Skip to main content
The harness reads its credentials from the environment and the auth files of the sandbox. Boat fills them from one of two sources:
Your account keys go on a sandbox only if its environment lets them in. If you chose the platform option at onboarding (the preselected option), your first environment is Safe for third parties. This setting keeps every key out.If a prompt fails with “no credential” but the Agents tab shows you as connected, do these steps:
  1. Open Dashboard > Environment.
  2. Turn off Safe for third parties.
  3. Keep Agents credentials on.
New sandboxes get the change at once. For running sandboxes, press the upgrade button on that page. The Agents tab warns you when an environment blocks your keys.

Connect a subscription

The Agents dashboard connects subscriptions the same way for all four vendors:
  1. Click Sign in.
  2. Approve on the page of the vendor. ChatGPT and Kimi show a short code to confirm. Mistral needs no code.
  3. The dashboard shows the subscription as connected.
The Mistral sign-in gives Boat a Mistral API key. This key bills against the Vibe quota of your plan, not against paid API credits. It does not expire. Boat keeps the sign-in alive for you. The server refreshes the token before every prompt and every sandbox start. So a sandbox never starts on an expired token. To remove a subscription from every sandbox, click Sign out on the same row.

Use the keys of your users

--no-env keeps every one of your credentials out of the sandbox. The -e values are the only credentials the sandbox has. Use this for a product where each end user brings their own key or subscription and picks a harness in a selector: Keys are per sandbox, not per conversation. A sandbox that several users share runs on one set of credentials.
  • When the keys of each paying user must stay apart, give each user their own sandbox.
  • When the keys are yours, share one sandbox across conversations.

Environment variables

The harnesses read these variables. Any subset works. If the vendor key of a harness is missing, that harness refuses the prompt with a credential error. The other harnesses keep working. Kimi Code does not read a credential from the environment itself. Before the first prompt, the sandbox writes these values into ~/.kimi-code/config.toml and the token file. After that, the CLI refreshes the subscription token by itself.

DeepSeek

Claude Code and Codex can run on the models of DeepSeek instead of Anthropic or OpenAI. One credential covers both: a DeepSeek platform key. It is a single string that starts with sk-. DeepSeek publishes an Anthropic-shaped endpoint and an OpenAI-shaped endpoint for the same key. So Boat does not change either harness, and neither harness needs a gateway in front of it. What the sandbox gives each harness, and the model ids to pass:
pi, OpenCode and Prime Agent get DeepSeek in a different way. They use your OpenRouter key, with no DeepSeek account. They need only OPENROUTER_API_KEY. The models are:
  • openrouter:deepseek/deepseek-v4.1-flash
  • openrouter:deepseek/deepseek-v4-flash-0731
  • openrouter:deepseek/deepseek-v4-pro-0813

Amazon Bedrock

Claude Code and Codex can run on models that your AWS account serves, instead of the Anthropic or OpenAI API. The simplest credential is a Bedrock API key:
  • It is one string that starts with ABSK.
  • You make it in the Bedrock console, under API keys.
  • It is valid in every region.
IAM access keys also work: access key id, secret, and an optional session token.

Claude Code on Bedrock

The sandbox gives Claude Code CLAUDE_CODE_USE_BEDROCK=1, AWS_REGION, and the key (or AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY). The model ids are Bedrock cross-region inference profiles on the Anthropic line:
  • us.anthropic.claude-sonnet-4-6
  • us.anthropic.claude-opus-4-6-v1
  • us.anthropic.claude-sonnet-4-5-20250929-v1:0
  • us.anthropic.claude-opus-4-5-20251101-v1:0
  • us.anthropic.claude-haiku-4-5-20251001-v1:0
  • us.anthropic.claude-sonnet-5
  • us.anthropic.claude-opus-5
  • us.anthropic.claude-fable-5-1
  • us.anthropic.claude-fable-5
  • us.anthropic.claude-opus-4-8
  • us.anthropic.claude-opus-4-7
When you use the Bedrock credential, these are the only Claude Code models that Boat offers. The default becomes Sonnet 4.6. The reason: inside Claude Code, the plain sonnet and opus aliases point to model ids that many AWS accounts have not enabled.

Codex on Bedrock

The sandbox gives Codex OPENAI_BASE_URL=https://bedrock-mantle.<region>.api.aws/v1 and the key. Codex ignores OPENAI_BASE_URL itself. So the agent server selects the built-in amazon-bedrock provider of Codex for that region. It uses the OpenAI-compatible Mantle endpoint of Bedrock. Web search is off. The model ids are the OpenAI line on Mantle:
  • openai.gpt-5.6-terra
  • openai.gpt-5.6-sol
  • openai.gpt-5.6-luna
  • openai.gpt-5.5
  • openai.gpt-5.5-2026-04-23
  • openai.gpt-5.4
  • openai.gpt-5.4-2026-03-05
Codex on Bedrock needs the API key. IAM keys alone do not authenticate the OpenAI-compatible endpoint. The list does not include the open-weight gpt-oss models. It also does not include the third-party models on Mantle (Kimi, MiniMax, Qwen, DeepSeek, GLM, Mistral). These models answer the /v1 routes of Mantle, but not the /openai/v1/responses route that Codex calls.

Example

Model access is granted per AWS account and region

The lists above show what Amazon Bedrock offers for each harness. They do not show what your account can call today. Bedrock grants model access per AWS account and per region. Boat lists a model as soon as Bedrock serves it, including frontier models that AWS has not granted to you yet. Your access to a model is between your account and AWS. To request access:
  1. Open the Amazon Bedrock console in the region that your credential uses.
  2. Go to Model catalog.
  3. Find the model.
  4. Choose Request model access.
Some models ask for a short use case form. AWS approves these, so the approval is not instant. Access in one region does not carry to another region. If you pick a model that your account cannot use, the prompt fails. The error names the model, the reason and the fix. For example:
Two related failures show different errors: The us. profiles above work only from US regions. From eu-west-1, pass eu.anthropic.claude-sonnet-4-6 instead. The same applies to au. and jp.. A global. prefix works from any supported source region. It needs a wider IAM policy. Read global cross-region inference.

Mistral

Mistral Vibe runs the models of Mistral. pi, OpenCode and Prime Agent run the same models on the same credential. They also run them through OpenRouter or LLM Gateway, on those keys. When both Mistral credentials are on, Boat uses the subscription key. So usage goes to the Vibe quota of your plan first.