Credentials
How your agents' and tools' sign-ins reach a box: handed over from your machine through the SSH tunnel, never seen, stored, or proxied by the control plane.
On this page8
Hand them over from your machine
prized setup
# or, for the agents alone:
prized agents handoff claude codexEach asks first: prized setup once for the agents it found, prized agents handoff per agent with the exact files listed, and the Cursor installer (--install-cursor) separately. The GitHub token and git identity go along when gh is signed in on your machine (--no-gh skips them; --non-interactive runs and prized agents handoff need --gh).
| Tool | What travels |
|---|---|
| Claude Code | Your sign-in (the macOS Keychain item or ~/.claude/.credentials.json), with your MCP servers and settings, to ~/.claude/.credentials.json on the box (0600). The box refreshes it from then on, so one side will eventually ask you to /login again. With no readable local sign-in, nothing is copied and the box keeps its own, as the report says (on a box a teammate used, /login to make it yours); sign in on the box with claude, then /login, or locally and re-run the handoff to carry your settings too. |
| Codex | config.toml (with your MCP servers) and an API-key sign-in in ~/.codex/auth.json. A ChatGPT sign-in stays put, since its single-use refresh token would sign one side out: the handoff runs codex login on the box and opens its sign-in page in your browser; when the browser says the sign-in was delivered, return to your terminal for the result. With --json or --non-interactive, the report prints the steps instead: prized ssh, then codex login --device-auth on the box. |
| Cursor | MCP and CLI config. Cursor's sign-in lives in your system keychain, which Prized never reads; on the box, agent login prints a URL to open. |
| GitHub | Your gh token, piped to gh auth login --with-token (never on a command line), plus your git name and email if the box has none. |
| Other CLIs | With --env-secrets (or a yes to the secrets question): the project's .env files, CLI sign-in files (~/.aws, ~/.config/gcloud, ~/.kube/config, ...), and secret-looking env vars from your shell files, written 0600 (Bring your environment). For AWS, a connected role needs none of this. |
A box safe for third parties, itself or through its environment, never receives your credentials: the handoff and setup's agent, secrets and data steps refuse it with CHECK_FAILED (exit 5). They also copy nothing while the box's status cannot be checked: signed out is AUTH (exit 8, run prized login); offline, or a box outside your workspace, is CHECK_FAILED (exit 5). prized setup still syncs the project and runs its other steps.
MCP servers whose sign-in cannot travel are reported as needing re-auth, with the command to run. The handoff is a one-time copy: re-run it after changing MCP config.
What the report means
| Result | Meaning |
|---|---|
ok | The tool says it is signed in (for GitHub, as the same account as your machine). |
needs-reauth | The files landed, but the check disagreed, could not run, or found a different account. |
manual | Nothing to transfer; the printed steps sign you in on the box. |
needs-rerun | Skipped on purpose (the agent was running); re-run the handoff afterwards. |
Symlinks and order
The handoff never writes a credential through a symlink, which on a box with a synced folder could land it in your repo: a symlinked directory (~/.codex, ~/.cursor, ~/.claude, or a parent) stops the transfer and names the path, and a symlinked file is replaced by a real file. Installs run first; the GitHub token goes last.
From your machine, only real files travel: a symlinked config file (~/.codex/auth.json pointing elsewhere) is left out, and the consent prompt and the report say so.
Or sign in on the box
prized ssh
gh auth login
claude
codex login --device-authOnce per box is enough; disks persist. codex login --device-auth prints a code to enter in a browser on any device; if your account has no device-code sign-in, run prized agents handoff codex on your machine to sign the box in through your browser.
Copying the sign-in link
Claude prints a sign-in link: select it and press c to copy it to your clipboard through prized ssh (Copy out). Paste it in a browser, then paste the code back into Claude.
Secrets for agents
For API keys an agent should use but never read, use Secrets in the dashboard: a value is encrypted at rest, cannot be read back, and shows up on the box only as a placeholder. The box's broker swaps in the real value on requests to HTTPS hosts you allowlisted; plain HTTP is refused.
A secret is open to every box but a contractor's until you grant it to boxes or members; scoping and each secret's usage record (never a value) are on Teams: Scoped secrets. Provider presets are Connectors.
The machine itself
Every box is its own machine, reached only through your encrypted tunnel; what it exposes and what the control plane can see are on Security and trust.
What Prized itself stores
prized login writes an API key and an SSH identity to ~/.config/prized on your machine, and registers the identity's public key with your workspace as a restricted, tunnel-only fallback for SSH clients that cannot use certificates (Claude Desktop remote). The private key never leaves your machine, and your dev credentials never leave your machines. Revoking a machine's API key signs it out and drops its SSH key from your boxes (Workspaces: API keys).
While signed in, the CLI reports which commands ran (name, version, OS, duration, exit code), never arguments, paths, or file contents; opt out under CLI: usage telemetry.