supported means multi-cli provides working account isolation on that operating system through at least one mode (file overlay, process token, OS-user isolation, or whole-root --isolated); the mode requirements are noted per row. unsupported means no isolation mode works on that OS, and the row says why.
| Adapter | Product | Auth boundary | Shared normal state | Windows | macOS | Linux |
|---|---|---|---|---|---|---|
agy-cli |
Antigravity CLI (agy) | fixed OS credential, separate OS user required | settings/plugins/skills | supported (Windows OS-user isolation; elevated terminal) | unsupported: owned-user Keychain isolation is not proven | unsupported: owned-user Secret Service session is not implemented |
antigravity |
Google Antigravity IDE | fixed OS credential, separate OS user required | none | supported (Windows OS-user isolation; elevated terminal) | unsupported: owned-user GUI/Keychain session is not proven | unsupported: owned-user GUI/Secret Service session is not implemented |
claude-cli |
Claude Code | profile-local .credentials.json |
.claude configuration and conversations |
supported (file overlay) | supported for API-key profiles only; subscription OAuth is unsupported because its fixed Keychain identity is not isolated | supported (file overlay) |
codex |
OpenAI Codex CLI | profile-local auth.json, file credential mode required |
.codex configuration and conversations |
supported (file overlay; file credential store mode) | supported | supported |
codex-gui |
Codex Desktop App | owned Windows user | none | supported (Store AppX activation; first launch elevated) | unsupported; owned-user GUI/Keychain session is not proven | unsupported; no desktop Codex app on Linux |
commandcode |
Command Code | profile-local .commandcode/auth.json |
.commandcode configuration and conversations |
supported (file overlay; use commandcode, bare cmd collides with cmd.exe) |
supported | supported |
copilot-cli |
GitHub Copilot CLI | per-process COPILOT_GITHUB_TOKEN |
Copilot configuration and session state | supported (process token via multi-cli auth set; GH_TOKEN/GITHUB_TOKEN cleared) |
supported | supported |
copilot-vscode |
GitHub Copilot in VS Code | separate OS user (GitHub auth in the OS store) | none | supported (Windows OS-user isolation; elevated terminal) | unsupported: owned-user GUI/Keychain session is not proven | unsupported: owned-user GUI/Secret Service session is not implemented |
cursor |
Cursor Desktop | whole-root profile; no narrow split claimed | none | supported (--isolated whole-root required) |
supported (--isolated whole-root required) |
supported (--isolated whole-root required) |
cursor-cli |
Cursor CLI | per-process CURSOR_API_KEY |
cli-config.json |
supported (process token via multi-cli auth set) |
supported | supported |
gemini-cli |
Gemini CLI | profile-local OAuth/account files | .gemini configuration and conversations |
supported (file overlay) | supported | supported |
grok-cli |
Grok Build CLI | per-process XAI_API_KEY with precedence preconditions |
documented config/sandbox state | supported (process token via multi-cli auth set; the shared config must not pin model.api_key) |
supported | supported |
kimi-cli |
Kimi Code CLI | per-process KIMI_MODEL_API_KEY |
documented config files | supported (process token via multi-cli auth set) |
supported | supported |
kiro |
Kiro IDE | fixed OS credential, separate OS user required | none | supported (OS-user isolation; elevated terminal) | supported (OS-user isolation with sudo) |
supported (OS-user isolation with sudo and acl) |
opencode |
OpenCode | auth and sessions share one database | none | supported (--isolated whole-root required) |
supported (--isolated whole-root required) |
supported (--isolated whole-root required) |
windsurf |
Devin Desktop (Windsurf) | fixed OS credential, separate OS user required | none | supported (OS-user isolation; elevated terminal) | supported (OS-user isolation with sudo) |
supported (OS-user isolation with sudo and acl) |
zed |
Zed | credential store scoped to an owned OS user | none | supported (Windows OS-user isolation; elevated terminal) | unsupported: owned-user GUI/Keychain session is not proven | unsupported: owned-user GUI/Secret Service session is not implemented |
- File overlay adapters keep only the declared credential files profile-local; everything else links to the native shared root, so conversations and configuration are shared between profiles.
- Process token adapters inject a per-profile, highest-precedence credential into the child process only. Store the secret first with
multi-cli auth set <tool>/<profile>; launch stays fail-closed until then. - OS-user isolation provisions a multi-cli-owned user per profile. Windows requires an elevated terminal. macOS and Linux require
sudo, and Linux also requiresacl. Products that need an unimplemented desktop credential session remain unsupported on that platform. These adapters reject--isolatedbecause folder redirection cannot isolate a fixed OS credential store. --isolatedwhole-root redirects the product's entire home/config root into the profile dir. It separates filesystem-based products such asopencodeandcursor. It does not isolate fixed OS credential identities, including Claude Code subscription OAuth in the macOS Keychain. Product availability still applies:--isolatedcannot make an unavailable platform binary supported.