Kairokuplaybook
Orchestration

Onboarding

What a new team member sets up, in order.

Each person signs in as themselves and mints their own credentials. Nothing on this list is shared, forwarded, or pasted on someone's behalf — a shared credential makes the activity feed stop telling you who did what, which is the one thing it exists to do.

Authenticate your forge. GitHub and GitLab are both supported and a workspace may use either or both — sign in to whichever one holds the repositories you work on.

gh auth login     # GitHub
glab auth login   # GitLab

The app's own read access is a separate thing, configured once per workspace in Settings — see Connections.

Sign in to Claude Code. Start claude, then run /login and complete the browser flow. This is a human-only step.

Sign in to Codex.

codex login

Also a browser flow, also human-only.

Connect Claude Code to Kairoku. Install the plugin per the plugin page, then /mcp → kairoku → Authenticate. The browser grant means there is no token to paste.

Mint your own personal access token in Kairoku under Settings → Developers → MCP tokens, for headless use only. The value is shown once — put it straight into your password manager.

A token is bound at mint time to whichever context was active when you minted it — the organization you had selected, or your personal workspace if you had none. That binding is fixed and travels with the token, so mint it while you are in the workspace the runner is meant to act in. A token minted personally sees a personal workspace no matter which organization the agent is working for.

PAT values are never shared with anyone, never pasted into a chat, a document, a commit, or a brief, and never appear in these docs. If a value has been seen somewhere it should not have been, revoke it and mint a new one; revocation is a hard delete and takes effect immediately.

Optional: add the agent machines to the Paseo desktop app. Paseo is the manual cockpit and nothing depends on it — skip this step unless you want to watch or steer a session by hand. Install it from paseo.sh/download or the GitHub releases page — the desktop build bundles its own daemon, so there is nothing else to install on your laptop. The agent machines run the headless CLI instead (npm install -g @getpaseo/cli), which is what the daemon on each of them is.

Add each daemon by <vm-ip>:6767 with its password. Get the address and password from whoever provisioned the machine — through your password manager, not a message.

Paseo is the manual cockpit: it is for watching and steering a session by hand. Automated dispatch does not go through it. See Orchestration for why that line is drawn where it is.