Kiro CLI
Operating Kiro CLI on workers — login or KIRO_API_KEY, stream-json output, why a missing login waits, and what it cannot do.
Install
curl -fsSL https://cli.kiro.dev/install | bashcurl -fsSL https://cli.kiro.dev/install | bashThe worker looks for kiro-cli on the worker user's PATH.
Sign-in
Run kiro-cli login once as the worker's user, or put KIRO_API_KEY in the task's environment profile (Kiro's
documentation says the key is available on its paid plans). Do one of them before the first task: without a
key or login Kiro CLI starts a browser login and waits, even in a headless run. The worker reports
authentication required as soon as that line appears, but the process ends only when the hang timeout stops
it. A rejected key ends the run with "The bearer token included in the request is invalid".
How it runs
kiro-cli chat --no-interactive --trust-all-tools --output-format stream-json [--model <model>] <prompt>
--trust-all-toolslets it use its tools without confirmation; without it a headless run cannot edit files.stream-jsongives the run's events as JSON lines; the worker takes the session id and errors from them.- Kiro CLI has no Windows build. The adapter was checked in a Linux container.
Add-on models
Kiro CLI cannot use add-on models or providers configured on the worker. When it reaches its limit, the task moves to another compatible agent, or waits, as the fallback policy says.
Sessions
Resume is not claimed for Kiro CLI: no resume command could be verified without an account. After a crash, recovery starts a fresh session from the checkpoint.
What was verified
Checked against Kiro CLI 2.27.1 on 2026-10-06 in a Linux container (there is no Windows build): its --help, a
run with a rejected key and a run without a login. A task with a Kiro account has not been run, so the events of
a successful run follow the ACP format Kiro documents.