck-kimi-relay",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T09:08:13.891Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-askegor-space-duck-kimi-relay/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-askegor-space-duck-kimi-relay/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T09:08:13.891Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.5K downloads",
"href": "https://clawhub.ai/askegor/space-duck-kimi-relay",
"sourceUrl": "https://clawhub.ai/askegor/space-duck-kimi-relay",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T09:08:13.891Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.9.8",
"href": "https://clawhub.ai/askegor/space-duck-kimi-relay",
"sourceUrl": "https://clawhub.ai/askegor/space-duck-kimi-relay",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-26T05:18:21.991Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-askegor-space-duck-kimi-relay/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-askegor-space-duck-kimi-relay/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.9.8",
"description": "0.9.8: no-op lockstep bump with space-duck 0.9.8 (family version alignment).",
"href": "https://clawhub.ai/askegor/space-duck-kimi-relay",
"sourceUrl": "https://clawhub.ai/askegor/space-duck-kimi-relay",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-26T05:18:21.991Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
