Agent skill

Jev Key Setup

by kerpopule in kerpopule/hermes-jev-skills

Connects the Jev decision model by storing a TypeSafe, OpenRouter, Venice or OpenCode Zen key with jev setup-key, so the key never passes through the agent.

MITAuto-check: notesAI & LLM Engineering

Install Jev Key Setup

skills CLI
$ npx skills add kerpopule/hermes-jev-skills --skill jev-setup -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kerpopule/hermes-jev-skills jev-setup --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kerpopule/hermes-jev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/jev-setup .claude/skills/jev-setup && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
jev-setup
GitHub stars
1k
Token cost
~1.4k tokens
SKILL.md length
821 words
Files
1
Skills in repo
10
Repo updated
First seen
Licence
MIT

At a glance

Connects the Jev decision model by storing a TypeSafe, OpenRouter, Venice or OpenCode Zen key with jev setup-key, so the key never passes through the agent.

  • Works in 5 steps: Check the state: jev doctor. If… → Start the private key page → Tell the person, in one sentence, to… → …
  • Jev tools report no_key or auth_failed
  • SKILL.md covers Rules, Flow, When there is no browser and Where the key goes
  • Needs TYPESAFE_API_KEY and JEV_PROXY_API_KEY

What it does

Jev, TypeSafe's decision model, needs one API key, and the skill's central rule is that the agent must never see, ask for or handle it. The key is saved with the jev setup-key command, which supports four sources: TypeSafe by default, OpenRouter through its Decisions API, Venice, and OpenCode Zen, whose free tier suits people without a TypeSafe key since TypeSafe is not accepting new signups. It suggests OpenRouter when the person already holds a key there, so there is one bill instead of two.

A TYPESAFE_BASE_URL variable can override the endpoint for a local mock or HTTPS proxy. The client never sends a saved provider credential to an override endpoint, a gateway that needs a bearer token uses JEV_PROXY_API_KEY, plaintext is allowed only on loopback addresses and redirects are not followed. The jev doctor command names any override and shows a gateway rejecting the request as auth_failed. The excerpt is cut off after this section, so later steps are not described.

When your agent uses it

  • Jev tools report no_key or auth_failed
  • Connecting Jev for the first time on a new machine
  • Switching Jev to a different key source such as OpenRouter
  • Diagnosing a Jev setup that points at a proxy or mock endpoint

Example prompts

  • “Jev says no_key; help me connect it.”
  • “I already have an OpenRouter key. Set Jev up to use that instead of TypeSafe.”
  • “Jev returns auth_failed after I set a custom base URL; run the doctor and explain what it shows.”
  • “I have no TypeSafe account; what is the free way to get Jev working?”

Requirements

  • The jev CLI
  • An API key from TypeSafe, OpenRouter, Venice or OpenCode Zen

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Check the state: jev doctor. If key.present is true and jev.reachable is true, you are done.
  2. Start the private key page
  3. Tell the person, in one sentence, to paste their TypeSafe key into the page that just opened. If browser_opened is false, or they are…
  4. Wait for the command to finish. It prints {"status": "stored", "verified": true, ...} when the key was saved and the provider accepted it…
  5. Run jev doctor once more and report the result in a sentence.

What it can do on your machine

Read from SKILL.md and the folder at commit dddaa39. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • console.typesafe.ai

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • TYPESAFE_API_KEY
    • JEV_PROXY_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Jev Key Setup loads about 1.4k tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 821 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:29
    - Never read the secret store, `.env` files or `~/.config/jev/credentials` to "check" the key. Use `jev doctor`, which r
  • NoteMentions a .env fileSKILL.md:54
    en as `TYPESAFE_API_KEY` into `~/.hermes/.env` and every `profiles/*/.env`, because each Hermes lane reads its own file.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kerpopule/hermes-jev-skills at commit dddaa39, republished under its MIT licence (© kerpopule). 821 words, ~1,358 tokens.

