ktx
Install and configure ktx, the open-source context layer for data agents.
Use this skill when a user wants an agent to add ktx to a project, connect
data sources, build initial context, install agent integration, or troubleshoot
a local ktx setup.
Operating rules
- Act autonomously when the user asks you to install or configure ktx.
The non-interactive scripted flow below is the canonical path — bare
ktx setup is interactive (clack prompts) and an agent cannot drive it.
- Setup's non-interactive flags are intentionally hidden from
--help. Use the
flags listed below; verify uncommon flags against the docs at
https://docs.kaelio.com/ktx/ or this skill — not against --help output.
- Ask only for values you cannot infer: project directory, connection targets,
credentials, account identifiers, and source selections.
- Prefer
file:/abs/path secret refs over env:VAR_NAME. env: refs are
re-resolved against the process environment on every ktx run, so a var
exported only in the setup shell is gone when ktx ingest or ktx mcp start
runs later — the secret silently resolves to empty and the connection fails.
file: refs read from disk and survive across shells. The same caveat
applies to --*-api-key-env flags: the named var must be present in every
shell that runs ktx, including the ktx mcp daemon's environment.
- A literal database URL is safe to pass —
ktx setup auto-externalizes it
into .ktx/secrets/<id>-url and rewrites ktx.yaml to a file: ref (see
workflow step 2). Source credential refs are not auto-externalized: write
the secret to a file under .ktx/secrets/ (chmod 600) and pass a file:
ref. Never ask the user to paste a secret when a file: or env: ref works.
- Do not commit
.ktx/secrets/*.
- Print each command you run and its result.
- Setup and ingest can run for many minutes (LLM-heavy source ingests take the
longest), and from the outside a slow step looks identical to a stuck one.
Don't go silent: say what's about to run and that it may take a while, then
post brief progress/liveness updates while it runs (see step 4) so the user
never has to wonder whether it stalled — otherwise they may kill it mid-run.
- If a command fails, identify the cause and change something before retrying.
Gather inputs once
Before invoking ktx setup, collect in one round:
- Project directory (default: current working directory).
- LLM backend and key strategy. In
--no-input mode the CLI defaults to
anthropic and requires an API key. When the user is inside Claude
Code, pass --llm-backend claude-code explicitly; otherwise pass
--llm-backend anthropic --anthropic-api-key-env ANTHROPIC_API_KEY.
- Embedding backend (
sentence-transformers is the local default and needs
no key; use openai only if the user already has a key, then pass
--embedding-api-key-env OPENAI_API_KEY).
- Database: driver, connection id, URL (or
env: / file: ref), and one or
more schemas.
- Optional context sources (dbt, Metabase, Looker, LookML, MetricFlow,
Notion). Add each one with a follow-up
ktx setup --source … run (see
Add context sources); use --skip-sources only
when the user has none.
Do not discover these inputs across multiple setup runs.
Install workflow
Detect the install path. If the working directory contains
packages/cli/dist/bin.js or pnpm-workspace.yaml referencing
@kaelio/ktx you are inside the ktx monorepo — build and link the
local CLI with pnpm and do not run npm install -g. Otherwise:
node --version # require >= 22; stop and ask the user if older
ktx --version || npm install -g @kaelio/ktx
Run scripted setup (canonical path):
ktx setup --no-input --yes \
--project-dir <path> \
--llm-backend claude-code \
--embedding-backend sentence-transformers \
--database <driver> --database-connection-id <id> \
--database-url '<raw-url | file:/abs/path>' \
--database-schema <schema> \
--skip-sources \
--skip-agents
- Configure one new database connection per setup invocation. For multiple
connections, rerun setup once per connection.
- Pasting a literal
--database-url is safe: the CLI relocates the URL
into .ktx/secrets/<connection-id>-url and rewrites ktx.yaml to a
file: ref automatically.
ktx setup runs agent integration as its last step. In --no-input
mode with neither --target nor --skip-agents, that step has no input,
prints Run in a TTY, or pass --target <target>., and the command exits
non-zero even though every database/LLM/embedding step succeeded. Pass
--skip-agents to defer agents to step 5 (as above), or --target <agent>
to install them inline and exit 0. Judge data-layer success from
ktx status, not from this exit code.
Resumability and --skip-*. Re-running ktx setup against an existing
project resumes its config. Use --skip-llm, --skip-databases,
--skip-sources, or --skip-embeddings to leave a slice unconfigured but
let the rest complete instead of aborting on the first failure. When
resuming an existing project to change one slice (e.g. only LLM), still
pass the database flags from the previous run — setup validates current
flags, not persisted ktx.yaml state.
