Repository navigation
Conversation
…ing code` `lightning code setup|status|remove` now take pi, codex, dsh and cursor as well as opencode. Each tool plans its file changes as text, which the commands show for --dry-run and apply, so a tool only decides what its files should say: - pi: provider spliced into ~/.pi/agent/models.json, key in pi's auth.json, default model in settings.json. - Codex: its own profile, ~/.codex/lightning.config.toml (0600), used with `codex --profile lightning`; config.toml is never touched. - dsh: provider and default model in the web and headless profile patches, only those entries rewritten; key in ~/.dsh/.credentials.yaml as LIGHTNING_CODE_API_KEY (not LIGHTNING_API_KEY, which Studios set). - Cursor: can't be configured from outside, so a key is created and the steps to add it in Cursor Settings are printed. Also: OpenCode adds `lightning` to an enabled_providers allowlist, remove deletes files setup created, files holding keys are never backed up, and --dry-run masks keys and summarises shared credential files.
rusenask
requested review from
dhedey,
ethanwharris,
justusschock,
k223kim,
owbone and
tejapulagam
as code owners
October 9, 2026 16:03
andyland
approved these changes
Oct 9, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
lightning code setup | status | removenow handle pi, Codex, DeepSeek Harness (dsh) and Cursor, as well as OpenCode (#192). Each sets the tool up to use code.lightning.ai, with a key that bills the chosen org. The org picker, the Pro/Teams/Enterprise check, the model list from/v1/modelsand the DeepSeek V4.1 Flash default work the same for every tool.How each tool is configured
provider.lightningspliced into~/.config/opencode/opencode.json[c]~/.local/share/opencode/auth.jsonmodel, only if unsetproviders.lightningspliced into~/.pi/agent/models.jsonauth.json(api_key)settings.jsondefaultProvider/defaultModel, only if unset~/.codex/lightning.config.toml(0600), used withcodex --profile lightning;config.tomlis never touchedexperimental_bearer_tokenin the profilemodel(a/modelchoice in Codex is kept on re-runs)llm-pi-aientry in thewebandheadlessprofile patches; only that entry andagent-default-modelare rewritten, so other entries keep their text and comments~/.dsh/.credentials.yamlasLIGHTNING_CODE_API_KEYagent-default-model, only if the profile has noneNotes on the choices:
/v1/responsesstreams correct Codex-shaped requests (store: false, tools) for all three models.LIGHTNING_API_KEYfrom the provider id, but Studios already set that variable to the platform key, and the environment wins over dsh's credential file. That's why it'sLIGHTNING_CODE_API_KEY.cursor-agentCLI can't use custom endpoints, and while the base-URL override is on, Cursor's own GPT/Auto models stop working. The printed steps say both.models.jsonif any entry is invalid, so only fields its schema accepts are written.Changes to the existing OpenCode setup
enabled_providers: if the user's config has this allowlist, setup now addslightningto it andremovetakes it out again. Before, setup only warned, and OpenCode quietly ignored the provider. Testing on a real config found this.removedeletes files setup created once nothing else is left in them. A file with the user's comments is kept.--dry-runmaskssk-lit-keys. Shared credential files (auth.json,.credentials.yaml) get a one-line summary instead of a diff, so other providers' keys are never printed.Structure
tool.py: theToolinterface:read→ToolStateplan_setup/plan_remove→Plan, a list ofFileChangeobjects with the before and after textsummary,instructions,warningsIt also holds the shared
applystep, which backs up files and writes them atomically, and the default-model rule.opencode.py,pi.py,codex.py,dsh.py,cursor.py: one module per tool.registry.pylists them.files.py: file helpers, plus~/.lightning/code-tools.json(0600, IDs only, no keys). It records the org and key for tools with no place for metadata; OpenCode keeps usingauth.jsonmetadata.utils/jsonc.py: gains arrayappend_item/remove_itemandhas_comments.Testing
On macOS (my Mac, default paths, real configs):
opencode.jsoncwith six providers and anenabled_providerslist:opencode run -m lightning/deepseek-v4.1-flashansweredpong.removerestoredopencode.jsoncbyte-for-byte, andauth.jsonhad the same entries.config.toml:codex exec -p lightningansweredpongviadeepseek-v4.1-flash.-m lightning-ai/glm-5.3it ranwc -lthrough the shell tool and answered3.config.tomlwas untouched by our code, andremovedeleted the profile.pi --list-models lightningshowed all three models with the right context, output and image support.pongwith the default model and read a blue test image (Blue).4).removedeleted the files setup created, andauth.jsonwas restored.~/.dsh:dsh --profile headlessansweredpongand used its shell tool (5).removeleft the empty[]patch dsh expects.read_filetool call for a Cursor-style/v1/chat/completionsrequest.removerevokes the key and prints how to switch the override off.On Linux, end to end in a Lightning Studio (
lightningai-engineering/skills), with this branch's wheel, OpenCode 1.18.35, pi 1.1.0, Codex 0.162.0, dsh 0.2.0-rc.2 and Node 22.20:statuslisted each with its org, key and default.deepseek-v4.1-flash): OpenCode, pi, Codex and dsh all answeredpong.Blue): OpenCode and pi.6): OpenCode, pi, Codex and dsh.removefor each revoked its key, and none of the test keys are left.Locally:
tests/cli/codecover:remove--force!!jstags keptstatuscovering every toolutils/test_jsonc.py, the entry point and non-interactive tests also pass.Known limitation
Codex with images fails on the server. Codex sends no
max_output_tokens, and on/v1/responsesthe server's default seems to be computed before the image tokens are counted. Prompt plus completion then lands 181 tokens over the 262,144 context (6,469 + 255,856), and the engine returns 400. Text and tool use through Codex work. The fix belongs in the worker: when a Responses request has nomax_output_tokens, set it to the model'smax_completion_tokens. The tutorial says Codex image input isn't supported yet.🤖 Generated with Claude Code