Download SKILL.mdSave it as .claude/skills/jev-setup/SKILL.md (or your agent's skills folder).
name
jev-setup
description
Use when Jev is not working yet, a Jev tool reports no_key or auth_failed, or the person asks to connect or fix Jev. Gets their TypeSafe or OpenRouter key into the secret store, unseen by you.
version
0.2.0
license
MIT

Connect Jev (the key never passes through you)

Jev is TypeSafe's decision model. It needs one API key. You must never see, ask for, or handle that key.

The key can come from any of three places, and the same Jev answers either way:

  • TypeSafe (jev setup-key, the default): a key from console.typesafe.ai.
  • OpenRouter (jev setup-key --provider openrouter): reaches Jev through OpenRouter's Decisions API. Worth offering when the person already has an OpenRouter key, because it is then one key instead of two and one bill instead of two.
  • Venice (jev setup-key --provider venice): reaches the same Jev through Venice, which serves it as its own decision modality. Worth considering when the person already has a Venice key; check Venice's current pricing before relying on any cost claim.
  • OpenCode Zen (jev setup-key --provider zen): reaches Jev through OpenCode Zen, whose free tier answers the same request with the same model id shape. Worth offering when the person has no TypeSafe key — TypeSafe is not accepting new signups — and wants to start without a bill.

TYPESAFE_BASE_URL is an explicit compatible-endpoint override for a local mock or HTTPS proxy (for example http://127.0.0.1:8787, or a gateway that mounts the API under a path such as https://gw.example/jev). It is not a built-in provider endpoint editor: the official URLs above stay fixed by default. The client never forwards a saved or supplied provider credential to an override endpoint — not the keychain entry, not the credentials file, and not TYPESAFE_API_KEY from the environment, because that variable is where most installs keep their real TypeSafe key. A gateway that requires a bearer gets JEV_PROXY_API_KEY instead: the operator sets it in the same environment as TYPESAFE_BASE_URL, for that gateway only, and it is sent to nothing else. The client permits plaintext only on numeric loopback and does not follow redirects. jev doctor names the override, says whether a bearer goes with it, and asks it: a gateway answering 401 shows up there as auth_failed instead of as silence. Do not send sensitive states to an untrusted proxy. Clear the variable to return to the official endpoint and normal key flow.

If more than one key exists, TypeSafe is used: an existing install never starts routing its decisions somewhere else because an OpenRouter or Zen key happened to be in the environment for a text model. To pick a different one on purpose, set JEV_PROVIDER=openrouter or JEV_PROVIDER=zen in the environment the commands run in; it is honoured only when that provider actually has a key here, and an unset or unknown value changes nothing. jev doctor reports which one is in use under key.provider.

Rules

  • Never ask the person to paste the key into the chat. If they paste one anyway, do not store it, do not repeat it, tell them that key should be replaced, and start the flow below.
  • Never read the secret store, .env files or ~/.config/jev/credentials to "check" the key. Use jev doctor, which reports only presence and length.
  • Never put the key in a command line, a URL, a config file you write, or a log.
Show full SKILL.md (312 more words)Show less

Flow

  1. Check the state: jev doctor. If key.present is true and jev.reachable is true, you are done.

  2. Start the private key page:

    bash
    jev setup-key

    It opens a page in the browser on the computer you are running on and prints one JSON line on stderr with a url. The URL holds no secret.

  3. Tell the person, in one sentence, to paste their TypeSafe key into the page that just opened. If browser_opened is false, or they are talking to you from another device (Telegram, phone), send them the url and tell them it only opens on the computer the agent runs on. If they have no key yet, they create one at https://console.typesafe.ai/settings/keys.

  4. Wait for the command to finish. It prints {"status": "stored", "verified": true, ...} when the key was saved and the provider accepted it. rejected means the key was wrong: run it again. timed_out means nobody used the page within ten minutes.

  5. Run jev doctor once more and report the result in a sentence.

When there is no browser

Headless server over SSH: the person runs jev setup-key --tty themselves in their own terminal. It is a hidden prompt. Do not run it for them through a tool that captures the terminal.

