Agent skill

Quota Provider Onboarding

by kunchenguid in kunchenguid/quota-axi

Sets the rules and checklist for adding a new quota provider, or changing an existing adapter, in quota-axi, covering credential sources, liveness probes and tests.

MITAuto-check passedBackend & APIs

Install Quota Provider Onboarding

skills CLI
$ npx skills add kunchenguid/quota-axi --skill provider-onboarding -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kunchenguid/quota-axi provider-onboarding --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kunchenguid/quota-axi.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/provider-onboarding .claude/skills/provider-onboarding && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
provider-onboarding
GitHub stars
146
Token cost
~2.3k tokens
SKILL.md length
1,106 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Sets the rules and checklist for adding a new quota provider, or changing an existing adapter, in quota-axi, covering credential sources, liveness probes and tests.

  • Works in 4 steps: Enumerate every source in… → Separate local resolution from the… → Handover only after definitive… → …
  • Adding support for a new quota provider to quota-axi
  • SKILL.md covers Clean-Room & Dependency Policy, Provider Onboarding Checklist, Credential Selection Machinery and Multi-Source Handover &…, plus 2 more sections
  • Calls claude

What it does

This skill is the project's rulebook for adding quota providers or modifying provider adapters in quota-axi. Adapter behavior must be an original clean-room implementation based on the vendor's own HTTP and OAuth behavior, with no vendored third-party adapter code; the Z.AI adapter is the single credited exception. All remote requests go through providerFetch in src/lib/http.ts so proxy environment variables apply consistently, and process-table reads go through currentUserProcessListArgs in src/lib/process.ts.

The onboarding checklist begins by listing every credential source in order of ownership stability, with the priority set as a named constant. Local resolution distinguishes absent, structurally invalid, unsupported, read error and resolved results, and credentialPresent is derived once from it. A separate, bounded, read-only liveness probe then classifies outcomes as usable, live with no quota, definitively rejected or transient. Expired stored credentials are enrolled rather than skipped, and presence alone never counts as liveness.

Per its description, the skill goes on to cover multi-source handover between credential sources, the delegated refresh contract and the testing rules that provider changes must follow.

When your agent uses it

  • Adding support for a new quota provider to quota-axi
  • Modifying an existing provider adapter's credential lookup or refresh logic
  • Reviewing a provider pull request against the project's credential and proxy rules
  • Deciding how to classify a credential that is stored but expired

Example prompts

  • “Add a new provider adapter to quota-axi and follow the onboarding checklist.”
  • “Does my Copilot adapter change route its HTTP calls through providerFetch?”
  • “Review this adapter diff for how it classifies stored-expired credentials.”
  • “Refactor the credential resolution so credentialPresent is derived once.”

Requirements

  • A checkout of the quota-axi repository

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Enumerate every source in ownership-stability order
  2. Separate local resolution from the bounded read-only liveness probe
  3. Handover only after definitive credential failure
  4. Add comprehensive adapter regression tests

What it can do on your machine

Read from SKILL.md and the folder at commit 8ba593c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • claude

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Quota Provider Onboarding loads about 2.3k tokens when it runs. Until then it costs about 57 tokens; SKILL.md has 1,106 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~57
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kunchenguid/quota-axi at commit 8ba593c, republished under its MIT licence (© kunchenguid). 1,106 words, ~2,305 tokens.

Download SKILL.mdSave it as .claude/skills/provider-onboarding/SKILL.md (or your agent's skills folder).
name
provider-onboarding
description
Rules, checklist, credential selection machinery, multi-source handover, delegated refresh contract, and test discipline for onboarding new quota providers or modifying existing provider adapters in quota-axi.
user-invocable
false

Provider Onboarding & Credential Architecture

This document defines the requirements, shared machinery, and safety invariants for onboarding new quota providers or modifying existing adapters in quota-axi.

