The full list of commands and flags for fused-cli. Start with the main
README, then use the focused guides for
setup and operation, service imports, and
config as code.
All commands support the following global flags:
| Argument | Short | Description | Default |
|---|---|---|---|
--key |
Engine credential (overrides saved login, FUSED_API_KEY, and FUSED_LICENSE_KEY) |
"" |
|
--engine-url |
Fused Engine URL (overrides config & FUSED_ENGINE_URL) |
"" |
|
--file |
-f |
Path to a Fused config file (disables .fused/ discovery) |
"" |
--no-input |
Fail instead of prompting; also enabled by CI=true |
false |
|
--timeout |
Maximum duration for an Engine request; spec imports use 20m0s unless explicitly set |
1m0s |
|
--request-id |
Attach an audit correlation ID to every Engine request | "" |
|
--readme |
Print the concise CLI onboarding README and exit | false |
All Engine requests have a finite timeout and are cancelled when the CLI
receives SIGINT or SIGTERM. CI=true and FUSED_NO_UPDATE_CHECK=1 disable
release update checks. A command that would prompt fails with remediation when
--no-input or CI=true is active.
Read-only inspection commands accept --json without changing their default
human-readable output. This includes service and workspace discovery,
SDK/MCP inspection and token metadata, validation, bucket/secret/value/connect
metadata, identity, access, team, user, config, and skill listings.
Commands backed by an API page return:
{"items": [], "total": 0, "limit": 20, "offset": 0}Exact-object and non-paged reads return the object or array directly. Sensitive
reads keep the same safe projection as human output: secret values, decrypted
connect credentials, and execution-token values are never returned by list
commands. Plan commands retain their existing --json plan-result contract;
import and SDK apply, token generation, invocation, and activity also provide
stable JSON.
When a command using --json fails, stdout remains reserved for successful
output and stderr receives one JSON object before the CLI exits non-zero:
{
"ok": false,
"error": {
"code": "bucket_credentials_missing",
"message": "Provider credentials are not configured.",
"category": "validation",
"retryable": false,
"remediation": "Run the supplied credential command before repeating this call.",
"details": {
"bucket_id": "11111111-1111-4111-8111-111111111111",
"service_id": "22222222-2222-4222-8222-222222222222",
"command": "fused-cli secret set 22222222-2222-4222-8222-222222222222 --bucket 11111111-1111-4111-8111-111111111111 --type api_key --auth-name providerKey"
},
"trace_id": "...",
"http_status": 409,
"command": "fused-cli sdk invoke support-sdk@1.0.0 listIssues"
}
}Fields unavailable for a particular failure are omitted. Engine errors retain
their safe structured fields through CLI wrapping; untrusted response bodies
are still excluded. Cobra usage failures use invalid_arguments; other local
CLI failures use command_failed with the original message and a help-oriented
remediation. OTEL records the stable error code and retryability without
recording remote messages or command input.
Open the selected Engine's sign-in page and save a subject-scoped CLI credential after browser approval. The page supports managed Fused Auth and an existing Engine API key. The generated credential never passes through the browser and is not printed.
| Argument | Short | Description | Default |
|---|---|---|---|
--no-browser |
Print the sign-in URL instead of opening a browser | false |
Show the non-secret Engine identity used by the effective credential. The
command follows normal --key / saved config / environment resolution and
prints identity, account, workspace, credential source, authentication method,
and expiry when reported.
Pass --json for the Engine URL, local credential source, and non-secret
identity response as structured fields.
Revoke an Engine-issued managed CLI login and remove its saved local
credential. Logout deliberately uses the saved Engine URL and saved credential,
not --key or environment overrides. A failed remote revocation preserves the
local login for retry; an already-inactive login is cleared locally. The saved
engine-url remains configured. Manually saved API keys are left unchanged
because they are not managed CLI logins.
Manage your local CLI configuration (set, get, list, reset). Inherits global flags.
Create and start a typed SDK, a direct Engine API app, or an Engine-hosted MCP server. Top-level init composes the existing workspace and app plan/apply functions; it does not introduce a new resource kind or receipt boundary.
# Generate, apply, and download a typed SDK
fused-cli init google-workspace --sdk \
--service '@google/drive' \
--operation '@google/drive=listFiles'
# Apply the same execution app without generating a package
fused-cli init google-api --api \
--service '@google/drive' \
--select-all '@google/drive'
# Deploy an Engine-hosted MCP server
fused-cli init support-agent --mcp \
--description 'Help support teams manage issues' \
--service jira \
--select-all jira--service <service>[@<version>] accepts comma-separated values or repeated
flags. --operation <service>=<operationId> and --select-all <service> are
repeatable. An omitted provider version resolves to
the latest enabled workspace version, or the latest public Registry version
when activation is needed. New SDK/MCP configs default to app version 1.0.0;
generated SDKs default to TypeScript. --bucket only references an existing
bucket and is omitted by default—it never creates a bucket.
--no-apply writes and validates the same desired state, saves every plan
receipt whose dependencies are active, and stops before apply, generation, or
download. If a service is not active yet, the workspace plan receipt is saved
and app planning is deferred until workspace apply; otherwise the app plan
receipt is saved immediately. The command prints the exact remaining commands,
including sdk apply --download for generated SDKs, and tells users to re-plan
if a retained receipt becomes stale.
In a terminal, omit the mode flag to choose --sdk, --api, or --mcp. If a
service has no operation flags, the highlighted default is All operations;
choose the narrower path to search by operation ID, method, path, description,
or tag. In automation, --no-input or CI=true requires one explicit mode and
an explicit --operation or --select-all for every service. Non-interactive
MCP creation also requires --description.
