{"id":18892,"plugin_id":"plugins_6a8d98ca44208191890b95adc160558c","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:15:01.297Z","digest":"faf38458a888e412d5321e3c3ff24171a39529416b4fa8d57ecf74cf947ccb3f","against":null,"payload":{"description":"Install, upgrade, detect, and authenticate the Baseten CLI on a local Codex Desktop host, then install Baseten's official skill globally. Use when the Baseten CLI is missing, `baseten` is not on PATH, a Baseten profile or credential is not configured, authentication fails, the global Baseten skill is missing, or the user asks to set up Baseten before model API, deployment, or monitoring work.","included_files":[{"relative_path":"agents/openai.yaml","size_in_bytes":285}],"name":"onboard-baseten","skill_md_contents":"---\nname: onboard-baseten\ndescription: Install, upgrade, detect, and authenticate the Baseten CLI on a local Codex Desktop host, then install Baseten's official skill globally. Use when the Baseten CLI is missing, `baseten` is not on PATH, a Baseten profile or credential is not configured, authentication fails, the global Baseten skill is missing, or the user asks to set up Baseten before model API, deployment, or monitoring work.\n---\n\n# Baseten Setup\n\nPrepare the current local Codex Desktop host for general Baseten work. Keep credential entry in Baseten's browser flow, make no deployment during onboarding, and hand workload-specific work to Baseten's globally installed official skill.\n\n## Check existing tools\n\nDetect whether the host shell is POSIX-compatible or PowerShell, then use the matching commands throughout this skill.\n\nOn a POSIX-compatible shell, run:\n\n```bash\ncommand -v brew || true\ncommand -v npx || true\nif command -v baseten >/dev/null 2>&1; then\n  baseten version\nfi\n```\n\nOn PowerShell, run:\n\n```powershell\nGet-Command npx -ErrorAction SilentlyContinue\n$basetenCommand = Get-Command baseten -ErrorAction SilentlyContinue\nif ($null -ne $basetenCommand) {\n    baseten version\n}\n```\n\nPreserve an existing Baseten CLI installation when `baseten version` succeeds. If the user explicitly asks for an upgrade and the CLI was installed with Homebrew, explain that it changes the host, obtain any approval required by the execution environment, run `brew update && brew upgrade baseten`, and verify the version again.\n\nThe Baseten CLI is in beta and under active development; commands and flags may change. If a documented command fails unexpectedly, fetch the current CLI reference at `https://docs.baseten.co/reference/cli/baseten/overview` rather than guessing.\n\nBaseten's documented installation on macOS and Linux uses Homebrew. If `brew` is unavailable on those platforms, explain that prerequisite and stop before changing the host; offer the documented manual binary install from Baseten's GitHub releases only when the user explicitly chooses it. On Windows, the manual binary install is the documented path (see the next section). Installing Baseten's official skill requires Node.js and `npx`. If `npx` is unavailable, finish any valid Baseten CLI checks, report the missing prerequisite, and stop before skill installation.\n\n## Install the Baseten CLI\n\nOnly reach this section when `baseten version` failed. Explain that this step installs the Baseten CLI and obtain any approval required by the execution environment.\n\nOn macOS or Linux with Homebrew, run:\n\n```bash\nbrew tap basetenlabs/baseten\nbrew install baseten\n```\n\nOn Windows, or when the user explicitly chooses a manual install, download the `baseten` archive for the host platform from `https://github.com/basetenlabs/baseten-cli/releases`, extract the binary, and place it on `PATH`. Do not pipe release archives through `sudo` without showing the user the exact command first.\n\nThen run `baseten version`. If the command remains unavailable, explain that the install directory is not on `PATH`. Do not edit shell startup files unless the user asks.\n\n## Install the official Baseten skill\n\nFirst check whether the skill is already installed:\n\n```bash\nnpx skills list -g -a codex\n```\n\nIf the result includes the `baseten` skill, preserve the existing installation and skip the install command; do not reinstall or overwrite a version the user may have pinned. If the user explicitly asks to update the skill, explain that it refreshes the global copy from the source repository, obtain any approval required by the execution environment, run `npx skills update baseten -g -y`, and verify with `npx skills list -g -a codex` again.\n\nOnly when the `baseten` skill is absent: explain that this step downloads Baseten's current official skill from its source repository, `basetenlabs/baseten-skills` on GitHub, and writes it to the user's global Codex skill directory. Obtain any approval required by the execution environment, then run:\n\n```bash\nnpx skills add basetenlabs/baseten-skills -g -a codex -y\n```\n\nDo not vendor or copy the downloaded skill into this plugin. Verify the installation by running `npx skills list -g -a codex` again and confirming that the result includes the `baseten` skill. If it is not available in the current Codex task, tell the user to start a new task or refresh skill discovery before using it.\n\n## Allow Baseten network access in Codex\n\nBaseten CLI commands that authenticate, inspect, or mutate Baseten cloud state require external network access. Use Codex's normal network approval or escalation mechanism when required. If an API-backed command stalls because egress is blocked, stop it and retry after access is approved; do not treat blocked egress as invalid credentials or bypass the network policy.\n\n## Authenticate\n\nThe Baseten CLI stores each credential as a named profile, selected per command with `--profile` or the `BASETEN_PROFILE` environment variable, or set as default with `baseten auth switch`.\n\n1. Check the resolved authentication state without printing or reading credential values by running `baseten auth status`. If it reports a valid profile, preserve the existing credential and continue to verification.\n2. If no profile is configured or the credential is invalid, run `baseten auth login`. In a non-TTY environment, run `baseten auth login --web` to use browser login without interactive prompts.\n3. Tell the user that the CLI will open or print a browser verification URL (OAuth device flow) and that they must complete sign-in themselves. Pause while that human interaction is required. Browser logins name the profile after the user's email.\n4. For a non-default profile or remote, add `--profile NAME` or `--remote-url URL` only after the user names or confirms the intended target.\n\nDo not ask the user to paste an API key into chat. Do not place `BASETEN_API_KEY` in command arguments, inspect the system keyring or Baseten config directory, or reproduce user, organization, token, or credential values in logs or final responses. Browser OAuth is the default for local onboarding. If the user explicitly requires API-key authentication, use `baseten auth login --with-api-key --profile NAME`, which reads the key from stdin or an interactive prompt, never from chat. A later inference workflow may use an already exported `BASETEN_API_KEY`, but must never echo or commit it.\n\n## Verify configuration\n\nAfter authentication, run read-only checks for the active profile:\n\n```bash\nbaseten version\nbaseten auth status\nbaseten whoami\n```\n\n`baseten auth status` identifies the resolved profile, remote URL, and auth type without revealing the credential. `baseten whoami` verifies management API access. Report only the CLI version, profile name, auth type, and whether read-only verification succeeded; omit the user identity and credential storage details.\n\nDo not create, deploy, promote, stop, or delete a model merely to test authentication. These operations can change cloud state or consume billed compute and require a separate explicit user request.\n\n## Hand off\n\nReport the Baseten CLI version, whether Baseten's official global skill was installed, the verified profile name, and whether read-only access succeeded. Then continue with the globally installed Baseten skill for Model APIs, deployment, development, monitoring, Chains, or training work. Note that authoring Chains, Training jobs, and Loops still uses the separate Truss CLI per Baseten's documentation; install it only when such a workload is actually requested. Fetch current Baseten documentation rather than relying on stale commands, confirm the target workspace before mutations, and obtain explicit approval before starting billed compute.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}