# External Agents URL: /editor/external-agents An external agent is a coding CLI you already have installed. Tau starts it, gives it the project, and shows its work in the chat — it does not resell it. ## Supported CLIs [#supported-clis] | Agent | Adapter | CLI | Minimum CLI | | ----------- | ---------------------------------------------- | -------- | ----------- | | Codex | `@agentclientprotocol/codex-acp` 1.7.0 | `codex` | 0.148.0 | | Claude Code | `@agentclientprotocol/claude-agent-acp` 0.70.0 | `claude` | none pinned | | Grok Build | Native ACP (no adapter package) | `grok` | 1.0.41 | An older CLI is refused before the turn starts, naming the version it found. Codex is the qualified path; Claude Code and Grok Build are offered, but their authenticated live turns are not yet qualified. For Grok Build, follow the [official installation instructions](https://docs.x.ai/build/overview), then run `grok login` on the host machine. Tau starts `grok --no-auto-update agent stdio` using that local login. Its native ACP handshake has been verified without credentials. Agents run on a Tau Host: Tau Desktop, or `tau serve` paired with the browser. A browser tab with no host refuses the turn rather than quietly answering it with Tau. Each agent keeps its own configuration directory — `CODEX_HOME`, `CLAUDE_CONFIG_DIR`, or `GROK_HOME`. Tau credentials and provider API keys never reach the child process. ## Where the agent works [#where-the-agent-works] Each chat picks a revision mode, and every turn is recorded as a revision either way. * **Direct** — the agent works in the project folder itself. Its edits are the files you are looking at. * **Candidate** — the host materializes a checkout, the agent works there, and the result comes back as a branch you can review and merge. Tau Desktop and `tau serve` offer both. Chat and run records under `.tau/chats` and `.tau/runs` refuse agent writes; the revision store is hidden. [Workbench records](/editor/workbench-records) differ: `arrange_workbench` writes at the live project root, including candidate turns. The editor applies them, and the card offers Restore. ## What reaches the vendor [#what-reaches-the-vendor] The agent is the vendor's own client, so what it reads it may send. In direct mode that is your project tree. The CAD context Tau adds — the kernel, the open files, the model state — rides the session's first prompt as embedded resources, and is transmitted the same way. ## Billing and sign-in [#billing-and-sign-in] The vendor bills the account you signed that CLI into. Tau charges no credits for an external turn and quotes no price for one: the chat footer names the agent, the model and the vendor's own usage report. Tau surfaces a login; it never brokers one. A logged-out agent refuses with the methods it offers — a terminal command such as `codex login`, or a verification page and code — and the chat shows exactly that.