Account commands
None of the commands on this page runs today. They belong to kaleidoscope, a
second executable built from source and published on no channel, and the account
service they would reach answers provider not configured. They are written
down so you can see the shape of signing in before it arrives.
kscope, the command you have, carries no account commands at all.
What there is instead
Section titled “What there is instead”The alpha is opened by a key, not by an account. Email contact@kleosresearch.xyz for one, then:
kscope activateactivate takes the key as an argument, from KALEIDOSCOPE_API_KEY, from the
key file, or from standard input. It stores the key at the path kscope gate
prints, so an engine your editor starts with an empty environment still finds
it, and it waits for the verdict rather than leaving the next command to
discover an empty cache.
You do not need an account to use Kaleidoscope. Your memory lives on your machine and has never needed one.
Sign in and out
Section titled “Sign in and out”kaleidoscope loginkaleidoscope login --devicekaleidoscope status --jsonkaleidoscope logoutkaleidoscope logout --all-deviceskaleidoscope logout --local-only| Command | What it would do |
|---|---|
login | Ordinary browser sign-in. |
login --device | Code-based sign-in, for a machine with no browser. |
status --json | Report your account session on this machine. Unrelated to the status page, which is about what is available. |
logout | Remove the credential here and revoke it. |
logout --all-devices | End every session on the account. |
logout --local-only | Remove the local credential and warn you that nothing was revoked remotely. |
No form of logout changes which profile a command resolves to, or a byte of
your vault.
Linked sign-in providers
Section titled “Linked sign-in providers”kaleidoscope account link PROVIDERkaleidoscope account identitieskaleidoscope account unlink EXTERNAL_IDENTITY_UUIDkaleidoscope account revoke-session| Command | What it would do |
|---|---|
account link PROVIDER | Attach a sign-in provider to the account. |
account identities | List the opaque IDs, which is where unlink gets its argument. |
account unlink UUID | Detach one of them. |
account revoke-session | Revoke the session you are using. It does not deactivate an account. |
Devices
Section titled “Devices”kaleidoscope devices listkaleidoscope devices revoke DEVICE_UUIDThe devices attached to your account, and how to detach one. Revoking a device is an account operation; the vault on that device is untouched.
Local account reference
Section titled “Local account reference”kaleidoscope profile account showkaleidoscope profile account bind ACCOUNT_UUIDkaleidoscope profile account unbindThese three write a non-secret account ID into a local profile and nothing more: no engine started, no service contacted, no vault touched, no credential stored. Each takes an optional profile name and defaults to the one you are in.
The boundary
Section titled “The boundary”Account traffic goes to a closed list of account-only routes and never touches the memory engine. A guard rejects memory fields, profile fields and absolute local paths before anything is sent.
Account and devices covers what signing in would mean and where a credential would be kept.