agents
agents
¶
Agent providers, ACP, image build, instructions — public API surface.
Re-export catalog for everything agent-shaped: the provider registry,
the runner abstraction, ACP-socket inspection, image build, and the
instructions / config bundlers. Sources:
terok.lib.integrations.executor for
the executor wheel's surface,
terok.lib.orchestration.image for
terok's Dockerfile + image pipeline,
terok.lib.core.images for installed-agent
queries, terok.lib.domain.auth for the
authenticate workflow, and
terok.lib.orchestration.agent_config
for stack resolution.
__all__ = ['ACPEndpointStatus', 'AGENTS', 'AGENT_NAMES', 'AUTH_PROVIDERS', 'AgentRoster', 'AgentRunner', 'BuildError', 'DEFAULT_BASE_IMAGE', 'EXECUTOR_COMMANDS', 'ExecutorConfigView', 'ImageBuilder', 'acp_socket_is_live', 'auth_provider_aliases', 'available_auth_modes', 'bundled_default_instructions', 'ensure_sandbox_ready', 'get_agent', 'load_auth_providers', 'providers_config_dir', 'resolve_auth_provider', 'resolve_instructions']
module-attribute
¶
auth_provider_aliases()
¶
Map an LLM-provider name to the auth entry that authenticates it.
A native agent is reached for auth under its own name (terok auth codex)
yet authenticates a differently-named provider — codex → openai, claude →
anthropic, vibe → mistral — so the user should be able to type either.
Built from the AGENTS entries whose provider_binding.default differs
from their name; tools (gh, sonar) and the collapsed harness-providers
(blablador, …) aren't in AGENTS, so they yield no alias — each is
already reached under its own name.
Source code in src/terok/lib/domain/auth.py
available_auth_modes(provider)
¶
Ordered auth methods provider effectively offers.
The single source of truth for "which login methods does this provider
expose", honoring both the roster's declared capabilities and terok's
OAuth gate (the experimental flag plus the per-provider
allow_oauth). Returns mode ids drawn from "oauth",
"device_auth", and "api_key": the device-code variant appears
only alongside "oauth" — it is the same credential obtained
headlessly — and only for providers that declare it. Shared by the CLI
listing, the CLI/TUI method choosers, and the TUI's direct-vs-chooser
gating so the two frontends can't drift.
provider is resolved from its LLM-provider alias (openai → codex)
first. An unknown provider yields an empty list.
Source code in src/terok/lib/domain/auth.py
resolve_auth_provider(name)
¶
Resolve an LLM-provider alias (openai) to its auth entry (codex).
Returns name unchanged when it is already an auth entry (or unknown).
Source code in src/terok/lib/domain/auth.py
__getattr__(name)
¶
Resolve a re-exported name to its source module on first access (PEP 562).