Sign in

Credentials

How your agents' and tools' sign-ins reach a box: handed over from your machine through the SSH tunnel, never seen, stored, or proxied by the control plane.

On this page8

Hand them over from your machine

Terminal
prized setup
# or, for the agents alone:
prized agents handoff claude codex

Each asks first: prized setup once for the agents it found, prized agents handoff per agent with the exact files listed, and the Cursor installer (--install-cursor) separately. The GitHub token and git identity go along when gh is signed in on your machine (--no-gh skips them; --non-interactive runs and prized agents handoff need --gh).

ToolWhat travels
Claude CodeYour sign-in (the macOS Keychain item or ~/.claude/.credentials.json), with your MCP servers and settings, to ~/.claude/.credentials.json on the box (0600). The box refreshes it from then on, so one side will eventually ask you to /login again. With no readable local sign-in, nothing is copied and the box keeps its own, as the report says (on a box a teammate used, /login to make it yours); sign in on the box with claude, then /login, or locally and re-run the handoff to carry your settings too.
Codexconfig.toml (with your MCP servers) and an API-key sign-in in ~/.codex/auth.json. A ChatGPT sign-in stays put, since its single-use refresh token would sign one side out: the handoff runs codex login on the box and opens its sign-in page in your browser; when the browser says the sign-in was delivered, return to your terminal for the result. With --json or --non-interactive, the report prints the steps instead: prized ssh, then codex login --device-auth on the box.
CursorMCP and CLI config. Cursor's sign-in lives in your system keychain, which Prized never reads; on the box, agent login prints a URL to open.
GitHubYour gh token, piped to gh auth login --with-token (never on a command line), plus your git name and email if the box has none.
Other CLIsWith --env-secrets (or a yes to the secrets question): the project's .env files, CLI sign-in files (~/.aws, ~/.config/gcloud, ~/.kube/config, ...), and secret-looking env vars from your shell files, written 0600 (Bring your environment). For AWS, a connected role needs none of this.

A box safe for third parties, itself or through its environment, never receives your credentials: the handoff and setup's agent, secrets and data steps refuse it with CHECK_FAILED (exit 5). They also copy nothing while the box's status cannot be checked: signed out is AUTH (exit 8, run prized login); offline, or a box outside your workspace, is CHECK_FAILED (exit 5). prized setup still syncs the project and runs its other steps.

MCP servers whose sign-in cannot travel are reported as needing re-auth, with the command to run. The handoff is a one-time copy: re-run it after changing MCP config.

What the report means

ResultMeaning
okThe tool says it is signed in (for GitHub, as the same account as your machine).
needs-reauthThe files landed, but the check disagreed, could not run, or found a different account.
manualNothing to transfer; the printed steps sign you in on the box.
needs-rerunSkipped on purpose (the agent was running); re-run the handoff afterwards.

The handoff never writes a credential through a symlink, which on a box with a synced folder could land it in your repo: a symlinked directory (~/.codex, ~/.cursor, ~/.claude, or a parent) stops the transfer and names the path, and a symlinked file is replaced by a real file. Installs run first; the GitHub token goes last.

From your machine, only real files travel: a symlinked config file (~/.codex/auth.json pointing elsewhere) is left out, and the consent prompt and the report say so.

Or sign in on the box

Terminal
prized ssh
gh auth login
claude
codex login --device-auth

Once per box is enough; disks persist. codex login --device-auth prints a code to enter in a browser on any device; if your account has no device-code sign-in, run prized agents handoff codex on your machine to sign the box in through your browser.

Claude prints a sign-in link: select it and press c to copy it to your clipboard through prized ssh (Copy out). Paste it in a browser, then paste the code back into Claude.

Secrets for agents

For API keys an agent should use but never read, use Secrets in the dashboard: a value is encrypted at rest, cannot be read back, and shows up on the box only as a placeholder. The box's broker swaps in the real value on requests to HTTPS hosts you allowlisted; plain HTTP is refused.

A secret is open to every box but a contractor's until you grant it to boxes or members; scoping and each secret's usage record (never a value) are on Teams: Scoped secrets. Provider presets are Connectors.

The machine itself

Every box is its own machine, reached only through your encrypted tunnel; what it exposes and what the control plane can see are on Security and trust.

What Prized itself stores

prized login writes an API key and an SSH identity to ~/.config/prized on your machine, and registers the identity's public key with your workspace as a restricted, tunnel-only fallback for SSH clients that cannot use certificates (Claude Desktop remote). The private key never leaves your machine, and your dev credentials never leave your machines. Revoking a machine's API key signs it out and drops its SSH key from your boxes (Workspaces: API keys).

While signed in, the CLI reports which commands ran (name, version, OS, duration, exit code), never arguments, paths, or file contents; opt out under CLI: usage telemetry.