Clean-Room & Dependency Policy

  • Clean-room implementation: Adapter behavior (retry-after handling, snake/camel field tolerance, window parsing) must be an original implementation derived solely from the vendor's own HTTP/OAuth behavior. quota-axi carries no vendored third-party adapter code. The Z.AI adapter is the single attribution exception (derived from opencode-glm-quota, MIT) credited in src/providers/zai.ts.
  • HTTP & proxy handling: Remote HTTP requests must route through src/lib/http.ts (providerFetch) so standard HTTP_PROXY, HTTPS_PROXY, and NO_PROXY policies apply consistently without leaking proxy credentials in logs. Do not use global fetch directly.
    • Node 26 compatibility: src/lib/http.ts pairs the installed undici build's ProxyAgent with that same build's fetch because Node's built-in global fetch only accepts dispatchers from its bundled undici, and Node 26 rejects external ProxyAgent instances with InvalidArgumentError: invalid onError method.
  • Process table reads: Any process-table inspection (e.g. Antigravity loopback detection or Claude process checks) must route through currentUserProcessListArgs in src/lib/process.ts to handle platform flag differences portably (Linux procps rejects BSD -x alongside -u).

Provider Onboarding Checklist

When adding a new provider or migrating an existing adapter:

  1. Enumerate every source in ownership-stability order:

    • Declare source priority via a named constant (e.g. COPILOT_SOURCE_ORDER).
    • Distinguish absent, structurally_invalid, unsupported, read_error, and resolved (stored-valid or stored-expired) at the typed local resolution boundary.
    • Route Pi agent entries through classifyPiAuthEntry in src/lib/pi-auth-store.ts.
    • Derive credentialPresent once from local resolution rather than ad hoc at call sites.
  2. Separate local resolution from the bounded read-only liveness probe:

    • Enroll stored-expired credentials instead of skipping them.
    • Never infer liveness from presence alone.
    • Classify probe outcomes as usable, live_no_quota, definitively_rejected, or transient.
    • Only a first-party HTTP 401 or 403 is an authentication verdict. Server errors, rate limits, network timeouts, or schema mismatches are request failures, not auth verdicts.
  3. Handover only after definitive credential failure:

    • An absent source is never marked degraded.
    • A present-but-broken source superseded by a working sibling is marked degraded on fresh readings only (state.degradedSources).
    • Stale means last-known cache.
    • Never exchange a refresh token, and never retain, log, render, cache, or send its value. Delegated refresh checks presence only; Pi brokers may read a stored refresh value only to classify it as a usable literal, then discard it.
  4. Add comprehensive adapter regression tests:

    • Test cases: primary healthy, stored-expired plus live sibling, structurally invalid present, absent source, all rejected, refreshable expired, and transient failure stops handover.
    • Extend the cross-provider invariant table in test/credential-contract.test.ts.

Credential Selection Machinery

Credential selection is shared in src/providers/credential-selection.ts:

  • Advisory stored expiry: Stored expiresAt or expired fields are advisory only within a source, never a verdict or a reason to reorder declared sources.
  • Empirical testing: Stored-expired credentials are tested in that source's fixed priority position before any sign-in or expired verdict. An empirically live credential always wins.
  • Transient failures: Network errors, 5xx responses, or timeouts must never switch candidates within one source or become auth verdicts.
  • Adapters using selection: Grok, Codex, Kimi, Command Code, Copilot, OpenCode Go, Devin, and Muse route through selectCredential. Codex, Kimi, Copilot, and Devin call it once per source so each provider's ownership-stability order remains authoritative.
  • Probe token safety: A broker's expired resolution carries the stored token for probe use only; it must never be logged, cached, or rendered.
  • Profile-only mode: --profile-only is the fail-closed single-account quota probe for Claude and Codex: it requires CLAUDE_CONFIG_DIR or CODEX_HOME, reads only that profile's native credential file, and bypasses alternate sources, delegated refresh, and quota cache access (full JSON keeps non-secret account/source/attempt evidence; ordinary output stays redacted). Omitting the flag must preserve legacy discovery and cache behavior. Contract: README Profile-only quota reads.

Multi-Source Handover & Degraded Sources

  • Working store precedence: A broken store must never speak for a provider whose sibling store still answers. Consult sources in priority order.
  • Handover boundaries: Handover happens on credential problems only, never on transport, decoding, or server failures.
  • Tracking attempts: src/lib/source-attempts.ts classifies attempts as status: "failed" or skipped with credentialPresent. Adapters set degraded: false on non-credential attempts (e.g. Grok's live model catalog probe).
  • Reporting degradation: withQuotaSemantics in src/interpretation.ts publishes state.degradedSources on fresh readings only. src/render.ts emits the degraded_source attention row.

Show full SKILL.md (420 more words)Show less

Delegated Credential Refresh

Shared machinery lives in src/providers/delegated-refresh.ts. It is the single carve-out to quota-axi's read-only boundary:

  • Eligibility criteria: A delegate is eligible ONLY when:

    1. The same stored access token is expired,
    2. The stored credential carries a refresh token, and
    3. The token was definitively rejected (HTTP 401/403) by the vendor's quota/user endpoint.
  • Mechanism: quota-axi executes the vendor CLI's own smallest non-interactive rotation command (e.g. claude doctor, grok models) and re-reads the file/store that CLI updated.

  • Never exchange tokens: quota-axi must never perform an OAuth refresh-token exchange itself. These tokens rotate on use; a second exchange signs the user out of the measured tool.

  • Presence only: Delegated refresh inspects the refresh token's presence only (Object.hasOwn(credential, "refresh_token")). quota-axi never retains, logs, renders, caches, or sends its value. Pi brokers may read a stored refresh value only to classify it as a usable literal, then discard it.

  • Never signal the child: Quota-axi never signals or force-kills a delegated child process. The budget bounds only how long quota-axi waits. The child runs in its own process group (detached: true) so Ctrl+C on a live TUI does not abort it. If the command exceeds budget, resolve as unconfirmed/refresh_timed_out (reported as unmeasured or stale, never as sign-out, and never retiring cache).

  • Claude safety check: Before delegating Claude refresh, src/lib/running-processes.ts must confirm no Claude Code process is running, since Claude Code owns that session's refresh. If the process table cannot be listed, stay read-only. The check and spawn are not atomic - the check only narrows the common repeated --tui versus live-session collision; together with never signaling the delegate it is strictly safer than force-killing without adding a failure mode. Contract: README Delegated credential refresh.

  • Approved delegates: Only commands whose rotation behavior is empirically established from the vendor CLI are permitted:

    • Claude: claude doctor
    • Grok: grok models
    • Codex: app-server JSON-RPC probe

    All other providers (Cursor, Copilot, Kimi, Z.AI, Alibaba, OpenCode Go, Antigravity, Command Code, MiniMax, MiMo, DeepSeek, OpenRouter, ElevenLabs, Devin, Muse, Higgsfield) remain strictly read-only.

  • Option gating: Delegated refresh is gated by ProviderOptions.refreshCredentials. --no-credential-refresh disables it; the auth command always passes false. Tests must specify it explicitly to prevent accidental CLI spawning.


Test & Mocking Discipline

  • Synthetic credentials: All tests must use synthetic credentials and fixtures located in test/fixtures/. Never use real secrets or developer tokens.
  • Mock all boundaries: Mock Keychain (security), Windows Credential Manager (CredReadW), process table (ps), and remote HTTP requests.
  • No live network or execution: Tests and CLI runs during validation must never contact live provider endpoints or execute real credential refresh commands.

© kunchenguid, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/provider-onboarding of kunchenguid/quota-axi.

Open the folder on GitHubat commit 8ba593c

Compare with similar skills

Quota Provider Onboarding next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Quota Provider Onboarding compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Quota Provider Onboarding this skillkunchenguid/quota-axi146—~2.3kAutomated safety check: PassMIT
Passport Developmenttrypostit/trypost685—~1.9kAutomated safety check: PassMIT
Soundcloud API Integrationsoundcloud/api259—~787Automated safety check: PassNone
MCP API Key AuthenticationYourdaylight/stock_datasource189—~1.2kAutomated safety check: PassMIT
OmniRoute API Keysdiegosouzapw/OmniRoute74k—~1.4kAutomated safety check: PassMIT
Venice API Keysveniceai/skills143—~3.8kAutomated safety check: PassMIT

Similar skills

  • Passport Development

    trypostit/trypost

    Develops OAuth2 API authentication with Laravel Passport. An agent skill from trypostit/trypost.

    685 GitHub stars~1.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Integrates applications with the SoundCloud HTTP API using OAuth 2.1, OpenAPI, and developer docs.

    259 GitHub stars~787 tokensUpdated 8 days ago
    Backend & APIsAuto-check passed
  • MCP API Key Authentication

    Yourdaylight/stock_datasource

    Sets up and troubleshoots MCP API key authentication for a stock data service, covering key creation, client configuration and per-tool usage statistics.

    189 GitHub stars~1.2k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • OmniRoute API Keys

    diegosouzapw/OmniRoute

    Documents the OmniRoute REST endpoints for creating, listing, updating, regenerating and deleting API keys, with per-key scopes, spending limits, expiry and device lists.

    74k GitHub stars~1.4k tokensUpdated today
    Backend & APIsAuto-check passed
  • Venice API Keys

    veniceai/skills

    Manages Venice API keys through the /api_keys endpoints: create, list, update and revoke keys, set spending limits, and read rate limits.

    143 GitHub stars~3.8k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Venice API Overview

    veniceai/skills

    High-level map of the Venice.ai API: base URL, auth modes per endpoint, endpoint categories, response headers, pricing model, error shape and versioning.

    143 GitHub stars~3.5k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed

More from kunchenguid/quota-axi

  • quota-axi Release and CI Rules

    kunchenguid/quota-axi

    Documents release automation, CI workflow constraints, the contribution gate and generated-file rules for the quota-axi repository, driven by release-please.

    146 GitHub stars~934 tokensUpdated today
    Auto-check passed
  • Quota Cache Architecture

    kunchenguid/quota-axi

    Documents how quota-axi keeps its disk cache: location, strict file permissions, no stored secrets, and context-scoped identifiers that stop snapshots crossing accounts.

    146 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Quota Provider Adapter Notes

    kunchenguid/quota-axi

    Reference of credential sources, quota windows, endpoint shapes, error recovery and quirks for each provider supported by the quota-axi tool.

    146 GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Quota Interpretation Rules

    kunchenguid/quota-axi

    Specifies how quota-axi reads LLM subscription quota windows, derives pace and runway, computes a selection signal and renders output in TOON, JSON and TUI tiers.

    146 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Quota Axi

    kunchenguid/quota-axi

    Report local Claude, Codex, Cursor, GitHub Copilot, Grok, Kimi, Z.AI, Alibaba, OpenCode Go, Antigravity, Command Code, MiniMax, MiMo, DeepSeek, OpenRouter, ElevenLabs, Devin, Muse, and Higgsfield…

    146 GitHub stars~547 tokensUpdated today
    Auto-check passed

Categories

Questions about Quota Provider Onboarding

What does Quota Provider Onboarding do?

Sets the rules and checklist for adding a new quota provider, or changing an existing adapter, in quota-axi, covering credential sources, liveness probes and tests. This skill is the project's rulebook for adding quota providers or modifying provider adapters in quota-axi.AI adapter is the single credited exception.

When should I use Quota Provider Onboarding?

Quota Provider Onboarding fits situations like: adding support for a new quota provider to quota-axi; modifying an existing provider adapter's credential lookup or refresh logic; reviewing a provider pull request against the project's credential and proxy rules; deciding how to classify a credential that is stored but expired.

How do I install Quota Provider Onboarding in Claude Code?

Run `npx skills add kunchenguid/quota-axi --skill provider-onboarding -a claude-code`. Or copy the skill folder (skills/provider-onboarding in kunchenguid/quota-axi) into .claude/skills/provider-onboarding in your project. Claude Code loads it when a task matches its description.

How do I install Quota Provider Onboarding in Codex?

Run `npx skills add kunchenguid/quota-axi --skill provider-onboarding -a codex`. Or copy the skill folder (skills/provider-onboarding in kunchenguid/quota-axi) into .agents/skills/provider-onboarding in your project. Codex loads it when a task matches its description.

Can I use Quota Provider Onboarding in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kunchenguid/quota-axi --skill provider-onboarding -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/provider-onboarding, .gemini/skills/provider-onboarding, .github/skills/provider-onboarding and .opencode/skills/provider-onboarding in your project.

What does Quota Provider Onboarding need to run?

Going by SKILL.md and its folder, Quota Provider Onboarding needs the command-line tools its instructions call (claude). Our summary lists: A checkout of the quota-axi repository.

Does Quota Provider Onboarding access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Quota Provider Onboarding safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Quota Provider Onboarding use?

Quota Provider Onboarding is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Quota Provider Onboarding use?

About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Quota Provider Onboarding?

Skills that share tags, products or a category with Quota Provider Onboarding: Passport Development (trypostit/trypost, 685 stars), Soundcloud API Integration (soundcloud/api, 259 stars), MCP API Key Authentication (Yourdaylight/stock_datasource, 189 stars) and OmniRoute API Keys (diegosouzapw/OmniRoute, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Quota Provider Onboarding?

kunchenguid (a GitHub user) maintains it in kunchenguid/quota-axi, which has 146 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 9, 2026.

Source: kunchenguid/quota-axi on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.