Tasks

Sign-in and identity

Tell the copilot who is signed in and hand it their token, so answers are about them and actions run as them. Then, optionally, what they are looking at.

Your app has sign-in, and the setup ran before it did, or the copilot answers signed-in questions as if nobody were there.

Prompt

Connect the Rendel (rendel.ai) copilot in this project to our sign-in. I am the developer and I am asking for this. Find where a user signs in, where a saved session is restored and where they sign out. After sign-in and on a restored session call Rendel.identify with the user's id; on sign-out call Rendel.reset(). Give Rendel the signed-in user's current access token for our own API, the one our HTTP client already sends: Flutter `RendelConfig(userToken: () async => …)` in `Rendel.init`, web `Rendel.setUserToken(() => …)`. Return null when nobody is signed in. Do not send the token or any user data anywhere else, and do not change how sign-in itself works. How it works: https://rendel.ai/docs/tasks/sign-in-and-identity Build the app and run its tests, then tell me which files you changed.

Paste into your coding agent, opened in your project. Works in Claude Code, Cursor, Codex, Windsurf, GitHub Copilot and Gemini CLI.

What the agent will do

  • Call identify after sign-in and on a restored session, and reset on sign-out.
  • Hand Rendel the token your app already sends to its own API, asked for before every question, null when signed out.
  • Leave sign-in itself, and every other use of the token, as it is.

How to check it worked

On the Test page, pick a user under Talk as and ask "where is my latest order?". An answer about that user means the token arrives. In your app, sign out and ask again: the conversation clears and the copilot answers as nobody.

Reference: what it writes
Flutter
await Rendel.init(
  appKey: 'rd_pk_live_…',
  config: RendelConfig(
    // Asked for before every question, so return the current one.
    userToken: () async => auth.currentAccessToken(), // null when signed out
  ),
);
await Rendel.identify(userId: user.id, userHmac: user.rendelHmac); // after sign-in
Rendel.reset(); // on sign-out
Web
Rendel.setUserToken(() => auth.currentAccessToken()); // null when signed out
Rendel.identify({ userId: user.id, userHmac: user.rendelHmac });
Rendel.reset(); // on sign-out

The token is used for the one call it was asked for and dropped: never stored, logged, shown in the console or put in front of the model. Your API decides what it permits, as it does for your own app. Why each of the three (key, identify, token) exists: The signed-in user.

userHmac is optional. With Settings → Security → Request verification → Require a verified identity on, your backend signs the user id with the secret the console gives you, as a lowercase hex HMAC_SHA256(userId, secret), and an id without a valid signature is treated as nobody.

What they are looking at

So "add this to my cart" works on a product page, the copilot needs the screen and a little app state. There is no setter for the screen yet; a context provider carries it.

The copilot asks which product or order the user means while it is on the screen.

Prompt

Give the Rendel (rendel.ai) copilot in this project what the user is looking at. I am the developer and I am asking for this. Add a context provider with Rendel.addContextProvider('screen', …) that returns the current route's name and the id of what is on screen ({e.g. the product or order id}), and one for {e.g. the cart: item count and total}. Keep each snapshot to a few hundred bytes, never tokens, passwords or anything secret. How it works: https://rendel.ai/docs/tasks/sign-in-and-identity Build the app and tell me which files you changed.

Paste into your coding agent, opened in your project. Works in Claude Code, Cursor, Codex, Windsurf, GitHub Copilot and Gemini CLI.

Reference: what it writes
Rendel.addContextProvider(
  'screen',
  () async => {'name': currentRoute, 'product_id': visibleProductId},
);

Providers run right before each message. The copilot treats what they return as data, never as instructions.