Build context if setup did not already complete one:
ktx ingest <connection-id> --no-input
ktx ingest always builds enriched context and requires a configured model
and embeddings (set during setup); a database connection without them fails
with an enrichment-readiness error. Note: ktx ingest rejects --yes
together with --no-input (Choose only one runtime install mode);
ktx setup accepts both. Use --no-input only for ingest.
Ingest one connection at a time. It can run for many minutes with no
stdout until it exits (LLM-heavy sources like Metabase are the slowest), so
don't assume it hung, and don't pipe it through tail/head — that buffers
all output to the end, so run it raw. Tell the user up front that the step is
slow, then keep them posted instead of blocking silently: run the ingest in
the background and poll for liveness every minute or so, reporting a one-line
update each time (which connection, roughly how long it's been running, and
that .ktx files are still changing) so a long run never looks stuck:
find <path>/.ktx/worktrees <path>/.ktx/ingest-transcripts -type f -mmin -3
On success, the Ingest finished summary table shows done in the
Source ingest and Memory update columns with no Failed sources:
section.
Install agent integration:
ktx setup --agents --target <claude-code|claude-desktop|codex|cursor|opencode|universal>
ktx mcp start --project-dir <path>
Agent integration is not usable until ktx mcp start is running. The
--agents step prints this requirement as Required before using agents.
Fall back to bare ktx setup only when a human is at the keyboard —
it uses interactive prompts an agent cannot answer.
Add context sources
Context sources (dbt, Metabase, Looker, LookML, MetricFlow, Notion) are added
one at a time — --source is not repeatable, so run ktx setup once per
source. Source setup is resumable against an existing project: pass
--skip-databases --skip-llm --skip-embeddings --skip-agents so only the source
is configured (the trailing agent step otherwise fails the run — see install
step 2). Map Metabase, Looker, and LookML to an existing database connection
with --source-warehouse-connection-id <db-connection-id> (required for those).
dbt ignores --source-warehouse-connection-id — it maps to the warehouse by
table name — so omit it for dbt. Use file:/abs/path refs for keys and tokens
(see the secrets rule above); env: refs must be exported in every later ktx
shell.
# dbt — pick exactly one of --source-path (local) or --source-git-url (remote).
# No --source-warehouse-connection-id: dbt maps to the warehouse by table name.
ktx setup --no-input --yes --skip-databases --skip-llm --skip-embeddings --skip-agents \
--source dbt --source-connection-id <id> \
--source-git-url <url> --source-branch <branch>
# Metabase
ktx setup --no-input --yes --skip-databases --skip-llm --skip-embeddings --skip-agents \
--source metabase --source-connection-id <id> \
--source-url <url> --source-api-key-ref file:/abs/path/metabase-api-key \
--source-warehouse-connection-id <db-connection-id> \
--metabase-database-id <metabase-db-id>
# Notion
ktx setup --no-input --yes --skip-databases --skip-llm --skip-embeddings --skip-agents \
--source notion --source-connection-id <id> \
--source-auth-token-ref file:/abs/path/notion-token \
--notion-crawl-mode selected_roots --notion-root-page-id <page-id>
Notes:
--metabase-database-id is the numeric id of the warehouse inside
Metabase (not the ktx connection id). Discover it from the Metabase API
(GET /api/database) or UI if the user doesn't know it.
--notion-crawl-mode selected_roots requires at least one
--notion-root-page-id (repeatable); use all_accessible to crawl
everything the token can see.
- After adding sources, ingest each new connection so its context is queryable:
ktx ingest <source-connection-id> --no-input.
Files to inspect
ktx.yaml: project configuration.
.ktx/secrets/*: local secret files. Never commit them.
semantic-layer/<connection-id>/*.yaml: semantic sources for SQL
compilation.
wiki/**/*.md: project context pages for agents.
.claude/skills/ktx/, .agents/skills/ktx/, .cursor/rules/ktx.mdc, and
.opencode/commands/ktx.md: generated agent integration files.
Verification
After setup, run:
ktx connection test <connection-id>
ktx status --json --no-input
ktx sl --output plain # lists compiled semantic sources; `ktx sl` has no --no-input
Judge readiness from ktx status --json fields, not the exit code.
ktx status exits 1 whenever the LLM is none (verdict: "blocked"), even
when embeddings and every database connection are healthy. Treat success as:
verdict: "ready" at the top of the JSON, and
- every
connections[].status === "ok" (other levels: warn, fail,
skipped), and
- every
ktx connection test <id> exited 0, and
- for each ingested source,
localStats.semanticLayer[].sourceCount > 0 and
localStats.wikiPages[].count > 0 — these confirm the source actually
produced context. Do not rely on localStats.ingest.perConnection to
confirm source ingests: it reflects only completed warehouse ingest reports
and under-reports (often lists just the warehouse connection).