Remote machine on a private network (Tailscale, VPN): jev setup-key --host <private-ip> --no-open and send them the link. That traffic is plain HTTP, so use it only on a network you trust end to end. Never bind a public address.

Where the key goes

The OS secret store (macOS Keychain service Hermes TypeSafe API, or secret-tool on Linux), falling back to ~/.config/jev/credentials (mode 0600). On a Hermes machine it is also written as TYPESAFE_API_KEY into ~/.hermes/.env and every profiles/*/.env, because each Hermes lane reads its own file. Running gateways pick it up on their next restart; do not restart one without being asked.

© kerpopule, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/jev-setup of kerpopule/hermes-jev-skills.

Open the folder on GitHubat commit dddaa39

Compare with similar skills

Jev Key Setup next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Jev Key Setup compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Jev Key Setup this skillkerpopule/hermes-jev-skills1k—~1.4kAutomated safety check: NotesMIT
Pinme LLMglitternetwork/pinme3.7k1 repos~2.8kAutomated safety check: PassMIT
FreeRide Free Model ManagerShaivpidadi/FreeRide2383 repos~1.1kAutomated safety check: PassNone
Embeddings via 9Routerdecolua/9router30k—~604Automated safety check: PassMIT
Using Ccproxy Inspectorstarbaser/ccproxy350—~2.7kAutomated safety check: PassCustom licence
Outsourcereralexgreensh/outsourcerer170—~5.5kAutomated safety check: NotesCustom licence

Similar skills

  • Pinme LLM

    glitternetwork/pinme

    A skill your agent uses when a PinMe project (Worker TypeScript) needs to call OpenRouter-backed LLM APIs, including models, chat/completions, streaming, or OpenRouter web search.

    3.7k GitHub starsUsed in 1 repo~2.8k tokens
    AI & LLM EngineeringAuto-check passed
  • FreeRide Free Model Manager

    Shaivpidadi/FreeRide

    Configures OpenClaw to use free OpenRouter models, setting the best one as primary and adding ranked fallbacks so rate limits do not interrupt work.

    238 GitHub starsUsed in 3 repos~1.1k tokens
    AI & LLM EngineeringAuto-check passed
  • Embeddings via 9Router

    decolua/9router

    Generates vector embeddings through the 9Router /v1/embeddings endpoint, using models from providers such as OpenAI, Gemini, Mistral and Voyage for RAG and semantic search.

    30k GitHub stars~604 tokensUpdated 7 days ago
    AI & LLM EngineeringAuto-check passed
  • Using Ccproxy Inspector

    starbaser/ccproxy

    Operates the ccproxy inspector MITM system for intercepting, inspecting, and transforming LLM API traffic.

    350 GitHub stars~2.7k tokensUpdated 1 mo ago
    AI & LLM EngineeringAuto-check passed
  • Outsourcerer

    alexgreensh/outsourcerer

    Cross-harness orchestrator for AI coding work. An agent skill from alexgreensh/outsourcerer.

    170 GitHub stars~5.5k tokensUpdated 18 days ago
    AI & LLM EngineeringAuto-check: notes
  • LLM Router

    jamesrochabrun/skills

    This skill should be used when users want to route LLM requests to different AI providers (OpenAI, Grok/xAI, Groq, DeepSeek, OpenRouter) using SwiftOpenAI-CLI.

    216 GitHub starsUsed in 1 repo~3.3k tokens
    AI & LLM EngineeringAuto-check passed

More from kerpopule/hermes-jev-skills

All 10 skills in this repo
  • Jev Browser Use

    kerpopule/hermes-jev-skills

    Drives web pages that need interaction, letting Jev choose one action at a time from observed page elements under a host allowlist and step budget.

    1k GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Jev Desktop Computer Use

    kerpopule/hermes-jev-skills

    Drives desktop GUI apps and OS dialogs by letting Jev pick the next action from a menu of safe actions the agent built, with a Mac Co-Agent shortcut.