Creation refuses to replace an existing path before any remote plan. Extension is additive and
idempotent through the top-level extend command described below. The retained
init --extend flag is a compatibility alias for existing scripts.
If an exact version is not enabled, a terminal presents one combined
confirmation; governance remains split into a workspace plan receipt and an app
plan receipt. SDK/API planning securely remediates only typed missing
credentials in the exact selected bucket and retries once. Top-level init has
human apply output and does not expose --json; use the explicit plan/apply
commands for structured automation.
Without --no-apply, init builds and validates the app candidate in memory, then plans it before
atomically creating the YAML file. If that app plan fails, no app config or app
receipt is created. A workspace activation completed earlier in the composed
flow remains applied under its separate receipt.
For generated SDK mode, generation_contract_pin_unavailable starts one
bounded legacy-snapshot repair. The CLI resolves every selected active
service@version before changing anything, visibly refreshes each exact Engine
snapshot, and retries the unchanged app plan once. --no-input follows the
same deterministic path without prompting. The CLI never substitutes a runtime
hash, selects a newer version, or bypasses the Registry-retained generation pin.
API mode, MCP mode, and unrelated failures do not trigger this repair.
If exact resolution or refresh fails, init does not retry the plan. If the one retry fails, no app config or app receipt is created and the error reports any snapshot refreshes that already completed. A repeated missing-pin response directs you to the Engine and Registry logs or another enabled version. Changing credentials or operation selection does not repair a generation-pin failure.
SDK mode writes kind: sdk with generate: true, applies it, and downloads the
package. API mode writes the same resource with generate: false, applies it,
and prints a central execution REST request template. MCP mode writes kind: mcp, applies it, and reports the deployed Engine URL and token.
App scaffolding adds only missing required bucket-backed
server_variable injections. Existing injections remain authoritative, and
workspace policy or native x-fused-connect routing is not duplicated. The
older sdk init and mcp init scaffold commands remain callable but hidden for
compatibility. See the fused-config OpenAPI/Postman reference for the canonical
Sendbird binding and bucket-value setup.
Create an editable aggregate workspace skeleton at .fused/workspace.yaml, or
at the global --file path. Creation refuses to replace an existing file;
--extend adds service selections without duplicating existing entries. This
local authoring command does not activate or remove Engine services.
fused-cli workspace init
fused-cli workspace init --service stripe@v1,github@v3
fused-cli workspace init --extend --service slack| Argument | Short | Description | Default |
|---|---|---|---|
--service |
Service as <service>[@<version>]; comma-separated or repeatable |
[] |
|
--extend |
Merge services into an existing workspace config | false |
|
--json |
Print the scaffold result as JSON | false |
Add services or operations to an existing SDK, direct API app, or MCP server:
fused-cli extend support-sdk \
--service slack \
--select-all slackThe command finds the existing .fused/sdks/<name>.yaml or
.fused/mcps/<name>.yaml file and infers its mode from the validated document.
An SDK config with generate: false remains a direct API app. If both SDK and
MCP files use the same name, pass -f <exact-file> rather than letting the CLI
guess.
Extension updates that same YAML file. It preserves existing selections,
reports unchanged for an idempotent merge, and rejects conflicting identity,
routing, or service-version input before writing. A real change to a stable SemVer
version infers its next minor successor; 1.0.0 becomes 1.1.0. Terminal
confirmation shows that identity, and --no-input or CI=true uses the same
deterministic inference. An idempotent repeat keeps the current version. Pass
--version to override inference; prerelease and non-SemVer versions require it.
--service <service>[@<version>], --operation <service>=<operationId>, and --select-all <service> retain the same meanings
as init. Omit operation flags in a terminal to accept all operations or use the
searchable selector. The command reuses the same activation, plan, apply, SDK
download, API next-step, and MCP deployment functions as initial creation.
List, inspect, or install the Fused skills bundled with this CLI. Installed skills teach supported coding agents the relevant discovery, configuration, credential, and plan/apply workflows.
List every bundled skill. Pass --json for structured name and summary fields.
Print SKILL.md or one referenced skill file. --skill defaults to
fused-cli; pass --json for structured skill, file, and content fields.
Install all bundled skills into the selected agent's normal skill/rules
directory. Supported agents are codex, claude, antigravity, cursor, and
windsurf.
| Argument | Short | Description | Default |
|---|---|---|---|
--for |
Target agent or app (required) | "" |
|
--skill |
Install one named skill instead of all skills | "" |
|
--scope |
user or project; Cursor and Windsurf support project only |
target default | |
--path |
Exact destination; requires --skill |
"" |
The command writes files only; it does not inject a skill into an already
running agent context. Binary release archives include skills/<version>/, and
the official installers preserve it beside the executable. skill install
reads that immutable local snapshot first, avoiding network drift; GitHub and
embedded content remain fallbacks for older and go install installations.
Search workspace and Registry services together for read-only browsing. Pass a
non-empty --q <provider-or-product> and optionally --json. Results already
enabled in the workspace are listed first with workspace_status: enabled;
Registry-only results use workspace_status: available_to_add. The CLI uses
Registry's existing bounded search, then one Engine lookup limited to that
query/result set—it does not load the full workspace. This combined view
requires both catalogue.read and service.read.
You do not need to run this before adding a service: workspace service add <query-or-slug> performs the same workspace-first resolution and Registry
fallback itself.
List Registry versions visible to the current account for a service slug. Supports provider-qualified slugs such as @provider/slug.
The command requests only version identity, status, and execution-contract
compatibility fields; it does not download documentation or execution policies.
Pass --json to return those bounded summary objects directly.
