Skip to main content
Experimental. Engine 0.120.1 ships the adapters in the default CLI build (default = ["access-harness"] in nika-cli at v0.120.1). You still need the harness installed and signed in, and a model: that seat can serve. nika doctor listing a CLI is detection, not a completed generation. Retired ACP wrapper ids (claude-agent-acp · codex-acp) refuse with NIKA-1802.
model: picks the intelligence. Access picks the path the run takes to reach it — an API key, a local server, the mock, or a harness you already pay for. The same infer: / agent: task is admitted onto that path with a witness. Unsatisfied pins refuse (NIKA-1801 · NIKA-1803); they never silently fall back to a metered key.

What you need

The harness, signed in the way IT expects. Nika never holds its credential. Seats on 0.120.1: Classes also pin: local · mock · harness · oauth · api.

Run it

The authority bridge

The harness asks before it acts. Nika answers with your workflow’s permits: block, not with the harness’s defaults:
  • Inside your grants — the ask is allowed once (never “allow always”) and the decision is witnessed in the trace.
  • Outside them — the run pauses and shows you the harness’s question, word for word. Answer once with nika run --resume <trace> --answer <task>=true (or false). Nothing the harness asked for runs before you answer.

The honest receipt

A harness run’s trace row says access: harness and billing: unknown — because your plan’s quota is the harness’s business until the harness itself reports it. What you will never see is a fabricated $0.00: the ledger records the lane as subscription_quota, priced when evidence exists, absent when it doesn’t.

Kill-switch

One adapter refusing to behave? Take it off the machine without touching the rest:
A disabled adapter is no candidate at all — a pin naming it refuses in plain words.