1. See which keys your agents can reach
2. Set up Passport
- Sign in creates your workspace if you’re new. Already signed in on this computer? Init uses that sign-in.
- Apps covers Railway, Vercel, Supabase, Cloudflare, GitHub, and Stripe when it finds a key or the app’s CLI. If your workspace reviews new apps first, init says so and your admin gets the request.
- Agents adds your workspace’s Passport address to Claude Code, Codex, Cursor, and VS Code. Each agent signs you in through your browser the first time, so no key or token goes in its settings. For Claude Desktop, init shows the address to add in Settings → Connectors.
- Guard asks before destructive commands the agents run in your terminal, like
railway volume delete. It can’t see inside scripts, aliases, ormaketargets. See the CLI hook. - Safety makes destructive actions in those apps ask first, in every agent. If yours is off, init asks before turning it on; if it’s already on, init just shows it. Change it any time in Settings → Safety.
--yes to accept every default. Without a terminal, init doesn’t wait for app sign-ins: it prints the sign-in page and passport connect --wait 300 to run once you’re done. --yes --json prints one summary with each step’s status. --skip-apps, --skip-agents, and --skip-guard leave a step out, and --no-open prints links instead of opening a browser.
What changes on your computer
Init changes only Passport’s own entries. Before it edits a file it didn’t create, it says which one and saves the original once as
<file>.passport-backup. It never edits your shell profile; to run passport from any terminal, add the PATH line it prints.
Undo it
npx only? Use ~/.passport/cli/bin/passport in place of passport. Then remove the passport entry from ~/.cursor/mcp.json and from VS Code (MCP: List Servers), and delete ~/.passport/cli. Your original settings are in the .passport-backup files if you want them back.