Show the description, base URL, servers, and supported authentication methods
for a service. Pass --json for stable machine-readable metadata, including
the reusable provider-qualified slug and complete non-secret auth contract.
| Argument | Short | Description | Default |
|---|---|---|---|
--json |
Print service metadata as JSON | false |
List or search Registry operations for a service. Passing --q uses the server-side endpoint search path and supports pagination.
| Argument | Short | Description | Default |
|---|---|---|---|
--q |
Search query for service operations | "" |
|
--version |
Service version for operations | "" |
|
--limit |
Maximum rows to read; requires --q |
20 |
|
--offset |
Rows to skip before reading; requires --q |
0 |
|
--json |
Print operation summaries, descriptions, documentation, and security requirements as JSON | false |
Show one operation grounded in an exact service version. Parameters, description, documentation, protocol, and ordered security requirements are returned by default. Request and response contracts are opt-in so large schemas do not unnecessarily fill an agent's context.
| Argument | Short | Description | Default |
|---|---|---|---|
--version |
Exact service version (required) | "" |
|
--json |
Print operation detail as JSON | false |
|
--include-request |
Include the request content contract | false |
|
--include-responses |
Include response contracts | false |
List Registry webhook definitions for a service.
Pass --json to return webhook definitions directly.
Set authentication credentials for a workspace service. In a terminal, the
command prompts for a supported authentication method and securely collects its
value by default. Use --value-stdin for automation; it is required with
--no-input or CI=true. Credential values are rejected in argv so they cannot
leak through shell history or process listings.
If the service supports multiple authentication families, use --type to
specify the family. If that family has multiple named schemes, also pass the
exact --auth-name; the CLI never silently chooses the first same-family
scheme. Interactive mode selects the exact scheme directly.
Paired credentials are ONE structured value, not two commands. There is no
--username/--password/--cert/--keyflag and no separatesetcall per field. Send both fields as one;-delimitedkey=value;key=valuevalue over stdin:printf '%s' 'username=x;password=y' | fused-cli secret set jira --type basic --value-stdin printf '%s' 'cert=...;key=...' | fused-cli secret set jira --type mtls --value-stdin printf '%s' 'client_id=...;client_secret=...' | fused-cli secret set gmail --bucket default --type oauth --auth-name oauth2 --value-stdinWithout
--value-stdin, a terminal supplies both fields through protected prompts.
OAuth/OIDC application credentials are encrypted bucket secrets, separate from
each connected user's access, refresh, and ID tokens. The Engine derives the
callback from its canonical public URL; redirect_uri is never accepted as
credential input.
Recommended Pattern: Pipe API keys, tokens, and service credentials to
fused-cli secret set <service-slug> --value-stdin. OAuth/OIDC application pairs must include the exact--bucket <bucket-name>; other schemes may use it to override the default. This stores secrets securely in Fused's encrypted vault.
Tip: To see available authentication families and their exact scheme names, run
fused-cli service show <service-slug>.
| Argument | Short | Description | Default |
|---|---|---|---|
--interactive |
-i |
Explicitly require authentication prompts (the terminal default) | false |
--value-stdin |
Read the credential value from stdin | false |
|
--type |
Authentication family (for example bearer, api_key, or oauth) |
"" |
|
--auth-name |
Exact Registry auth scheme name; required when the selected family has multiple schemes | "" |
|
--bucket |
Bucket name or full UUID; required for OAuth/OIDC application credentials | "" |
|
--expires-at |
RFC3339 expiry timestamp (e.g. 2026-12-31T23:59:59Z) | "" |
List secret metadata in a specific bucket. Secret values are never read back.
| Argument | Short | Description | Default |
|---|---|---|---|
--bucket |
Bucket name or full UUID to inspect (required) | "" |
|
--limit |
Maximum rows to read | 20 |
|
--offset |
Rows to skip before reading | 0 |
Delete a workspace secret. Use --bucket <bucket-name-or-id> for an override secret.
Create a new bucket for storing overrides and secrets.
List workspace buckets from the Engine GraphQL page used by the UI.
| Argument | Short | Description | Default |
|---|---|---|---|
--limit |
Maximum rows to read | 20 |
|
--offset |
Rows to skip before reading | 0 |
Show bucket counts and metadata.
List services represented in a bucket, including secret, value, Connect config, and connected-user counts.
| Argument | Short | Description | Default |
|---|---|---|---|
--limit |
Maximum rows to read | 20 |
|
--offset |
Rows to skip before reading | 0 |
List secret metadata in a bucket without reading secret values.
| Argument | Short | Description | Default |
|---|---|---|---|
--limit |
Maximum rows to read | 20 |
|
--offset |
Rows to skip before reading | 0 |
Set a service-independent secret for SDK/MCP injection or webhook references.
The bucket is always required. In a terminal, the secret name may be omitted
and the value is collected through a masked prompt. Automation must pass the
name and pipe the value with --value-stdin; values are never accepted in
argv. --json returns only bucket ID, secret name, and optional expiry.
printf '%s' "$WEBHOOK_SECRET" | fused-cli --no-input bucket secret set default webhook_signing --value-stdin| Argument | Short | Description | Default |
|---|---|---|---|
--interactive |
-i |
Explicitly require prompts (the terminal default) | false |
--value-stdin |
Read the secret value from stdin | false |
|
--expires-at |
Optional RFC3339 expiry timestamp | "" |
|
--json |
Print non-sensitive mutation metadata as JSON | false |
List non-secret values in a bucket.
| Argument | Short | Description | Default |
|---|---|---|---|
--limit |
Maximum rows to read | 20 |
|
--offset |
Rows to skip before reading | 0 |
List connected users in a bucket. Filters are sent to Engine GraphQL.
| Argument | Short | Description | Default |
|---|---|---|---|
--service |
Service filter as <service>[@<version>]; comma-separated or repeatable |
[] |
|
--user |
End-user reference to filter connections | "" |
|
--limit |
Maximum rows to read | 20 |
|
--offset |
Rows to skip before reading | 0 |
List SDKs linked to a bucket. Each relationship applies to every version of the SDK.
| Argument | Short | Description | Default |
|---|---|---|---|
--limit |
Maximum rows to read | 20 |
|
--offset |
Rows to skip before reading | 0 |
Delete a workspace bucket.
