Skip to content

Remove competing provider keys from harness launches - #803

Closed
czpython wants to merge 1 commit into
mainfrom
codex/issue-383-provider-env
Closed

czpython wants to merge 1 commit into
mainfrom
codex/issue-383-provider-env

Conversation

@czpython

@czpython czpython commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

A harness launch unsets every provider credential variable except the one that holds the run's own credential. A sandbox can inject a competing value, for example the ANTHROPIC_API_KEY that Docker Sandboxes sets, and the CLI can read it instead of the Druks placeholder. The agent's billing mode and its model's provider select the variable to keep.

The sandbox applies this once to every harness run. A Chat adapter starts the same way. The bridge keeps the reply command of the turn, so the conversation title runs with the credential of that turn.

Closes #383. Linear: DRU-693.

@czpython
czpython force-pushed the codex/issue-383-provider-env branch from 35d246e to 7ee1d92 Compare October 3, 2026 15:37
@czpython

czpython commented Oct 3, 2026

Copy link
Copy Markdown
Owner Author

Closing without a change. Claude Code chooses ANTHROPIC_AUTH_TOKEN before ANTHROPIC_API_KEY, so a subscription run already wins over the key that Docker Sandboxes injects. An API-key run reads ANTHROPIC_API_KEY itself, and removing variables at launch cannot help there. See #383.

@czpython czpython closed this Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Harness CLIs inherit provider API keys from the sandbox environment

1 participant