If the LLM is intentionally left unconfigured, verdict is blocked and the
exit is non-zero by design — that is still a usable context layer, so report it
as "ready, LLM optional" and judge the data layer by the connection and
localStats fields above rather than retrying setup.
Troubleshooting
For known failure signatures (invalid ELF header,
Native CLI binary for <plat> not found, Missing Anthropic API key,
claude-code probe failure, KTX cannot work without a database on resume,
Run in a TTY, or pass --target <target>. with a misleading exit 1, and a
secret that resolves empty only during ktx ingest/ktx mcp), see
troubleshooting.md.
Final report
End setup work with a concise report:
ktx SETUP COMPLETE
Project: <path>
LLM: <backend> / <model>
Embeddings: <backend> / <model>
Connections: <name> (<driver>) status=<ok|warn|fail>
Sources: <list or none>
Verdict: <ready|needs action>
Next:
1. <copy-pasteable command or action>
2. <copy-pasteable command or action>
RESULT: PASS
1---2name: ktx-23description: Installs and configures ktx, the open-source context layer for data agents — runs ktx setup non-interactively with hidden CLI flags, configures database connections and embeddings, installs agent integration, and verifies readiness. Use when the user asks an agent to add ktx to a project, connect data sources, install agent rules, ingest schema, or troubleshoot a local ktx install.4---56# ktx78Install and configure **ktx**, the open-source context layer for data agents.9Use this skill when a user wants an agent to add **ktx** to a project, connect10data sources, build initial context, install agent integration, or troubleshoot11a local **ktx** setup.1213## Operating rules1415- Act autonomously when the user asks you to install or configure **ktx**.16 The non-interactive scripted flow below is the canonical path — bare17 `ktx setup` is interactive (clack prompts) and an agent cannot drive it.18- Setup's non-interactive flags are intentionally hidden from `--help`. Use the19 flags listed below; verify uncommon flags against the docs at20 `https://docs.kaelio.com/ktx/` or this skill — not against `--help` output.21- Ask only for values you cannot infer: project directory, connection targets,22 credentials, account identifiers, and source selections.23- Prefer `file:/abs/path` secret refs over `env:VAR_NAME`. `env:` refs are24 re-resolved against the process environment on **every** `ktx` run, so a var25 exported only in the setup shell is gone when `ktx ingest` or `ktx mcp start`26 runs later — the secret silently resolves to empty and the connection fails.27 `file:` refs read from disk and survive across shells. The same caveat28 applies to `--*-api-key-env` flags: the named var must be present in every29 shell that runs `ktx`, including the `ktx mcp` daemon's environment.30- A literal database URL is safe to pass — `ktx setup` auto-externalizes it31 into `.ktx/secrets/<id>-url` and rewrites `ktx.yaml` to a `file:` ref (see32 workflow step 2). Source credential refs are **not** auto-externalized: write33 the secret to a file under `.ktx/secrets/` (`chmod 600`) and pass a `file:`34 ref. Never ask the user to paste a secret when a `file:` or `env:` ref works.35- Do not commit `.ktx/secrets/*`.36- Print each command you run and its result.37- Setup and ingest can run for many minutes (LLM-heavy source ingests take the38 longest), and from the outside a slow step looks identical to a stuck one.39 Don't go silent: say what's about to run and that it may take a while, then40 post brief progress/liveness updates while it runs (see step 4) so the user41 never has to wonder whether it stalled — otherwise they may kill it mid-run.42- If a command fails, identify the cause and change something before retrying.4344## Gather inputs once4546Before invoking `ktx setup`, collect in one round:47481. Project directory (default: current working directory).492. LLM backend and key strategy. In `--no-input` mode the CLI defaults to50 `anthropic` and **requires an API key**. When the user is inside Claude51 Code, pass `--llm-backend claude-code` explicitly; otherwise pass52 `--llm-backend anthropic --anthropic-api-key-env ANTHROPIC_API_KEY`.533. Embedding backend (`sentence-transformers` is the local default and needs54 no key; use `openai` only if the user already has a key, then pass55 `--embedding-api-key-env OPENAI_API_KEY`).564. Database: driver, connection id, URL (or `env:` / `file:` ref), and one or57 more schemas.585. Optional context sources (dbt, Metabase, Looker, LookML, MetricFlow,59 Notion). Add each one with a follow-up `ktx setup --source …` run (see60 [Add context sources](#add-context-sources)); use `--skip-sources` only61 when the user has none.6263Do not discover these inputs across multiple setup runs.6465## Install workflow66671. **Detect the install path.