Set a non-secret configuration value in a bucket. Location can be env, body, query, header, or path.
List all non-secret values stored in a bucket.
Delete a non-secret value from a bucket.
Commands accept team slugs and user email addresses. Bucket names and workspace
service slugs are accepted at their respective resource boundaries. App access
mutations require the SDK_ID or MCP_ID displayed by list commands because
the generic app command cannot infer SDK versus MCP from a potentially shared
name. Kind-specific SDK/MCP commands can resolve names safely. List
operations are paginated by the Engine; use --limit and --offset rather
than fetching an entire workspace into the CLI.
Provider connection and discovered-resource IDs remain opaque IDs because providers do not guarantee a stable, workspace-unique human name for them.
List active teams. Use --search <text> to search names and slugs and
--include-archived to include archived teams.
Show a team and its workspace, service, bucket, SDK, and MCP bindings.
List active teams the current caller can select as the owner of a new SDK, MCP
server, or webhook. Supports --search, --limit, and --offset.
Create a team. Optional flags are --slug and --description.
Update a team with one or more of --name, --slug, or --description.
Pass an empty --description value to clear it.
Archive a team after its bindings and owned apps have been removed or transferred.
List team members. Supports --limit and --offset.
Add a person to a team, creating their person record when needed. Use
--role member (default) or --role manager.
Remove a person from a team.
Set the team's workspace role. The canonical roles are owner, admin,
builder, and viewer.
Clear the team's workspace role.
Grant or revoke use or manage access to a service.
Grant or revoke use or manage access to a bucket.
Grant or revoke read, use, or manage for an SDK or MCP server. The ID is
shown as SDK_ID or MCP_ID, and the grant applies to every version.
List services or buckets available to both the current caller and the team.
Use --resource service|bucket, with optional --search, --limit, and
--offset.
List active people. Use --search <text> to search names and email addresses,
--include-suspended to include suspended people, and --limit/--offset for
pagination.
Show a person, their team memberships, and non-secret credential metadata.
Add a person without sending an email. --name <display-name> is required.
Update a person with --email, --name, or both.
Suspend a person and stop their credentials, or reactivate a suspended person.
Issue a personal credential. --name defaults to personal. The raw key is
printed once and is never written to config, logs, or OTEL.
Revoke a personal credential.
Preview SDK package or MCP server changes. Each command reads only its matching
config kind, so an MCP plan never generates SDK code and an SDK plan never
deploys an MCP server. Plan runs the same local/offline validation as
validate before its first Engine request.
| Argument | Short | Description | Default |
|---|---|---|---|
--json |
Print plan result JSON, including summary and notifications; the default receipt is still written | false |
|
--interactive |
-i |
Explicitly require SDK credential prompting when needed (the terminal default); incompatible with --json, CI, and --no-input |
false |
--receipt-out |
Write the plan receipt to a specific path | "" |
|
--owner-team |
Optional owning team slug; defaults to the authenticated person | "" |
Terminal SDK planning may receive successful credential_readiness metadata,
offer one secure write to the exact YAML-resolved bucket, and retry once.
Declining preserves the valid plan. It never creates or substitutes a bucket.
Static auth is stored through the ordinary secret path; OAuth/OIDC prompts for
the bucket's client registration rather than an end-user provider token. MCP
planning reports the same non-blocking readiness but does not prompt.
Apply an SDK generation plan or deploy an MCP server plan.
Generated-SDK apply returns after Engine durably queues the non-runnable build;
package generation continues in Engine's background finalizer. Use sdk show <name@version-or-version-id> to inspect generation_status. --download
waits through Engine-local Version ID status reads before downloading, without
replaying apply or depending on a Registry event stream.
| Argument | Short | Description | Default |
|---|---|---|---|
--download |
Download generated SDKs after sdk apply; unavailable for MCP |
false |
|
--json |
Print SDK apply, generation, and download outcomes as JSON; unavailable for MCP | false |
|
--plan-id |
Apply a specific remote plan ID | "" |
|
--receipt |
Read a specific plan receipt | "" |
Full-mirror a local SDK config from the exact Engine app version declared in that file. There is no implicit latest lookup or sync-time version upgrade.
Usage: fused-cli sdk sync <sdk-name> -f .fused/sdks/<sdk-name>.yaml
Validate only the matching SDK or MCP configuration files without an Engine
request. This remains useful for offline checks; plan already performs this
validation first. Inherits global flags.
List generated SDK versions or deployed MCP versions. The kind is fixed by the command.
Use sdk versions <name-or-id> or mcp versions <name-or-id> to inspect one application, or omit the selector
to list all versions of that kind, including exact version IDs. MCP output also
includes stable and pinned transport URLs.
SDK_ID or MCP_ID remains stable across versions; VERSION_ID identifies
one exact immutable version.
| Argument | Short | Description | Default |
|---|---|---|---|
--limit |
Maximum rows to read | 20 |
|
--offset |
Rows to skip before reading | 0 |
List each SDK or direct API application once by canonical name and stable
SDK_ID, with a version count and latest published version. --limit (default 20) and --offset (default 0)
paginate applications in name order using Engine-owned grouping and authorized totals.
--json returns the usual pagination envelope with app_family_id, name, and
version_count, plus latest_version and its exact latest_version_id. Latest is catalogue metadata; runtime and lifecycle commands still require an exact version.
