Build1 publisher3 min readPublished
A consumer desktop client shipped an internal AI gateway, and a cleartext token store
Kimi Desktop 3.1.10 hides Moonshot's employee-only model gateway behind five clicks, then saves the personal bearer token to disk unencrypted in two places, according to RuntimeWire.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Static analysis and runtime testing of Kimi Desktop 3.1.10 by RuntimeWire found a concealed internal, office/VPN-only KTH gateway feature inside the public client; methods were reverse engineering, testing and data analysis.
- Five rapid clicks on the Version row (each interval under one second) invoke the BYOK reveal handler in Kimi Desktop 3.1.10 and persist the setting in byok-availability.json.
- The application stores the complete personal token in byok-providers.json without application-layer encryption and also writes it into the daemon configuration.
- Reproduction steps: install and launch Kimi Desktop 3.1.10, open Kimi Work Settings, scroll to About, click the Version row five times rapidly, then scroll up to Model Sources.
- The revealed interface identifies the service as "KTH Gateway (Internal)", defaults to https://free-tokens.msh.team/v1, requires a personal token, and says access is limited to an office network or VPN.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
Kimi Desktop 3.1.10, the public Windows build of Moonshot AI's client, contains a concealed configuration panel for an internal, office-or-VPN-only model gateway, according to static analysis and runtime testing published by RuntimeWire [1]. The panel is revealed by five rapid clicks on the Version row in settings, and the client then stores the user's complete personal token on disk without application-layer encryption [2] [3].
The mechanics are ordinary, which is the point. Clicking the Version row five times, each interval under a second, invokes a reveal handler and persists the unlocked state in byok-availability.json [2] [4]. The panel identifies the service as "KTH Gateway (Internal)", defaults its base URL to https://free-tokens.msh.team/v1, asks for a personal token, and states that access requires a Moonshot office network or VPN [5]. The importer authenticates against /v1/models and /v1/models/api.json, accepts model names prefixed kimi-, gpt- and codex-, and wires up both Kimi and OpenAI Responses providers [6]. Conversations routed through it are labelled as not billed to membership [7], and failure strings refer to a congested "KTH upstream pool" [8]. RuntimeWire says the client does not establish whether Moonshot buys OpenAI capacity directly or reaches it through another internal pool [9].
Set aside the off-quota access story and look at the artifact. Five clicks is not an access control; the real controls are the corporate network and the bearer token. What the hidden panel demonstrates is that an internal tool passed through the release pipeline into a signed consumer download without anyone stripping it. Version 3.1.5 contained no BYOK, KTH or free-tokens.msh.team artifacts at all [10], so the code entered the public product somewhere between builds 3.1.5+c88420152 and 3.1.10+e0c4c9980 [11]. RuntimeWire reached the implementation by extracting the 3.1.10 ASAR and decoding its obfuscated string tables, tracing the renderer click handler through the preload IPC bridge to the main process [12]. Obfuscated strings inside an Electron package are packaging, not a boundary.
The credential handling is the more portable lesson. The application writes the full token into byok-providers.json with no application-layer encryption and also writes it into the daemon configuration [3], which means at least two plaintext copies of a corporate credential land on any machine where the flow is completed [13]. That is a defect no model evaluation would ever surface, and it is the class of defect that AI desktop clients keep shipping: hidden feature flags, hard-coded internal endpoints, and secrets kept in application-owned JSON rather than an OS keychain.
Scope matters. Moonshot's official Windows download endpoint served 3.1.10 on 17 August while the macOS endpoint still served 3.1.9, so the finding is confirmed for the current Windows release rather than every build [14]. RuntimeWire reproduced the hidden interface on an installed Windows copy without entering a token, testing the connection or sending an authenticated request [15] [16]. It requested comment, and Moonshot had not responded by publication [17].
Worth watching: whether the next Windows release removes the panel or merely re-hides it; whether the macOS build carries the same code once it reaches 3.1.10; and whether the token store moves out of a plaintext JSON file. A vendor that answers only the first of those three has fixed the embarrassment, not the pipeline.