████ ███ ██ ████ ████ ████ ▒▒██ ██▒ ▒▒ ▒▒██ ▒▒██ ▒▒██ ▒██ ██ ███ ██████ █████ ▒██ ▒██ ██████ ▒██ ████ ▒█████ ▒▒██ ▒▒██▒▒█ ██▒▒██ ▒██ ▒██ ▒▒██▒▒█ ▒██▒▒██ ▒██▒▒██ ▒██ ▒██ ▒ ▒██ ▒██ ▒██ ▒██ ▒██ ▒▒ ▒█████ ▒██ ▒▒██ ▒██ ▒██ ▒██ ▒██ ▒██ █ ▒██ ▒██ ██ ▒██▒▒██ ███ ▒▒█████ ████ ▒▒█████ ███████▒█ ████ ███▒███ ███ ████ ▒▒▒ ▒▒▒▒▒ ▒▒▒▒ ▒▒▒▒▒ ▒▒▒▒▒▒▒ ▒ ▒▒▒▒ ▒▒▒ ▒▒▒ ▒▒▒ ▒▒▒▒
kirolink is a small Go CLI that reads Kiro auth tokens from your local SSO cache, then exposes an Anthropic-shaped local API so tools like Claude Code can talk to it without a bunch of manual bullshit.
In practice: your client sends POST /v1/messages to this proxy, the proxy translates the request to AWS CodeWhisperer, sends it to the CodeWhisperer API, and translates the response back on the way out.
- Reads tokens from
~/.aws/sso/cache/kiro-auth-token.json - Prints shell-ready
ANTHROPIC_*environment variable setup - Starts a local server on port
8080by default - Exposes these endpoints:
POST /v1/messagesGET /v1/modelsGET /health
- Includes a
claudehelper command that edits~/.claude.json
🔍 Troubleshoot: Token Not Found
If you get a "file not found" error, ensure you've run the Kiro login first.
Default path: ~/.aws/sso/cache/kiro-auth-token.json
go build -o kirolink kirolink.goThis tool expects a token file at:
~/.aws/sso/cache/kiro-auth-token.json
If you want to sanity-check that file first:
./kirolink readHeads-up: read prints both the access token and refresh token, so maybe don't paste that shit into screenshots.
On macOS/Linux, you can eval the output directly:
eval "$(./kirolink export)"On Windows, the command prints both CMD and PowerShell variants for you to copy:
./kirolink exportBy default this sets:
ANTHROPIC_BASE_URL=http://localhost:8080ANTHROPIC_API_KEY=<current access token>
./kirolink serverCustom port:
./kirolink server 9000Note: Make sure your server proxy is running before using Claude Code with kirolink.
If you use a custom port, set ANTHROPIC_BASE_URL manually — the export command always prints http://localhost:8080.
Claude Code and other Anthropic-compatible clients can use the exported env vars. You can also hit the proxy directly:
curl -X POST http://localhost:8080/v1/messages \
-H "Content-Type: application/json" \
-d '{"model":"claude-sonnet-4-5-20250929","messages":[{"role":"user","content":"Hello"}],"max_tokens":256}'| Command | What it does |
|---|---|
./kirolink read |
Reads and prints the cached token data. |
./kirolink refresh |
Refreshes the token using the stored refresh token and writes the updated file back to disk. |
./kirolink export |
Prints environment variable commands for the current OS/shell style. |
./kirolink claude |
Updates ~/.claude.json and sets hasCompletedOnboarding=true plus kirolink=true. |
./kirolink server [port] |
Starts the local Anthropic-compatible proxy server. |
When the server is running, these routes are available:
POST /v1/messages— main Anthropic-compatible message endpointGET /v1/models— returns the currently exposed model aliasesGET /health— returnsOK
Example:
curl http://localhost:8080/v1/modelsThe proxy currently exposes multiple Anthropic-style aliases, including:
defaultclaude-sonnet-4-6claude-sonnet-4-5claude-opus-4-6claude-haiku-4-5-20251001claude-4-sonnetclaude-4-opus
If you want the full live list, ask the running server with GET /v1/models.
- Read the token from your local Kiro SSO cache.
- Accept Anthropic-style requests over HTTP.
- Translate them into the backend request format.
- Send them to
https://codewhisperer.us-east-1.amazonaws.com/generateAssistantResponse. - Translate the response back into Anthropic-style JSON or SSE.
OpenClaw is an open-source AI assistant framework that supports multiple LLM providers. You can configure it to use this proxy as a custom Claude provider.
Add a custom provider to your openclaw.json or environment config:
{
"providers": {
"kiro-claude": {
"api": "anthropic-messages",
"baseURL": "http://localhost:8080",
"apiKey": "<your-kiro-token>"
}
}
}Build:
go build -o kirolink kirolink.goRun tests:
go test ./...Run protocol tests only:
go test ./protocol -v- This tool depends on a local Kiro token file already existing.
refreshwrites back to~/.aws/sso/cache/kiro-auth-token.json.claudemodifies~/.claude.json; that's convenient, but it's still changing your config, so don't run it blindly.- The documented export path is hardcoded to
http://localhost:8080. - The upstream CodeWhisperer endpoint is hardcoded to
https://codewhisperer.us-east-1.amazonaws.com/generateAssistantResponse.
| Feature | Supported natively | Handled by kirolink |
Notes |
|---|---|---|---|
| Standard Messaging | ❌ | ✅ | Translated cleanly |
| Streaming (SSE) | ❌ | ✅ | Handled dynamically |
| Local Auth | ❌ | ✅ | Auto-reads AWS SSO cache |
| Tool Use | ❌ | ✅ | Tool-use/Mcp |
|
Alexandephilia Vibing |
![]() Claude Implementation |
Jules Planning |