Use sdk versions [sdk-or-api-name-or-id] for exact version rows and status;
sdk versions --json provides the previous sdk list --json output shape.
List each MCP application once by its canonical name and stable MCP_ID.
Shows the version count, latest published version, explicitly promoted stable version, and stable transport
URLs. Applications without a promoted version remain listed with no stable URL;
the CLI does not select a newer sibling automatically.
--limit (default 20) and --offset (default 0) paginate applications in name
order, using Engine-owned grouping and authorized totals. --json uses the
usual items/total pagination envelope with application-level fields:
app_family_id, name, version_count, latest_version, latest_version_id, optional stable_version,
stable_version_id, default_transport, and stable transport_urls.
For the previous version-level output, use mcp versions --json.
Application listing requires Engine support for the appFamilies GraphQL query.
Upgrade Engine alongside this CLI change. The UI uses the same family catalogue and keeps app/appVersions for exact-version details.
Show one exact SDK version from the Engine.
List services selected by one exact SDK version.
List every operation ID callable through one exact MCP server version. The
Engine expands select_all from its immutable local service-contract snapshots
and includes Unified Operations from the integrity-checked applied plan. Human
output shows OPERATION_ID and KIND (physical or unified); --json
returns the MCP and Version IDs plus exact physical service provenance. A bare
MCP name without @version is rejected so the result cannot float to another
version.
List credential buckets shared by all versions of an SDK.
Deactivate exactly one MCP server version. Human-readable references must use
name@version; a version ID can identify the version directly. There is no
implicit latest version.
Download one exact generated SDK version through the Engine. Human-readable
references must use name@version; a version ID can identify the version
directly. There is no implicit latest version.
fused-cli sdk download security-sdk@1.2.0The package is extracted to <out>/fused-sdks/<sdk-name>. When the generated
archive includes an Agent Skill, the CLI installs it centrally at
<out>/fused-sdks/.agents/skills/<skill-name>/SKILL.md so all downloaded SDK
skills share one discovery root.
| Argument | Short | Description | Default |
|---|---|---|---|
--out |
-o |
Output directory for the SDK | "." |
--json |
Print SDK, Version ID, status, and output path as JSON | false |
Export an OpenAPI 3.1 document for one exact immutable generated SDK
version. Use api openapi for an app created with init --api or any SDK
configuration whose generate field is false. The CLI
resolves the Version ID with its ordinary control credential and app.read,
then calls GET /apps/{app_id}/openapi; an SDK execution token does not
authorize this export. The document describes the real
POST /v1/apps/{app_id}/executions route, pins that path to the resolved
Version ID, and declares the SDK execution token as the runtime Bearer
credential.
The command always atomically writes a file and never writes the document to
stdout. YAML is the default; JSON is available for consumers that require it.
The generated server URL is the configured Engine URL. Redirects are rejected,
and the CLI accepts at most 16 MiB from the Engine. Before replacing the file,
the CLI verifies that the document identifies the resolved Version ID and
contains the actual app-execution POST path with the matching app_id enum and
a request-branch count consistent with the declared operation count.
| Argument | Short | Description | Default |
|---|---|---|---|
--operation |
Export one exact physical or Unified operation name; surrounding whitespace is rejected and the value is case-sensitive, non-empty, and at most 512 bytes | "" |
|
--out |
-o |
Atomic output file path | <safe-sdk-name>-<version>.openapi.<format>; Version ID input uses <version-id>.openapi.<format> |
--format |
Output format: yaml or json |
"yaml" |
|
--json |
Print export metadata only (SDK, version, Version ID, operation, operation_count, format, path, bytes, sha256:<64 lowercase hex>, server URL, and status) |
false |
Export the OpenAPI 3.1 execution contract for one exact immutable direct REST
API version created with init --api or represented by an SDK configuration
with generate: false.
fused-cli api openapi billing-api@1.2.0 --out billing-api.openapi.yamlThe export has the same immutable-version resolution, app.read control
credential, operation filtering, atomic file writing, size bound, and document
validation described for sdk openapi. It describes the same Engine execution
route and runtime Bearer token contract. Its generated filename and --json
metadata identify the resource as an API instead of an SDK.
| Argument | Short | Description | Default |
|---|---|---|---|
--operation |
Export one exact physical or Unified operation name | "" |
|
--out |
-o |
Atomic output file path | <safe-api-name>-<version>.openapi.<format>; Version ID input uses <version-id>.openapi.<format> |
--format |
Output format: yaml or json |
"yaml" |
|
--json |
Print export metadata only, using the api field for the resource name |
false |
Invoke one JSON operation through the Engine REST execution route configured by
the global --engine-url / FUSED_ENGINE_URL setting. The SDK execution token
comes from FUSED_SDK_TOKEN, a variable named by --token-env, or stdin with
--token-stdin; management and provider credentials are never substituted.
Generated SDKs retain their broader gRPC transports; this CLI smoke-test surface
accepts only buffered JSON provider responses up to 1 MiB each and bounds a
Unified aggregate response at 17 MiB.
| Argument | Short | Description | Default |
|---|---|---|---|
--params |
One duplicate-free JSON value, @file, or - for stdin; physical operations require an object |
"{}" |
|
--token-env |
Environment variable containing the execution token | "FUSED_SDK_TOKEN" |
|
--token-stdin |
Read the execution token from stdin | false |
|
--environment |
Physical provider environment selector; sugar for --selector |
"" |
|
--target |
Required for Unified: explicit unique target; repeat 1–16 times. Omit for physical operations. | [] |
|
--selector |
Strict physical selector JSON object or @file |
"" |
|
--selectors |
Strict Unified service-selector map or @file |
"" |
|
--idempotency-key |
Stable logical-request key; generated when omitted | "" |
|
--json |
Print Engine endpoint, inferred kind, results, rollbacks, and timing | false |
List canonical Engine execution receipts. Use --all-versions for the entire
SDK and --status, --start, or --end to narrow the page. Requires both
app.read and audit.read.