    1k GitHub stars~4.1k tokensUpdated today
    Auto-check passed
  • Jev Transcript Compaction

    kerpopule/hermes-jev-skills

    Uses Jev to mark each transcript turn keep, summarize or drop when cutting a conversation to a fixed size, with measured results on handoff quality.

    1k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Jev Model Routing

    kerpopule/hermes-jev-skills

    Routes a turn or delegated task to the cheapest model and effort lane that will still do it right, using the Jev decision model to classify difficulty and escalate only when needed.

    1k GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Jev Skill Selector

    kerpopule/hermes-jev-skills

    Ranks a large catalog of installed skills against the current request through the Jev service, and can conclude that no skill applies.

    1k GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Frontier Model Handoff

    kerpopule/hermes-jev-skills

    Chooses which paid frontier model seat should take a task already judged hard, hands it off with proper context, and keeps a watch on the delegated run.

    1k GitHub stars~1.5k tokensUpdated today
    Auto-check: warnings

Works with

Questions about Jev Key Setup

What does Jev Key Setup do?

Connects the Jev decision model by storing a TypeSafe, OpenRouter, Venice or OpenCode Zen key with jev setup-key, so the key never passes through the agent. Jev, TypeSafe's decision model, needs one API key, and the skill's central rule is that the agent must never see, ask for or handle it. The key is saved with the jev setup-key command, which supports four sources: TypeSafe by default, OpenRouter through its Decisions API, Venice, and OpenCode Zen, whose free tier suits people without a TypeSafe key since TypeSafe is not accepting new signups.

When should I use Jev Key Setup?

Jev Key Setup fits situations like: jev tools report no_key or auth_failed; connecting Jev for the first time on a new machine; switching Jev to a different key source such as OpenRouter; diagnosing a Jev setup that points at a proxy or mock endpoint.

How do I install Jev Key Setup in Claude Code?

Run `npx skills add kerpopule/hermes-jev-skills --skill jev-setup -a claude-code`. Or copy the skill folder (skills/jev-setup in kerpopule/hermes-jev-skills) into .claude/skills/jev-setup in your project. Claude Code loads it when a task matches its description.

How do I install Jev Key Setup in Codex?

Run `npx skills add kerpopule/hermes-jev-skills --skill jev-setup -a codex`. Or copy the skill folder (skills/jev-setup in kerpopule/hermes-jev-skills) into .agents/skills/jev-setup in your project. Codex loads it when a task matches its description.

Can I use Jev Key Setup in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kerpopule/hermes-jev-skills --skill jev-setup -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/jev-setup, .gemini/skills/jev-setup, .github/skills/jev-setup and .opencode/skills/jev-setup in your project.

What does Jev Key Setup need to run?

Going by SKILL.md and its folder, Jev Key Setup needs credentials named TYPESAFE_API_KEY and JEV_PROXY_API_KEY. Our summary lists: The jev CLI; An API key from TypeSafe, OpenRouter, Venice or OpenCode Zen.

Does Jev Key Setup access the network?

SKILL.md names 1 domain. As links in the text: console.typesafe.ai. This is read from the text; nothing was executed.

Is Jev Key Setup safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Jev Key Setup use?

Jev Key Setup is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Jev Key Setup use?

About 1.4k tokens (SKILL.md is roughly 5.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Jev Key Setup?

Skills that share tags, products or a category with Jev Key Setup: Pinme LLM (glitternetwork/pinme, 3.7k stars), FreeRide Free Model Manager (Shaivpidadi/FreeRide, 238 stars), Embeddings via 9Router (decolua/9router, 30k stars) and Using Ccproxy Inspector (starbaser/ccproxy, 350 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Jev Key Setup?

kerpopule (a GitHub user) maintains it in kerpopule/hermes-jev-skills, which has 1,046 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 7, 2026.

Source: kerpopule/hermes-jev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.