Skip to content

Accounts, providers and rig environments ​

Documented against OpenRig 0.5.14. Help text uses "node" where these pages say seat, for a seat's position in the running rig.

What it is for ​

Seats run on the accounts your harnesses are already logged into. rig auth manages named auth profiles for a runtime without ever printing, logging or storing a token. rig provider reads which seats are bound to which accounts, what the usage signals say, and whether a seat can be switched to another account without stranding the conversation it is in. rig env inspects and controls the services a service-backed rig runs alongside its seats, such as the Vault behind the secrets-manager starter.

The three commands you will use first ​

See the auth state without secrets.

bash
rig auth status
rig auth list --runtime codex
rig auth seats list

Read the provider model, and switch safely.precheck never offers an unsafe switch; switch is precheck-gated and orchestrated by the daemon.

bash
rig provider status
rig provider signals
rig provider precheck --seat dev-impl@my-rig --account <ref>

Check a service-backed rig's environment.env status is the honest health surface for managed services; ps alone is not.

bash
rig env status secrets-manager
rig env logs secrets-manager vault
rig env down secrets-manager

The auth, provider and env families ​

CommandWhat it does (from help)Help source
rig authManage agent auth profiles (CLI-local; runtime via --runtime). Tokens are never printed, logged, or stored.auth.txt
rig auth listList saved profiles by name.auth.list.txt
rig auth saveSnapshot the active auth state into a named profile (file copy; contents never echoed).auth.save.txt
rig auth seatsSeat -> profile registry (metadata only; not proof of a live account).auth.seats.txt
rig auth seats listList seat -> profile mappings.auth.seats.list.txt
rig auth seats reportCounts: total / known / unknown / malformed.auth.seats.report.txt
rig auth seats setUpsert a seat -> profile metadata row.auth.seats.set.txt
rig auth seats showShow the registry row for one seat.auth.seats.show.txt
rig auth statusAuth-file presence + login state (no secrets).auth.status.txt
rig auth switchActivate a saved profile.auth.switch.txt
rig auth validateCheck a profile's file mode + JSON parseability (NOT live-auth).auth.validate.txt
rig envInspect and control rig environment services for service-backed rigs and managed appsenv.txt
rig env downenv.down.txt
rig env logsenv.logs.txt
rig env statusenv.status.txt
rig providerProvider accounts, usage signals, and interruption-safe account switchingprovider.txt
rig provider accountsThe accounts block of the provider read modelprovider.accounts.txt
rig provider bindingsThe bindings block of the provider read modelprovider.bindings.txt
rig provider precheckWhether switching a seat to an account is safe (never offers an unsafe switch)provider.precheck.txt
rig provider signalsThe signals block of the provider read modelprovider.signals.txt
rig provider statusThe whole four-block provider read model (accounts, bindings, signals)provider.status.txt
rig provider switchSwitch a seat to an account (precheck-gated; the daemon orchestrates the switch)provider.switch.txt

What it does not do ​

  • rig auth validate checks a profile's file mode and JSON shape, not that the account is live.
  • provider signals reports anomalies (unbound seats, accounts shared across seats), not a listing.
  • env down --volumes removes compose volumes; it is a data-loss action, not a stop.

Where it goes next ​

  • Lifecycle: booting a service-backed rig such as secrets-manager.
  • Troubleshooting: what to read when a seat's runtime is not logged in.

Read as Markdown

Self-contained SOP. No outbound links. OpenRig 0.5.14.