Skip to content
Anlyon
Esc
↑↓navigate↵open⌘Jpreview
On this page

Anlyon CLI

Operate Anlyon from a terminal with the same permissions and the same server-side checks as the API: log in, list actions, invoke one, and decide approvals.

The anlyon command-line interface operates Anlyon from a terminal with the same permissions and the same server-side checks as the API. The CLI submits requests to Anlyon. Policy evaluation, approvals and provider execution stay on the server. An action invoked from the CLI is checked against the same policies, waits for the same approvals and is recorded the same way as one invoked through the SDK.

Commands are organised by resource: anlyon actions …, anlyon approvals …, anlyon runs ….

Quickstart

Install

The CLI needs Node 20.3 or later. See Install for other options.

npm install -g @anlyonhq/cli
anlyon --version

Log in

A browser opens. Sign in. If you belong to more than one workspace, Anlyon asks which workspace and environment this login acts in. With one workspace, the login is bound to its default environment.

anlyon auth login

Check where you are

Shows the user, workspace and environment the credential acts in.

anlyon whoami

List the actions you can invoke

anlyon actions list

Invoke one

The CLI asks you to confirm, naming the workspace and environment. If the action requires approval, the command exits with code 12 and prints the approval id. Add --wait 10m to follow it to its outcome.

anlyon actions invoke refund_payment --data '{"charge":"ch_123","amount":1200}'

On a server or in CI, where there is no browser, use an API key instead of auth login. See Scripting and CI.

Command map

anlyon auth login | status | logout | scopes
anlyon profile list | use <name>
anlyon whoami
anlyon doctor

anlyon actions list | get <ref> | versions <ref>
anlyon actions invoke <ref> [--data '<json>' | --input <file|->] [--idempotency-key <key>] [--wait 10m]
anlyon actions declare <ref> [--dimension … --amount … --bound …] [--verify-url … --verify-status …] [--governed | --ungoverned]
anlyon invocations list [--action <ref>] [--status <status>] | get <id>
anlyon runs list [--status …] [--search …] [--agent …] [--since …] [--until …] | get <id>
anlyon approvals list [--status pending|…] [--origin …] | get <id>
anlyon approvals approve <id> [--note …] | deny <id> [--note …]
anlyon policies list [--action <name>] | get <id> | versions <id>
anlyon effects list [--action <name>] [--outcome <o>] [--grade <g>] [--unresolved] | get <id>
anlyon impact-limits list [--include-archived] | get <id>

anlyon <command> --help describes each one. The command reference covers them all with examples.

How it behaves

  • Decisions happen on the server. Policy evaluation, approvals and the provider call run there, so a command passes every gate the API applies.
  • A credential is bound to one workspace and environment. --environment asserts which one you expect and stops the command if it differs. The binding stays as it is.
  • anlyon policies reads approval policies. Change them from deployment code with policy as code.

Next steps

Was this page helpful?