# How to Configure API Keys for Kimi-CLI: Environment Variables and Config Files

> Easily configure API keys for Kimi-CLI using environment variables or config files. Learn the precedence rules for secure and flexible credential management with MoonshotAI kimi-cli.

- Repository: [Moonshot AI/kimi-cli](https://github.com/MoonshotAI/kimi-cli)
- Tags: how-to-guide
- Published: 2026-07-25

---

**Kimi-CLI reads API credentials from the `KIMI_API_KEY` environment variable or the `api_key` field in `~/.kimi/config.toml`, with environment variables taking precedence over file-based configuration.**

To authenticate with Moonshot AI or OpenAI services, you must configure API keys for kimi-cli using either environment variables or a persistent configuration file. The MoonshotAI/kimi-cli repository implements a hierarchical configuration system that prioritizes runtime environment variables over settings stored in the user config. This guide explains the exact mechanisms defined in the source code for secure credential management.

## Configuration Sources and Precedence

The CLI evaluates credentials in a strict hierarchy, as implemented in [`src/kimi_cli/llm.py`](https://github.com/MoonshotAI/kimi-cli/blob/main/src/kimi_cli/llm.py) (lines 289-291) and [`src/kimi_cli/config.py`](https://github.com/MoonshotAI/kimi-cli/blob/main/src/kimi_cli/config.py):

1. **Environment variables** (`KIMI_API_KEY` or `OPENAI_API_KEY`)
2. **User configuration file** (`~/.kimi/config.toml`)

When the CLI initializes via `KimiCLI.create`, it merges these sources. If an environment variable is present, the UI displays a masked value (e.g., `****** (from KIMI_API_KEY)`) according to the implementation in [`src/kimi_cli/app.py`](https://github.com/MoonshotAI/kimi-cli/blob/main/src/kimi_cli/app.py) (lines 722-726).

## Setting API Keys via Environment Variables

Environment variables provide the highest precedence and are ideal for CI/CD pipelines, Docker containers, or temporary testing scenarios.

### Configuring KIMI_API_KEY for Moonshot AI

Set the `KIMI_API_KEY` variable to authenticate with Moonshot AI's API:

```bash
export KIMI_API_KEY="sk-your-kimi-api-key"

```

This value is read via `os.getenv("KIMI_API_KEY")` in [`src/kimi_cli/llm.py`](https://github.com/MoonshotAI/kimi-cli/blob/main/src/kimi_cli/llm.py) before any file-based configuration is loaded.

### Configuring OPENAI_API_KEY for OpenAI Services

For OpenAI-compatible endpoints, use the standard variable:

```bash
export OPENAI_API_KEY="sk-your-openai-api-key"

```

## Persisting API Keys in the Config File

For permanent storage, create or edit `~/.kimi/config.toml`. The file uses TOML format and is parsed by the `Config` model in [`src/kimi_cli/config.py`](https://github.com/MoonshotAI/kimi-cli/blob/main/src/kimi_cli/config.py), which stores the `api_key` as a `SecretStr` to prevent accidental exposure in logs.

### Basic Configuration Structure

```toml
[services.kimi]
api_key = "sk-your-kimi-api-key"

# Optional: override the default base URL

# base_url = "https://api.kimi.ai"

```

### Multi-Provider Configuration

You can store keys for multiple providers in the same file:

```toml
[services.kimi]
api_key = "sk-kimi-key"

[services.openai]
api_key = "sk-openai-key"

```

## Verifying Active Configuration

To confirm which credential is active, run:

```bash
kimi config show

```

If an environment variable is overriding the config file, the output will indicate the source (e.g., `from KIMI_API_KEY`) and display the masked value as handled in [`src/kimi_cli/app.py`](https://github.com/MoonshotAI/kimi-cli/blob/main/src/kimi_cli/app.py).

## Summary

- **Environment variables** (`KIMI_API_KEY`, `OPENAI_API_KEY`) take precedence and are checked first in [`src/kimi_cli/llm.py`](https://github.com/MoonshotAI/kimi-cli/blob/main/src/kimi_cli/llm.py) (lines 289-291).
- **Config file** (`~/.kimi/config.toml`) stores persistent credentials using `SecretStr` protection via [`src/kimi_cli/config.py`](https://github.com/MoonshotAI/kimi-cli/blob/main/src/kimi_cli/config.py).
- **Precedence rule**: Environment variables mask config file values, with the UI indicating active overrides in [`src/kimi_cli/app.py`](https://github.com/MoonshotAI/kimi-cli/blob/main/src/kimi_cli/app.py) (lines 722-726).
- **Security**: Use environment variables for CI/CD and ephemeral environments; use the config file with restrictive permissions (0600) for personal development machines.

## Frequently Asked Questions

### Where does kimi-cli store the API key configuration?

Kimi-cli stores persistent configuration in `~/.kimi/config.toml`. The `api_key` field is defined in [`src/kimi_cli/config.py`](https://github.com/MoonshotAI/kimi-cli/blob/main/src/kimi_cli/config.py) as a `SecretStr` type, which helps prevent accidental logging of sensitive values while allowing the application to use the credential.

### Can I use multiple API providers simultaneously?

Yes. You can define separate sections in `~/.kimi/config.toml` for different providers (e.g., `[services.kimi]` and `[services.openai]`), or use environment variables to switch between them. The CLI reads both `KIMI_API_KEY` and `OPENAI_API_KEY` environment variables according to the provider configuration.

### How do I temporarily override the API key for a single command?

Prefix the command with the environment variable assignment:

```bash
KIMI_API_KEY="sk-temporary-key" kimi chat "Your prompt here"

```

This overrides any value in the config file for that specific process without modifying persistent storage or affecting other shell sessions.

### Is the API key visible in process lists when set via environment variables?

When using environment variables, the value may be visible to other processes running as the same user via `/proc` or `ps` utilities. For shared systems, prefer using the config file with appropriate file permissions (0600) on `~/.kimi/config.toml`, as the `SecretStr` handling in [`src/kimi_cli/config.py`](https://github.com/MoonshotAI/kimi-cli/blob/main/src/kimi_cli/config.py) ensures the key is masked in UI outputs and logs.