Claude Code keys its macOS Keychain entry to CLAUDE_CONFIG_DIR, so one config directory per OAuth account gives native per-account credentials without cwtch copying Anthropic-owned credential JSON around. The trade-off is that the whole config tree (settings, plugins, skills, history, project state) moves with it.
Spike: prototype cwtch profile use <oauth> exporting CLAUDE_CONFIG_DIR=~/.cwtch/profiles/<name>/claude (with shared settings symlinked in), confirm the Keychain service/account naming empirically, and decide whether to replace the Keychain-swap mechanism in 7.0.
Refs: audit item 4 and decision Q2; Claude Code authentication docs, "Credential management".
Claude Code keys its macOS Keychain entry to
CLAUDE_CONFIG_DIR, so one config directory per OAuth account gives native per-account credentials without cwtch copying Anthropic-owned credential JSON around. The trade-off is that the whole config tree (settings, plugins, skills, history, project state) moves with it.Spike: prototype
cwtch profile use <oauth>exportingCLAUDE_CONFIG_DIR=~/.cwtch/profiles/<name>/claude(with shared settings symlinked in), confirm the Keychain service/account naming empirically, and decide whether to replace the Keychain-swap mechanism in 7.0.Refs: audit item 4 and decision Q2; Claude Code authentication docs, "Credential management".