How to Configure API Keys for Kimi-CLI: Environment Variables and Config Files
Kimi-CLI reads API credentials from the KIMI_API_KEY environment variable or the api_key field in ~/.kimi/config.toml, with environment variables taking precedence over file-based configuration.
To authenticate with Moonshot AI or OpenAI services, you must configure API keys for kimi-cli using either environment variables or a persistent configuration file. The MoonshotAI/kimi-cli repository implements a hierarchical configuration system that prioritizes runtime environment variables over settings stored in the user config. This guide explains the exact mechanisms defined in the source code for secure credential management.
Configuration Sources and Precedence
The CLI evaluates credentials in a strict hierarchy, as implemented in src/kimi_cli/llm.py (lines 289-291) and src/kimi_cli/config.py:
- Environment variables (
KIMI_API_KEYorOPENAI_API_KEY) - User configuration file (
~/.kimi/config.toml)
When the CLI initializes via KimiCLI.create, it merges these sources. If an environment variable is present, the UI displays a masked value (e.g., ****** (from KIMI_API_KEY)) according to the implementation in src/kimi_cli/app.py (lines 722-726).
Setting API Keys via Environment Variables
Environment variables provide the highest precedence and are ideal for CI/CD pipelines, Docker containers, or temporary testing scenarios.
Configuring KIMI_API_KEY for Moonshot AI
Set the KIMI_API_KEY variable to authenticate with Moonshot AI's API:
export KIMI_API_KEY="sk-your-kimi-api-key"
This value is read via os.getenv("KIMI_API_KEY") in src/kimi_cli/llm.py before any file-based configuration is loaded.
Configuring OPENAI_API_KEY for OpenAI Services
For OpenAI-compatible endpoints, use the standard variable:
export OPENAI_API_KEY="sk-your-openai-api-key"
Persisting API Keys in the Config File
For permanent storage, create or edit ~/.kimi/config.toml. The file uses TOML format and is parsed by the Config model in src/kimi_cli/config.py, which stores the api_key as a SecretStr to prevent accidental exposure in logs.
Basic Configuration Structure
[services.kimi]
api_key = "sk-your-kimi-api-key"
# Optional: override the default base URL
# base_url = "https://api.kimi.ai"
Multi-Provider Configuration
You can store keys for multiple providers in the same file:
[services.kimi]
api_key = "sk-kimi-key"
[services.openai]
api_key = "sk-openai-key"
Verifying Active Configuration
To confirm which credential is active, run:
kimi config show
If an environment variable is overriding the config file, the output will indicate the source (e.g., from KIMI_API_KEY) and display the masked value as handled in src/kimi_cli/app.py.
Summary
- Environment variables (
KIMI_API_KEY,OPENAI_API_KEY) take precedence and are checked first insrc/kimi_cli/llm.py(lines 289-291). - Config file (
~/.kimi/config.toml) stores persistent credentials usingSecretStrprotection viasrc/kimi_cli/config.py. - Precedence rule: Environment variables mask config file values, with the UI indicating active overrides in
src/kimi_cli/app.py(lines 722-726). - Security: Use environment variables for CI/CD and ephemeral environments; use the config file with restrictive permissions (0600) for personal development machines.
Frequently Asked Questions
Where does kimi-cli store the API key configuration?
Kimi-cli stores persistent configuration in ~/.kimi/config.toml. The api_key field is defined in src/kimi_cli/config.py as a SecretStr type, which helps prevent accidental logging of sensitive values while allowing the application to use the credential.
Can I use multiple API providers simultaneously?
Yes. You can define separate sections in ~/.kimi/config.toml for different providers (e.g., [services.kimi] and [services.openai]), or use environment variables to switch between them. The CLI reads both KIMI_API_KEY and OPENAI_API_KEY environment variables according to the provider configuration.
How do I temporarily override the API key for a single command?
Prefix the command with the environment variable assignment:
KIMI_API_KEY="sk-temporary-key" kimi chat "Your prompt here"
This overrides any value in the config file for that specific process without modifying persistent storage or affecting other shell sessions.
Is the API key visible in process lists when set via environment variables?
When using environment variables, the value may be visible to other processes running as the same user via /proc or ps utilities. For shared systems, prefer using the config file with appropriate file permissions (0600) on ~/.kimi/config.toml, as the SecretStr handling in src/kimi_cli/config.py ensures the key is masked in UI outputs and logs.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →