Set up, authenticate, and run external coding agents (Claude Code, Codex) via the Agent Client Protocol

MITAuto-check passed

Install Acp

skills CLI
$ npx skills add vellum-ai/vellum-assistant --skill acp -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vellum-ai/vellum-assistant acp --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vellum-ai/vellum-assistant.git skills-src && mkdir -p .claude/skills && cp -r skills-src/assistant/src/config/bundled-skills/acp .claude/skills/acp && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
acp
GitHub stars
1.4k
Token cost
~2.9k tokens
SKILL.md length
1,670 words
Files
7
Skills in repo
108
Repo updated
First seen
Licence
MIT

At a glance

Set up, authenticate, and run external coding agents (Claude Code, Codex) via the Agent Client Protocol

  • Works in 2 steps: Install the adapter binary if it's… → Call acp_spawn. Do NOT run vellum sleep…
  • SKILL.md covers Usage, Choosing a model, When the user names Claude… and First-time setup, plus 9 more sections
  • Runs TypeScript scripts from its folder; calls claude, bun and codex; needs CLAUDE_CODE_OAUTH_TOKEN and CODEX_API_KEY

What it does

Acp is an agent skill from vellum-ai/vellum-assistant. Set up, authenticate, and run external coding agents (Claude Code, Codex) via the Agent Client Protocol

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files (for example `TOOLS.json`, `tools/acp-abort.ts` and `tools/acp-list-agents.ts`). Compatibility notes: Designed for Vellum personal assistants

The repository describes itself as: An AI Assistant that’s easy to setup, does your work 24/7, knows your preferences and gets better over time. The licence is MIT.

Example prompts

  • “/acp”

Requirements

  • Node.js
  • A credential in CLAUDE_CODE_OAUTH_TOKEN
  • A credential in CODEX_API_KEY
  • Compatibility (from SKILL.md): Designed for Vellum personal assistants

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. Install the adapter binary if it's missing. This happens automatically: when acp_spawn finds the agent's binary missing from PATH, the…
  2. Call acp_spawn. Do NOT run vellum sleep && vellum wake - that kills the conversation.

What it can do on your machine

Read from SKILL.md and the folder at commit 33cc983. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (TypeScript), which the agent can run.

    Shell commands in SKILL.md call:

    • claude
    • bun
    • codex

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CLAUDE_CODE_OAUTH_TOKEN
    • CODEX_API_KEY
    • OPENAI_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Vellum personal assistants

    From compatibility in the SKILL.md frontmatter.

Context cost

Acp loads about 2.9k tokens when it runs. Until then it costs about 27 tokens; SKILL.md has 1,670 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~27
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vellum-ai/vellum-assistant at commit 33cc983, republished under its MIT licence (© vellum-ai). 1,670 words, ~2,905 tokens.

Download SKILL.mdSave it as .claude/skills/acp/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
acp
description
Set up, authenticate, and run external coding agents (Claude Code, Codex) via the Agent Client Protocol
compatibility
Designed for Vellum personal assistants
metadata.emoji
🔗

ACP agent orchestration - spawn external coding agents (Claude Code, Codex) to work on tasks via the Agent Client Protocol. Each agent runs as its own subprocess speaking ACP over stdio and streams results back into the conversation.

Usage

Use acp_spawn to delegate a coding task to an external agent. The agent runs as a subprocess speaking the ACP protocol over stdio and streams results back.

Users can refer to agents by natural names: "claude code", "codex cli", and "openai codex" all resolve to the canonical claude and codex ids (unless the user's config defines an agent literally keyed by that name, which always wins).

Choosing a model

Claude runs on Opus unless the user names a model; every other agent starts on its own default.

When the user does name one, pass it as model on acp_spawn. Model names are the agent's own vocabulary, not Assistant model ids: an alias such as default, sonnet, opus, haiku, fable, or opusplan for Claude, or a full model id. Pass what the user said and let the agent resolve it.

The spawn result reports requestedModel and effectiveModel. Treat effectiveModel as authoritative for the top-level ACP session. Never infer that model from the task text or from a nested subagent. When requestedModel is non-null and differs from effectiveModel, state which model the session is actually running on and relay modelWarning when present.

If the agent refuses the model, or advertises no model selector, the spawn result says so: relay it in one sentence and carry on, because the session is live on the agent's own model.

A session runs on the model it started on, so a different model means a new acp_spawn. A standing default per agent lives in the config at acp.agents.<id>.model.

When the user names Claude Code or Codex

If they name Claude Code or Codex without asking you to run it here (for example they say that tool will do the work), offer once, in one short sentence, that you can connect and run it in this conversation. Then continue with whatever they were doing.

  • Do not spawn unless they accept.
  • Skip if you already offered this conversation, they declined, or they are already connected.
  • This is not the missing-token card path. Do not invent setup steps.

First-time setup

ACP is always available - default profiles for claude and codex ship out-of-box, so no config edit is needed to start. First-time setup is just making the adapter binary available, then spawning:

  1. Install the adapter binary if it's missing. This happens automatically: when acp_spawn finds the agent's binary missing from PATH, the assistant installs the pinned version via a sandboxed bun global install and proceeds in the same call (see "Automatic adapter availability" below).

  2. Call acp_spawn. Do NOT run vellum sleep && vellum wake - that kills the conversation.

Automatic adapter availability

When an agent's binary is missing from PATH, the assistant installs the adapter version it was built against via a sandboxed bun global install and then runs the real installed binary. The install runs in a fresh empty temporary directory (never the task's project directory), with known secrets stripped from the installer environment and the registry pinned to the public npm registry, so a malicious project directory cannot hijack package resolution or capture a token.

An adapter already on PATH is left alone, whoever installed it: the install runs only when preflight found no binary at all.

Only the allowlisted out-of-box packages are ever installed this way (@agentclientprotocol/claude-agent-acp, @agentclientprotocol/codex-acp); user-configured agents with custom commands are never installed automatically.

Manual installation is fallback guidance for unusual setups: bun unavailable, restricted global installs, or an auto-install failure (the failure reason is surfaced in the tool result). Install the pinned version below rather than @latest, so the adapter matches what the assistant was built against.

bash
bun add -g @agentclientprotocol/claude-agent-acp@0.75.1   # claude
bun add -g @agentclientprotocol/codex-acp@1.10.0          # codex

Claude setup

The claude-agent-acp adapter requires a Claude OAuth token (sk-ant-oat…), NOT an API key (sk-ant-api…). Every spawn injects the stored token as CLAUDE_CODE_OAUTH_TOKEN automatically. The write path rejects an API key in this field, so never direct a user to paste an sk-ant-api… key here.

Primary: the in-app Connect Claude Code flow. When a spawn fails because the token is missing, the UI automatically renders an inline "Connect Claude Code" card for the failed step — one click on desktop (loopback), one paste on cloud. The card restores itself after a reload or reconnect, so it stays available. It mints and stores the OAuth token so it never enters the conversation or the workspace config.

When a spawn fails for a missing token, do NOT prompt or instruct the user yourself. The inline card already handles it, and the task auto-continues once they connect — so you don't need them to re-ask. Specifically, do NOT tell them to run claude setup-token, run assistant credentials set/prompt, open a terminal, or paste an sk-ant-oat… token — and do NOT retry the spawn yourself. Add at most one short sentence pointing at the card ("Click Connect Claude Code to sign in — I'll pick it back up once you're connected"), then stop and wait. Keep it terse and never say where the card is (no "above"/"below"/"at the bottom" — its placement is a UI detail you can't see): do not narrate that a card appeared, explain how the sign-in works, or say "nothing to paste" (the cloud flow does paste a key).

Fallback (headless environments where no inline card can appear): the user runs claude setup-token on a machine where they are logged in to Claude, then stores the result via the secure prompt:

bash
assistant credentials prompt --service acp --field claude_oauth_token --label "Claude OAuth Token"

This is strictly for headless/channel sessions. In an interactive session the daemon refuses this prompt for acp/claude_oauth_token and returns a message pointing at the inline Connect card, so do not run it to work around the card — just wait for the user to connect.

Do NOT ask the user to paste the token into chat — the secure prompt keeps it out of the conversation and the workspace config.

Show full SKILL.md (683 more words)Show less

Codex setup

The @agentclientprotocol/codex-acp adapter runs Codex App Server using its included @openai/codex dependency.

Authenticate. The adapter reuses an existing Codex login. To sign in, use codex login from an installed Codex CLI. API-key authentication supports CODEX_API_KEY and OPENAI_API_KEY.

Optional CLI override. Set CODEX_PATH in the agent profile's env to use a different compatible Codex executable. Keep the agent command as codex-acp.

Do NOT put API keys (or any secret) in the workspace config file - secrets never belong in the workspace directory. Use the credential store instead.