Add a service to an SDK configuration.
| Argument | Short | Description | Default |
|---|---|---|---|
--version |
Specific version to use for the service | "" |
Remove a service from an SDK configuration. Inherits global flags.
Add OpenAPI operation IDs to an existing SDK configuration.
| Argument | Short | Description | Default |
|---|---|---|---|
--interactive |
-i |
Interactive operation selection | false |
--apply |
Apply changes after adding operation | false |
|
--download |
Download SDK after apply (implies --apply) |
false |
Remove OpenAPI operation IDs from an existing SDK configuration. Inherits global flags.
Generate a named execution token that works across every active or deprecated
version of the SDK. Use --expires-in 4h to grant temporary full-SDK execution
access for testing; omit it for a non-expiring service token. Pass --json to
receive the one-time token, absolute expiry, and metadata as a structured object.
List execution-token metadata for an SDK, including expired tokens that may still need to be inspected or revoked.
Revoke an SDK execution token by name.
Generate a named MCP execution token. It defaults to full access (--allow "*")
with no expiry. Repeat --allow <operation-id> (or pass a comma-separated list)
to narrow the token, and use --expires-in 15m to make it short-lived. Pass
--json to receive the one-time token, absolute expiry, allowlist, binding
metadata, and creation time as a structured object.
List MCP execution-token metadata, including its operation allowlist, expiry, last use, and creation time.
Revoke an MCP execution token by name.
Add webhooks to an existing SDK configuration. Use --interactive to select
webhooks when IDs are omitted.
Remove webhooks from an existing SDK configuration.
Preview changes for webhook registration configurations.
| Argument | Short | Description | Default |
|---|---|---|---|
--json |
Print plan result JSON, including summary and notifications, instead of writing the default receipt | false |
|
--receipt-out |
Write the plan receipt to a specific path | "" |
|
--owner-team |
Optional owning team slug; defaults to the authenticated person | "" |
Apply a generated plan for webhook registration configurations.
| Argument | Short | Description | Default |
|---|---|---|---|
--plan-id |
Apply a specific remote plan ID for a single webhook config | "" |
|
--receipt |
Read a specific plan receipt for a single webhook config | "" |
Validate webhook registration configuration files (kind: webhook).
Preview changes that will be made to your Workspace configuration.
| Argument | Short | Description | Default |
|---|---|---|---|
--json |
Print plan result JSON, including summary and notifications, instead of writing the default receipt | false |
|
--receipt-out |
Write the plan receipt to a specific path | "" |
Apply a generated plan to activate Workspace changes.
| Argument | Short | Description | Default |
|---|---|---|---|
--plan-id |
Apply a specific remote plan ID | "" |
|
--receipt |
Read a specific plan receipt | "" |
Pull selected non-secret service configuration from the Engine into local files. With no scope flag, sync refreshes only services already declared in .fused/workspace.yaml and .fused/services/**/*.yaml. A local declaration absent from the Engine is retained and reported, never deleted.
fused-cli workspace sync
fused-cli workspace sync --file .fused/services/payments.yaml
fused-cli workspace sync --service stripe
fused-cli workspace sync --service stripe@v1,github@v3 --file .fused/services/payments.yaml
fused-cli workspace sync --all--service <service>[@<version>] accepts comma-separated values or repeated flags. An omitted version pulls every active version; an exact version pulls only that active version while retaining unselected local versions. With --file, every selected service is created or updated in that one file; declarations already owned by another local file are transferred to the requested destination while preserving authored policy. Without --file, an undeclared service gets its own .fused/services/<service-slug>.yaml type: services document; colliding readable slugs receive a stable service-identity suffix. --all is the only full import. Sync is Engine-to-local only: it never changes Engine state, and local paths are never sent to the Engine.
| Argument | Short | Description | Default |
|---|---|---|---|
--file |
-f |
Refresh only services declared in this file, or choose the destination with --service/--all |
"" |
--service |
Active service as <service>[@<version>]; comma-separated or repeatable |
[] |
|
--all |
Explicitly import every active workspace service | false |
List buckets and SDK/MCP permission scopes shared for bounded workspace-wide use. The Engine filters and paginates this collection; the CLI does not load the full workspace and filter it locally.
| Argument | Short | Description | Default |
|---|---|---|---|
--resource |
Filter by bucket or app |
"" |
|
--limit |
Maximum rows to return | 20 |
|
--offset |
Rows to skip before reading | 0 |
Grant every authenticated workspace member and eligible app-owning team bounded use of a bucket. Ownership and secret, value, connection, and bucket management remain unchanged.
Remove workspace-wide bucket use. Owner and explicit team bindings remain.
Grant bounded workspace-wide read/use of an SDK or MCP server. Use the
SDK_ID or MCP_ID shown by the list command. The grant applies to every
version. It does not grant lifecycle or token
management and does not replace the runtime token.
Remove workspace-wide SDK or MCP use. Owner and explicit team bindings remain.
List workspace services along with their enabled versions.
| Argument | Short | Description | Default |
|---|---|---|---|
--q |
-q |
Filter visible workspace services by name or slug | "" |
--interactive |
-i |
Interactive service selection | false |
--json |
Print visible workspace services as JSON | false |
Explicitly refresh a bounded batch of activated service versions whose runtime contract snapshot is missing or does not retain a valid generation pin. Each refresh reacquires the exact immutable contract from Registry; it does not derive a pin locally or move a service to another version. The command reports the number found, refreshed, and failed.
