Docs Start here

The KIFF skill for coding agents

The KIFF skill is a SKILL.md file that teaches Claude Code, Codex and similar agents how to work with KIFF. With it installed, an agent can:

  • connect an agent or a remote MCP tool to KIFF, step by step, through the MCP gateway, kiff-guard or the decision API;
  • propose a Card: draft the terms an agent needs (which tool, the most per call, totals per day, hold or refuse, how long a hold waits) and explain each line, for the owner to issue;
  • handle a held call correctly: tell the person it is waiting, retry the identical call with the same kiff_operation_id, and never make the same change another way;
  • find the right place: the KIFF repositories, SDKs, endpoints and doc pages.

It is a plain markdown file, served at kiff.dev/skills/kiff.md. Read it before you install it.

Install it

Claude Code, as a plugin. It adds this skill, the domain skill and the KIFF MCP gateway as a server named kiff:

/plugin marketplace add kiff/kiff-plugins
/plugin install kiff@kiff

Claude Code asks for this agent’s gateway key when you enable the plugin and keeps it in its secure storage (from the agent’s Tools tab, Connect to the KIFF gateway). Leave it empty and the skills still work; the server just does not connect. The skill itself never reads or handles a key. Source: github.com/kiff/kiff-plugins.

Claude Code, the skill only:

mkdir -p ~/.claude/skills/kiff && curl -fsSL https://kiff.dev/skills/kiff.md \
  -o ~/.claude/skills/kiff/SKILL.md

Codex:

mkdir -p "${CODEX_HOME:-$HOME/.codex}/skills/kiff" && curl -fsSL https://kiff.dev/skills/kiff.md \
  -o "${CODEX_HOME:-$HOME/.codex}/skills/kiff/SKILL.md"

Any other agent that reads an instructions file (Cursor, Gemini CLI, Aider, Amp, OpenCode, Windsurf): save the skill as its own file, then point your instructions file at it once.

curl -fsSL https://kiff.dev/skills/kiff.md -o KIFF.md
echo "Read KIFF.md before working with KIFF." >> AGENTS.md

Use your agent’s own instructions file in place of AGENTS.md if it has one (for example GEMINI.md). Start a new session so the agent picks it up. To update, run the curl line again: it overwrites KIFF.md, and the line in AGENTS.md stays as it is.

What to ask

Connect my refund tool to KIFF and give this agent a Card.
What should this agent's Card be? It issues refunds of about 30 euros, about ten a day.
KIFF held my last call. What do I do?

What it will not do

The skill keeps the agent on its side of the Card:

  • It never issues or changes a Card itself. It drafts the terms; the owner issues them in KIFF Cloud. An agent’s key is refused if it tries.
  • It never answers a held call. Only a person on the account who may approve, signed in at app.kiff.dev, can. A “yes” in the chat is not an approval.
  • It never asks for an owner or admin credential, and keeps keys out of files you commit.
  • When KIFF holds or refuses a call, it does not make the same change another way (a direct API call, a shell, a browser). It reports what happened and stops.

It also says plainly that KIFF governs only the calls that go through it, and suggests removing any direct route the agent still has to the same tool.