Critical: correct agent command

  • Two agents are supported out-of-box: claude (via the claude-agent-acp adapter) and codex (via the codex-acp adapter).
  • NEVER use claude, claude -p, claude --acp, or the bare codex CLI as the ACP command. Claude and Codex only speak the protocol through their dedicated *-acp adapters.
  • Default profiles for both ship out-of-box. Users only need an agents.<id> entry in config if they want to override the defaults (e.g. point to a custom binary path or pass extra args/env). An entry that still runs the bundled adapter, whether it omits command or names the same binary by name or full path, inherits the command, description and model it leaves out, so a single-field change such as acp.agents.claude.model is all it takes. An entry that points the id at a different binary stands on its own, so it must spell out everything it needs, command included.
  • NEVER change an existing ACP config to use a different command. If the config already has claude-agent-acp or codex-acp, leave it alone.

Updating an adapter

Adapter upgrades ship with Assistant releases: the pinned version is what a missing adapter is installed at. An adapter already on PATH is never replaced, so a user who upgrades one themselves keeps that version.

Codex uses the adapter's bundled dependency by default, within the version range declared by the adapter. If CODEX_PATH selects a separate CLI, update that installation separately.

When to use acp_steer vs acp_spawn

  • On a running session, acp_steer interrupts the in-flight prompt. Use it to course-correct ("stop, do X instead"). It cancels whatever the agent is currently working on and replaces it with the new instruction. Queued follow-ups behind a running prompt are not supported - wait for the acp_session_completed notification instead.
  • On a completed (or assistant-restarted) session, acp_steer transparently resumes it. The session is restored from persisted history via ACP session loading when the agent supports it, and the new instruction runs with the agent's full prior context. This is the primary way to do follow-up work on an existing session id - prefer it over spawning a fresh session that would lose context.
  • If resume isn't possible (the session was recorded before resume support and has no working directory, or the agent lacks the capability), the error explains why; fall back to acp_spawn. For claude sessions, the completion message also includes a claude --resume <id> CLI hint for resuming outside the assistant.

Discoverability

Use acp_list_agents to see what's set up and what's missing. It returns each available agent profile, whether the agent's binary is on PATH (missing binaries are installed automatically on first spawn), and an install hint if not. This is the right tool to call when deciding between claude and codex, or when the user asks "what coding agents do I have?"

Working directory

Default to the conversation's current working directory when spawning an agent. For risky changes or parallel work where you don't want the agent touching the same checkout the user is editing, create a git worktree first via the shell tool and pass that worktree path as cwd to acp_spawn. That keeps the agent isolated from the user's in-progress work.

Tips

  • The spawned agent runs autonomously with its own tools, file editing, and terminal access.
  • Results are streamed back and injected into the conversation when the agent completes.
  • Use acp_status to inspect running and idle agents. Use acp_steer to attempt follow-up work on an idle session; do not replace it with a new acp_spawn.
  • The cwd parameter controls where the agent works - set it to the project root the user wants the agent to operate in.

© vellum-ai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files in assistant/src/config/bundled-skills/acp of vellum-ai/vellum-assistant.

  • SKILL.md
  • TOOLS.json
  • tools/acp-abort.ts
  • tools/acp-list-agents.ts
  • tools/acp-spawn.ts
  • tools/acp-status.ts
  • tools/acp-steer.ts

Open the folder on GitHubat commit 33cc983

Compare with similar skills

Acp next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Acp compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Acp this skillvellum-ai/vellum-assistant1.4k—~2.9kAutomated safety check: PassMIT
Agent Authenticationruvnet/ruflo74k2 repos~711Automated safety check: PassMIT
Acp Routeropenclaw/openclaw392k—~2.4kAutomated safety check: PassMIT
Configuring Multi Factor Authentication With Duomukul975/Anthropic-Cybersecurity-Skills34k—~1.6kAutomated safety check: PassApache-2.0
AuthenticationBuilderIO/agent-native7.1k—~7.1kAutomated safety check: NotesNone
Accessible Authentication Reviewthedaviddias/Front-End-Checklist74k—~579Automated safety check: PassMIT

Similar skills

  • Agent skill for authentication - invoke with $agent-authentication

    74k GitHub starsUsed in 2 repos~711 tokens
    Backend & APIsAuto-check passed
  • Acp Router

    openclaw/openclaw

    Route plain-language requests for Claude Code, Cursor, Copilot, OpenClaw ACP, OpenCode, Gemini CLI, Qwen, Kiro, Kimi, iFlow, Factory Droid, Kilocode, or explicit ACP harness work into either…

    392k GitHub stars~2.4k tokensUpdated today
    Writing & ContentAuto-check passed
  • Configuring Multi Factor Authentication With Duo

    mukul975/Anthropic-Cybersecurity-Skills

    Deploys Cisco Duo multi-factor authentication across enterprise applications, VPN, RDP, and SSH access points, covering Duo Authentication Proxy setup, adaptive authentication policies, device trust…

    34k GitHub stars~1.6k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Authentication

    BuilderIO/agent-native

    How auth works in agent-native apps. An agent skill from BuilderIO/agent-native.