This is an advanced workspace-maintenance command. It runs only when invoked
and processes at most --limit candidates per call. Generated init --sdk
uses a narrower recovery path that refreshes only the versions selected by that
SDK candidate.
| Argument | Short | Description | Default |
|---|---|---|---|
--limit |
Maximum missing or unpinned activated service versions to refresh | 100 |
Check if a specific service is available in the workspace and output its enabled versions.
Usage: fused-cli workspace has <service-name>
Resolve enabled workspace services first, then fall back to Registry search.
Without --file, the command immediately activates only the resolved services
through Engine's scoped additive boundary and does not read, create, or update
local workspace files. It prints each canonical service slug and a direct
Engine UI link backed by its stable service ID.
Find and add a service to the workspace. The command first checks the
access-filtered workspace service list. If there is no exact name or slug match,
it uses the Registry's set-based reference resolver with the same lexical
ranking and provider-identity rules as service search. In a terminal, an
ambiguous match opens service selection and every Registry fallback is confirmed
before activation or an explicitly requested file write. In CI or with --no-input, a unique or exact match
is added deterministically; ambiguous callers must supply an exact slug or
service ID.
Provider-qualified additions must use the complete @provider/service-slug
form. A leading @ with a missing, blank, whitespace-containing, or nested
segment is rejected locally before discovery. The read-only service search
command remains lexical and may accept incomplete @ text as a search query.
A workspace lookup permission error is not treated as absence and never falls
through to Registry search. Registry fallback requires catalogue.read.
Passing --file explicitly opts into local config authoring: the command
atomically updates that existing kind: workspace or type: services file and
performs no activation by default. Review it with workspace plan and apply it
through the normal declarative workflow, or add --apply to author the file and
activate only these additions immediately. The command never implicitly targets
.fused/workspace.yaml. service search remains available for explicit
read-only browsing, but is not a prerequisite.
If a later scoped activation fails, the error lists committed, failed, and
unattempted services and prints a stable code, failed phase, composite request
ID, whether the failed target may have committed, and exact ID-pinned recovery
commands. Re-running those commands is safe because the scoped Engine addition
is idempotent.
One --version value applies to every positional service reference. Omit it to
let Engine resolve each service's current public version, or run separate add
commands when the services need different explicit versions.
| Argument | Short | Description | Default |
|---|---|---|---|
--version |
Version to enable; omitted resolves latest during plan or scoped activation | "" |
|
--service-id |
Exact Registry service UUID to activate and, with --file, persist |
"" |
|
--interactive |
-i |
Explicitly require service selection and Registry confirmation (the terminal default) | false |
--apply |
With --file, also activate only the services added by this command |
false |
Delete a service from your Workspace configuration.
| Argument | Short | Description | Default |
|---|---|---|---|
--force |
Force removal when the generated plan action is applied | false |
Deprecate a service in your Workspace configuration.
| Argument | Short | Description | Default |
|---|---|---|---|
--at |
Deprecation effective date in YYYY-MM-DD | "" |
|
--reason |
Reason for deprecation | "" |
List versions enabled in the workspace for a service slug. Supports provider-qualified slugs such as @provider/slug.
List or search operationIds available for an enabled workspace service. Pagination is server-side with or without --q.
| Argument | Short | Description | Default |
|---|---|---|---|
--q |
Search query for the operations action | "" |
|
--version |
Enabled workspace service version; omitted uses the latest enabled version | "" |
|
--limit |
Maximum rows to read | 20 |
|
--offset |
Rows to skip before reading | 0 |
List the service's workspace webhook registrations without exposing signing secrets.
Start an OAuth/OIDC connection session for an end user.
| Argument | Short | Description | Default |
|---|---|---|---|
--bucket |
Workspace bucket name or full UUID (required) | "" |
|
--user-ref |
Stable end-user reference (required) | "" |
|
--type |
OAuth/OIDC family; pass with --auth-name to select an exact scheme |
"" |
|
--auth-name |
Exact OAuth/OIDC scheme; pass with --type |
"" |
|
--auth-ref |
Optional source application registration in the exact form ${bucket.auth.<service>.<auth-name>} |
"" |
|
--resource-input |
Tenant input as key=value; repeatable |
||
--scope |
OAuth/OIDC scope; repeatable |
Standalone consent resolves a reused application registration only from the
explicit --auth-ref. This initialization/debug command has no SDK or MCP
identity selector. Generated runtimes instead use the
services.<target>.auth.ref pinned in their app configuration.
Add an allowed version to a workspace service. Inherits global flags.
Delete a specific version of a service from your Workspace configuration.
| Argument | Short | Description | Default |
|---|---|---|---|
--force |
Force removal | false |
Deprecate a specific version of a service in your Workspace configuration.
| Argument | Short | Description | Default |
|---|---|---|---|
--at |
Deprecation effective date in YYYY-MM-DD | "" |
|
--reason |
Reason for deprecation | "" |
Parse an auto-detected OpenAPI 3, Swagger 2, Google Discovery, AsyncAPI, Postman Collection, WSDL, GraphQL SDL, or introspectable GraphQL endpoint, resolve the provider-version action, and diff it against the live service. Read-only apart from the plan record.
