---
title: "Anlyon CLI"
description: "Operate Anlyon from a terminal with the same permissions and the same server-side checks as the API: log in, list actions, invoke one, and decide approvals."
icon: "terminal"
---

The `anlyon` command-line interface operates Anlyon from a terminal with the same permissions and the same server-side checks as the API. The CLI submits requests to Anlyon. Policy evaluation, approvals and provider execution stay on the server. An action invoked from the CLI is checked against the same policies, waits for the same approvals and is recorded the same way as one invoked through the SDK.

Commands are organised by resource: `anlyon actions …`, `anlyon approvals …`, `anlyon runs …`.

**Versioning**

Anlyon is in early beta. The API contract can change before 1.0, and every change is announced in the changelog with a migration note.

The CLI covers authentication, profiles, read commands, invoking actions, declaring what an action changes and deciding approvals. Policy changes and more write commands come in later releases. While the CLI is 0.x, a minor release may add commands, flags, JSON fields and exit codes. A minor release may also remove, rename or change one, and that change carries a changelog entry marked **Breaking**. See [Compatibility](/cli/scripting#compatibility).

## Quickstart

1. **Install**

    The CLI needs Node 20.3 or later. See [Install](/cli/install) for other options.

    ```bash
    npm install -g @anlyonhq/cli
    anlyon --version
    ```

2. **Log in**

    A browser opens. Sign in. If you belong to more than one workspace, Anlyon asks which workspace and environment this login acts in. With one workspace, the login is bound to its default environment.

    ```bash
    anlyon auth login
    ```

3. **Check where you are**

    Shows the user, workspace and environment the credential acts in.

    ```bash
    anlyon whoami
    ```

4. **List the actions you can invoke**

    ```bash
    anlyon actions list
    ```

5. **Invoke one**

    The CLI asks you to confirm, naming the workspace and environment. If the action requires approval, the command exits with code 12 and prints the approval id. Add `--wait 10m` to follow it to its outcome.

    ```bash
    anlyon actions invoke refund_payment --data '{"charge":"ch_123","amount":1200}'
    ```

On a server or in CI, where there is no browser, use an API key instead of `auth login`. See [Scripting and CI](/cli/scripting).

## Command map

```
anlyon auth login | status | logout | scopes
anlyon profile list | use <name>
anlyon whoami
anlyon doctor

anlyon actions list | get <ref> | versions <ref>
anlyon actions invoke <ref> [--data '<json>' | --input <file|->] [--idempotency-key <key>] [--wait 10m]
anlyon actions declare <ref> [--dimension … --amount … --bound …] [--verify-url … --verify-status …] [--governed | --ungoverned]
anlyon invocations list [--action <ref>] [--status <status>] | get <id>
anlyon runs list [--status …] [--search …] [--agent …] [--since …] [--until …] | get <id>
anlyon approvals list [--status pending|…] [--origin …] | get <id>
anlyon approvals approve <id> [--note …] | deny <id> [--note …]
anlyon policies list [--action <name>] | get <id> | versions <id>
anlyon effects list [--action <name>] [--outcome <o>] [--grade <g>] [--unresolved] | get <id>
anlyon impact-limits list [--include-archived] | get <id>
```

`anlyon <command> --help` describes each one. The [command reference](/cli/commands) covers them all with examples.

## How it behaves

- **Decisions happen on the server.** Policy evaluation, approvals and the provider call run there, so a command passes every gate the API applies.
- **A credential is bound to one workspace and environment.** `--environment` asserts which one you expect and stops the command if it differs. The binding stays as it is.
- **`anlyon policies` reads approval policies.** Change them from deployment code with [policy as code](/trust-control/policy-as-code).

## Next steps

**[Install](/cli/install)**

npm, and the standalone executables for Linux, macOS and Windows.

**[Log in and profiles](/cli/authentication)**

Browser login, API keys for automation, and named targets.

**[Command reference](/cli/commands)**

Every command, what it needs, and how writes are confirmed.

**[Scripting and CI](/cli/scripting)**

JSON output, exit codes, environment variables and a CI example.