    7.1k GitHub stars~7.1k tokensUpdated today
    Backend & APIsAuto-check: notes
  • Accessible Authentication Review

    thedaviddias/Front-End-Checklist

    Reviews sign-in, MFA, CAPTCHA and recovery flows for accessibility barriers such as blocked paste, memorized codes and transcription, and suggests fixes.

    74k GitHub stars~579 tokensUpdated 3 days ago
    Frontend & DesignAuto-check passed
  • Authentication

    latitude-dev/latitude-llm

    Sessions, sign-in/sign-up flows, OAuth, magic links, or organization context on the session.

    4.7k GitHub stars~303 tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from vellum-ai/vellum-assistant

All 108 skills in this repo
  • Vellum GitHub App Setup

    vellum-ai/vellum-assistant

    Create and configure a GitHub App so the assistant can push commits, open PRs, and comment under its own bot identity.

    1.4k GitHub stars~3.1k tokensUpdated today
    Auto-check passed
  • Discord App Setup

    vellum-ai/vellum-assistant

    Connect a Discord bot to the assistant via the Discord Gateway with guided application creation and intent configuration

    1.4k GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Sentry App Setup

    vellum-ai/vellum-assistant

    Create and configure a Sentry internal integration so the assistant can manage issues, alerts, and releases under its own identity

    1.4k GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Memory Corpus Ingest

    vellum-ai/vellum-assistant

    Ingest a large dataset into memory as a skimmed map. An agent skill from vellum-ai/vellum-assistant.

    1.4k GitHub stars~3k tokensUpdated today
    Auto-check: notes
  • Plugin Builder

    vellum-ai/vellum-assistant

    A skill your agent uses when the user wants to build, scaffold, ship, or edit a Vellum plugin that bundles multiple surfaces (hooks, tools, skills, and more) into one installable package.

    1.4k GitHub stars~3.1k tokensUpdated today
    Auto-check passed
  • Slack App Setup

    vellum-ai/vellum-assistant

    Connect a Slack app to the Vellum Assistant via Socket Mode.

    1.4k GitHub stars~2.5k tokensUpdated today
    Auto-check: warnings

Questions about Acp

What does Acp do?

Set up, authenticate, and run external coding agents (Claude Code, Codex) via the Agent Client Protocol. Acp is an agent skill from vellum-ai/vellum-assistant.

How do I install Acp in Claude Code?

Run `npx skills add vellum-ai/vellum-assistant --skill acp -a claude-code`. Or copy the skill folder (assistant/src/config/bundled-skills/acp in vellum-ai/vellum-assistant) into .claude/skills/acp in your project. Claude Code loads it when a task matches its description.

How do I install Acp in Codex?

Run `npx skills add vellum-ai/vellum-assistant --skill acp -a codex`. Or copy the skill folder (assistant/src/config/bundled-skills/acp in vellum-ai/vellum-assistant) into .agents/skills/acp in your project. Codex loads it when a task matches its description.

Can I use Acp in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vellum-ai/vellum-assistant --skill acp -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/acp, .gemini/skills/acp, .github/skills/acp and .opencode/skills/acp in your project.

What does Acp need to run?

Going by SKILL.md and its folder, Acp needs TypeScript for the scripts in its folder, the command-line tools its instructions call (claude, bun and codex) and credentials named CLAUDE_CODE_OAUTH_TOKEN, CODEX_API_KEY and OPENAI_API_KEY. Our summary lists: Node.js; A credential in CLAUDE_CODE_OAUTH_TOKEN; A credential in CODEX_API_KEY. Compatibility (from SKILL.md): Designed for Vellum personal assistants.

Does Acp access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Acp safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Acp use?

Acp is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Acp use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Acp?

Skills that share tags, products or a category with Acp: Agent Authentication (ruvnet/ruflo, 74k stars), Acp Router (openclaw/openclaw, 392k stars), Configuring Multi Factor Authentication With Duo (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Authentication (BuilderIO/agent-native, 7.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Acp?

vellum-ai (a GitHub organization) maintains it in vellum-ai/vellum-assistant, which has 1,408 GitHub stars. The repository holds 108 skills in this directory. The repository was last updated on October 9, 2026.

Source: vellum-ai/vellum-assistant on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.