Usage: fused-cli import plan [spec-path] or fused-cli import plan --url <http(s)-url>
| Argument | Short | Description | Default |
|---|---|---|---|
--name |
Service name (required) | "" |
|
--slug |
Account-scoped service slug to create or update (required) | "" |
|
--url |
Import from an online HTTP(S) source | "" |
|
--version |
Source provider version fallback when the specification does not declare one | "" |
|
--destination-version |
Existing provider version to augment; valid only with --target webhooks |
"" |
|
--target |
Contract content to import: all, endpoints, or webhooks |
"endpoints" |
|
--public |
Mark a new service public | false |
|
--category |
Category for a new service | "" |
|
--overlay |
Local overlay file sent unchanged for Registry-owned canonicalization | "" |
|
--receipt-out |
Write the plan receipt to a specific path | "" |
|
--json |
Print the raw plan response as JSON instead of a summary | false |
|
--strict |
Reject warning or error import diagnostics before a plan is persisted | false |
Commit the exact source and optional overlay reviewed by import plan or
import discover. With no flags, this command reads
.fused/.state/import.plan.json; pass --receipt <path> when discovery or
planning wrote a different receipt. The receipt's combined review hash
authorizes the reviewed result; source and overlay hashes are informational.
Service, provider version, contract rows, immutable internal revision, and plan
completion are written atomically.
Import plan/apply requests use a 20-minute timeout unless the global --timeout
flag is explicitly set. A timeout leaves the apply outcome unknown; run the
exact fused-cli import status <operation-id> command reported by the error.
Reapplying the exact plan ID and review hash is idempotent and returns the
stored committed result instead of mutating Registry again.
Registry publication may commit before Engine workspace activation fails. In
that case the command exits non-zero with the structured code
import_workspace_activation_failed, phase workspace_activation, commit state
committed, the request and operation IDs, and an exact pinned
file-free workspace service add ... recovery command. The service is already
published; run the recovery command instead of replaying the import.
| Argument | Short | Description | Default |
|---|---|---|---|
--plan-id |
Apply a specific remote plan ID (requires --review-hash) |
"" |
|
--review-hash |
Combined Registry review hash to pair with --plan-id |
"" |
|
--receipt |
Read a specific plan receipt (default: most recent local receipt) | "" |
|
--json |
Print the validated committed apply proof as JSON | false |
Read the durable outcome of an import apply without retrying its mutation. The
immutable plan ID is also the operation ID. Human output reports status, phase,
commit state, and a compact service/version result after a complete commit;
--json exposes the complete raw status projection. A pending row conservatively
reports an unknown commit state because another apply may still hold its lock;
run the returned status command again instead of replaying apply. Terminal
failed or incomplete historical results include a stable code and a planning
recovery command rather than directing callers into a status loop.
| Argument | Short | Description | Default |
|---|---|---|---|
--json |
Print the raw operation status as JSON | false |
Resolve a machine-readable specification or crawl provider documentation, review exact operations and optional Fused enrichment, then produce the ordinary import-plan receipt. This command never applies the plan.
Usage: fused-cli import discover (--url <http(s)-provider-url> --name <service-name> --slug <service-slug> | --session <session-id>) [--all | --select METHOD:/path]
In an interactive terminal, the command shows the operation selector, opens
the Engine's browser review when the draft is ready, and waits for that review
to finish. --no-browser prints the review URL and waits without opening it.
Global --no-input uses only flags and typed actions: pass --all or repeat
--select, then repeat --accept-proposal or pass --reject-enrichment.
Non-interactive execution does not open or wait for browser review.
On plan_ready, discovery atomically writes
.fused/.state/import.plan.json, replacing the previous receipt at that path.
Use --receipt-out to retain the plan elsewhere. Applying is always a separate
fused-cli import apply invocation.
| Argument | Short | Description | Default |
|---|---|---|---|
--name |
Service name (required unless resuming) | "" |
|
--slug |
Account-scoped service slug to create or update (required unless resuming) | "" |
|
--url |
Provider specification or documentation URL (required unless resuming) | "" |
|
--session |
Resume this authoritative discovery session; cannot change start identity or limits | "" |
|
--version |
Provider version when it cannot be discovered | "" |
|
--source-mode |
Source admission strategy: auto, spec, or docs |
"auto" |
|
--workers |
Requested extraction workers; Registry clamps the value | 0 |
|
--max-pages |
Requested documentation page ceiling; Registry clamps the value | 0 |
|
--max-depth |
Requested documentation crawl depth; Registry clamps the value | 0 |
|
--all |
Explicitly select every discovered operation | false |
|
--select |
Exact operation as METHOD:/path; repeat for several |
[] |
|
--accept-proposal |
Accept one exact enrichment proposal ID; repeat for several | [] |
|
--reject-enrichment |
Reject every optional enrichment proposal | false |
|
--overlay |
Local JSON Fused overlay submitted for reviewed validation | "" |
|
--receipt-out |
Write the resulting import-plan receipt to a specific path | "" |
|
--no-browser |
Print the browser review URL and wait instead of opening it | false |
|
--json |
Print the final plan-ready snapshot as JSON | false |
|
--timeout |
Maximum discovery session duration | 20m0s |
The CLI also supports top-level plan, apply, and validate commands to process all configurations (both SDKs and workspaces).
validate
Validates the syntax and references for all Fused configurations in the target directory or file. Inherits global flags.
plan
| Argument | Short | Description | Default |
|---|---|---|---|
--json |
Print plan result JSON, including summary and notifications, instead of writing the default receipt | false |
|
--receipt-out |
Write the plan receipt to a specific path | "" |
|
--owner-team |
Optional owning team slug for selected SDK, MCP, and webhook configs; defaults to the authenticated person | "" |
apply
| Argument | Short | Description | Default |
|---|---|---|---|
--download |
Download generated SDKs after apply | false |
|
--plan-id |
Apply a specific remote plan ID for a single config | "" |
|
--receipt |
Read a specific plan receipt for a single config | "" |
Plan output includes the Engine's required permission checks. Human output
prints them under Required permissions; --json exposes them as
required_permissions for agents and CI policy checks.