** If the working directory contains68 `packages/cli/dist/bin.js` or `pnpm-workspace.yaml` referencing69 `@kaelio/ktx` you are inside the **ktx** monorepo — build and link the70 local CLI with `pnpm` and do **not** run `npm install -g`. Otherwise:7172 ```bash73 node --version # require >= 22; stop and ask the user if older74 ktx --version || npm install -g @kaelio/ktx75 ```76772. **Run scripted setup** (canonical path):7879 ```bash80 ktx setup --no-input --yes \81 --project-dir <path> \82 --llm-backend claude-code \83 --embedding-backend sentence-transformers \84 --database <driver> --database-connection-id <id> \85 --database-url '<raw-url | file:/abs/path>' \86 --database-schema <schema> \87 --skip-sources \88 --skip-agents89 ```9091 - Configure one new database connection per setup invocation. For multiple92 connections, rerun setup once per connection.93 - Pasting a literal `--database-url` is safe: the CLI relocates the URL94 into `.ktx/secrets/<connection-id>-url` and rewrites `ktx.yaml` to a95 `file:` ref automatically.96 - `ktx setup` runs agent integration as its **last** step. In `--no-input`97 mode with neither `--target` nor `--skip-agents`, that step has no input,98 prints `Run in a TTY, or pass --target <target>.`, and the command exits99 non-zero **even though every database/LLM/embedding step succeeded**. Pass100 `--skip-agents` to defer agents to step 5 (as above), or `--target <agent>`101 to install them inline and exit 0. Judge data-layer success from102 `ktx status`, not from this exit code.1031043. **Resumability and `--skip-*`.** Re-running `ktx setup` against an existing105 project resumes its config. Use `--skip-llm`, `--skip-databases`,106 `--skip-sources`, or `--skip-embeddings` to leave a slice unconfigured but107 let the rest complete instead of aborting on the first failure. **When108 resuming an existing project to change one slice (e.g. only LLM), still109 pass the database flags from the previous run** — setup validates current110 flags, not persisted `ktx.yaml` state.1111124. **Build context** if setup did not already complete one:113114 ```bash115 ktx ingest <connection-id> --no-input116 ```117118 `ktx ingest` always builds enriched context and requires a configured model119 and embeddings (set during setup); a database connection without them fails120 with an enrichment-readiness error. Note: `ktx ingest` rejects `--yes`121 together with `--no-input` (*Choose only one runtime install mode*);122 `ktx setup` accepts both. Use `--no-input` only for ingest.123124 Ingest one connection at a time. It can run for many minutes with **no125 stdout** until it exits (LLM-heavy sources like Metabase are the slowest), so126 don't assume it hung, and don't pipe it through `tail`/`head` — that buffers127 all output to the end, so run it raw. Tell the user up front that the step is128 slow, then keep them posted instead of blocking silently: run the ingest in129 the background and poll for liveness every minute or so, reporting a one-line130 update each time (which connection, roughly how long it's been running, and131 that `.ktx` files are still changing) so a long run never looks stuck:132133 ```bash134 find <path>/.ktx/worktrees <path>/.ktx/ingest-transcripts -type f -mmin -3135 ```136137 On success, the `Ingest finished` summary table shows `done` in the138 `Source ingest` and `Memory update` columns with no `Failed sources:`139 section.1401415. **Install agent integration:**142143 ```bash144 ktx setup --agents --target <claude-code|claude-desktop|codex|cursor|opencode|universal>145 ktx mcp start --project-dir <path>146 ```147148 Agent integration is **not usable until `ktx mcp start` is running**. The149 `--agents` step prints this requirement as `Required before using agents`.1501516. **Fall back to bare `ktx setup` only when a human is at the keyboard** —152 it uses interactive prompts an agent cannot answer.153154## Add context sources155156Context sources (dbt, Metabase, Looker, LookML, MetricFlow, Notion) are added157**one at a time** — `--source` is not repeatable, so run `ktx setup` once per158source. Source setup is resumable against an existing project: pass159`--skip-databases --skip-llm --skip-embeddings --skip-agents` so only the source160is configured (the trailing agent step otherwise fails the run — see install161step 2). Map Metabase, Looker, and LookML to an existing database connection162with `--source-warehouse-connection-id <db-connection-id>` (required for those).163**dbt ignores `--source-warehouse-connection-id`** — it maps to the warehouse by164table name — so omit it for dbt. Use `file:/abs/path` refs for keys and tokens165(see the secrets rule above); `env:` refs must be exported in every later `ktx`166shell.167168```bash169# dbt — pick exactly one of --source-path (local) or --source-git-url (remote).170# No --source-warehouse-connection-id: dbt maps to the warehouse by table name.171ktx setup --no-input --yes --skip-databases --skip-llm --skip-embeddings --skip-agents \172 --source dbt --source-connection-id <id> \173 --source-git-url <url> --source-branch <branch>174175# Metabase176ktx setup --no-input --yes --skip-databases --skip-llm --skip-embeddings --skip-agents \177 --source metabase --source-connection-id <id> \178 --source-url <url> --source-api-key-ref file:/abs/path/metabase-api-key \179 --source-warehouse-connection-id <db-connection-id> \180 --metabase-database-id <metabase-db-id>181182# Notion183ktx setup --no-input --yes --skip-databases --skip-llm --skip-embeddings --skip-agents \184 --source notion --source-connection-id <id> \185 --source-auth-token-ref file:/abs/path/notion-token \186 --notion-crawl-mode selected_roots --notion-root-page-id <page-id>187```188189Notes:190191- `--metabase-database-id` is the **numeric id of the warehouse inside192 Metabase** (not the ktx connection id). Discover it from the Metabase API193 (`GET /api/database`) or UI if the user doesn't know it.194- `--notion-crawl-mode selected_roots` requires at least one195 `--notion-root-page-id` (repeatable); use `all_accessible` to crawl196 everything the token can see.197- After adding sources, ingest each new connection so its context is queryable:198 `ktx ingest <source-connection-id> --no-input`.199200## Files to inspect201202- `ktx.yaml`: project configuration.203- `.ktx/secrets/*`: local secret files. Never commit them.204- `semantic-layer/<connection-id>/*.yaml`: semantic sources for SQL205 compilation.206- `wiki/**/*.md`: project context pages for agents.207- `.claude/skills/ktx/`, `.agents/skills/ktx/`, `.cursor/rules/ktx.mdc`, and208 `.opencode/commands/ktx.md`: generated agent integration files.209210## Verification211212After setup, run:213214```bash215ktx connection test <connection-id>216ktx status --json --no-input217ktx sl --output plain # lists compiled semantic sources; `ktx sl` has no --no-input218```219220**Judge readiness from `ktx status --json` fields, not the exit code.**221`ktx status` exits 1 whenever the LLM is `none` (`verdict: "blocked"`), even222when embeddings and every database connection are healthy. Treat success as:223224- `verdict: "ready"` at the top of the JSON, and225- every `connections[].status === "ok"` (other levels: `warn`, `fail`,226 `skipped`), and227- every `ktx connection test <id>` exited 0, and228- for each ingested source, `localStats.semanticLayer[].sourceCount > 0` and229 `localStats.wikiPages[].count > 0` — these confirm the source actually230 produced context. Do **not** rely on `localStats.ingest.perConnection` to231 confirm source ingests: it reflects only completed warehouse ingest reports232 and under-reports (often lists just the warehouse connection).233234If the LLM is intentionally left unconfigured, `verdict` is `blocked` and the235exit is non-zero by design — that is still a usable context layer, so report it236as "ready, LLM optional" and judge the data layer by the connection and237`localStats` fields above rather than retrying setup.238239## Troubleshooting240241For known failure signatures (`invalid ELF header`,242`Native CLI binary for <plat> not found`, `Missing Anthropic API key`,243`claude-code` probe failure, `KTX cannot work without a database` on resume,244`Run in a TTY, or pass --target <target>.` with a misleading exit 1, and a245secret that resolves empty only during `ktx ingest`/`ktx mcp`), see246[troubleshooting.md](troubleshooting.md).247248## Final report249250End setup work with a concise report:251252```text253ktx SETUP COMPLETE254255Project: <path>256LLM: <backend> / <model>257Embeddings: <backend> / <model>258Connections: <name> (<driver>) status=<ok|warn|fail>259Sources: <list or none>260Verdict: <ready|needs action>261262Next:2631. <copy-pasteable command or action>2642. <copy-pasteable command or action>265266RESULT: PASS267```