# Set up coda0

You are helping the user connect their coding agent to coda0. coda0 is an account-based workspace for publishing and managing self-contained HTML/Markdown artifacts. It uses the Open Artifacts publishing skill and CLI.

Follow these steps in order. Do not make global changes or handle credentials without the user's consent. Pause when the user needs to complete OAuth in a browser, or when a step fails.

---

## Step 1: Check prerequisites

The skill CLI requires Node.js 22 or newer. Check it before continuing:

```bash
node --version
```

If Node.js is unavailable or older than 22, stop and tell the user how to install or upgrade it.

---

## Step 2: Install the skill

Install the `using-open-artifacts` skill for the coding agent. Prefer project scope so the change is limited to the current project:

```bash
npx skills add coda0HQ/open-artifacts -s using-open-artifacts
```

Only install it at user scope after the user explicitly agrees:

```bash
npx skills add coda0HQ/open-artifacts -s using-open-artifacts -g
```

The skill contains the workflow for designing, validating, publishing, updating, and password-protecting artifacts. Do not silently install a global skill or a source-control hook.

---

## Step 3: Point the skill at this coda0 instance

Use the origin from which this file was fetched: remove `/install.md` and any following path from its URL. For example, if this file came from `https://coda0.com/install.md`, use `https://coda0.com`.

Set the URL for the current shell:

```bash
export OPEN_ARTIFACTS_URL="<instance-origin>"
```

Or save it in the project configuration at `.artifacts/config.json`:

```json
{
  "apiUrl": "<instance-origin>"
}
```

Replace `<instance-origin>` with the actual origin before running commands. Do not put API keys in prompts, source files, or committed configuration.

---

## Step 4: Check that coda0 is reachable

```bash
curl --fail --silent --show-error "<instance-origin>/health"
```

Replace `<instance-origin>` with the same actual origin used in Step 3. The response should be `{"ok":true}`. If the request fails, stop and report the URL and HTTP error instead of attempting to publish.

---

## Step 5: Sign in before publishing

coda0 is a login-gated SaaS instance. A create token is not a substitute for coda0 login. From the installed skill's `scripts` directory, run:

```bash
node artifact.mjs login --provider google
```

Use `--provider github` for GitHub, or omit `--provider` to choose a provider on the coda0 login page. The CLI attempts to open coda0 in a browser and prints the callback URL it is waiting for. If no browser window appears, open that exact URL manually; do not start a second login command while the first one is waiting. The user must complete OAuth and return to the callback page before the command finishes. The CLI then stores the long-lived `sk_` API key in the local, gitignored `.artifacts/credentials.json` file. Never print, copy, or commit that key.

Confirm the authenticated identity:

```bash
node artifact.mjs whoami
```

The command should print the signed-in email or name. If login or `whoami` fails, or `whoami` prints `unknown`, stop and report the exact output. Do not ask the user for `CREATE_TOKEN` or `OPEN_ARTIFACTS_TOKEN` for coda0.

---

## Step 6: Hand off publishing

coda0 is ready. Follow the installed `using-open-artifacts` skill for the rest of the workflow and run its bundled CLI with `node artifact.mjs`. New artifacts default to private; choose `org` or `public` explicitly in the Recipe when appropriate, and use `--password` for client-side password protection.

The skill can watch source files and report stale artifacts. It does not silently republish content: review the change and run `update` when the artifact should change. Ask the user before installing the optional staleness hook or enabling automatic updates.
