Guide and (where possible) automate obtaining the API keys a cloned workbench needs — from instruction-only provider pages to OAuth/CLI flows — without ever handling secret values. Use when opencode reports degraded capabilities, when a clone has an empty ~/.env.workbench, or when the user asks to "get the box working", "set up keys", or "why is MCP X disabled".