Skip to main content

CLI Reference

Generated from the registered command tree by node scripts/check-docs-drift.mjs --reference. The same script runs in CI and fails the build when this page and the binary disagree, so what you read here is what vagaris --help prints.

Global options on the root command: --version and --help. Every subcommand accepts --help.

vagris is the legacy alias of vagaris; it runs the same command tree and prints a deprecation warning on stderr.

vagaris onboard​

Interactive first-run setup wizard

vagaris onboard [options]
OptionDescriptionDefault
-c, --config <path>Path to config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--bind <mode>Quickstart reachability preset (loopback, lan, tailnet)
-y, --yesAccept quickstart defaults (trusted local loopback unless --bind is set) and start immediately
--runStart Vagaris immediately after saving config
--jsonOutput raw JSON

vagaris doctor​

Run diagnostic checks on your Vagaris setup

vagaris doctor [options]
OptionDescriptionDefault
-c, --config <path>Path to config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--repairAttempt to repair issues automatically
-y, --yesSkip repair confirmation prompts
--jsonOutput raw JSON

vagaris env​

Deployment environment variables, and execution environment operations

vagaris env <subcommand>

Subcommands: vagaris env vars, vagaris env list, vagaris env capabilities, vagaris env get, vagaris env create, vagaris env update, vagaris env delete, vagaris env probe, vagaris env probe-config, vagaris env leases, vagaris env lease

vagaris env vars​

Print environment variables for deployment

vagaris env vars [options]
OptionDescriptionDefault
-c, --config <path>Path to config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)

vagaris env list​

List environments for a company

vagaris env list [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
--status <status>Status filter (active|archived)
--driver <driver>Driver filter (local|ssh|sandbox|plugin)
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris env capabilities​

Show environment driver capabilities available to a company

vagaris env capabilities [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris env get​

Get one environment

vagaris env get [options] <environmentId>
ArgumentRequiredDescription
environmentIdyesEnvironment ID
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris env create​

Create an environment

vagaris env create [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
--name <name> (required)Environment name
--driver <driver> (required)Driver (local|ssh|sandbox|plugin)
--description <text>Environment description
--status <status>Status (active|archived)
--driver-config <json>Driver config as a JSON object
--metadata <json>Metadata as a JSON object
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris env update​

Update an environment

vagaris env update [options] <environmentId>
ArgumentRequiredDescription
environmentIdyesEnvironment ID
OptionDescriptionDefault
--name <name>Environment name
--driver <driver>Driver (local|ssh|sandbox|plugin)
--description <text>Environment description
--status <status>Status (active|archived)
--driver-config <json>Driver config as a JSON object
--metadata <json>Metadata as a JSON object
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris env delete​

Delete an environment

vagaris env delete [options] <environmentId>
ArgumentRequiredDescription
environmentIdyesEnvironment ID
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris env probe​

Probe a saved environment's connectivity

vagaris env probe [options] <environmentId>
ArgumentRequiredDescription
environmentIdyesEnvironment ID
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris env probe-config​

Probe connectivity for an unsaved environment config

vagaris env probe-config [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
--driver <driver> (required)Driver (local|ssh|sandbox|plugin)
--name <name>Environment name
--description <text>Environment description
--driver-config <json>Driver config as a JSON object
--metadata <json>Metadata as a JSON object
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris env leases​

List leases for an environment

vagaris env leases [options] <environmentId>
ArgumentRequiredDescription
environmentIdyesEnvironment ID
OptionDescriptionDefault
--status <status>Status filter (active|released|expired|failed|retained)
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris env lease​

Get one environment lease

vagaris env lease [options] <leaseId>
ArgumentRequiredDescription
leaseIdyesEnvironment lease ID
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris configure​

Update configuration sections

vagaris configure [options]
OptionDescriptionDefault
-c, --config <path>Path to config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
-s, --section <section>Section to configure (llm, database, logging, server, storage, secrets)
--jsonOutput raw JSON

vagaris db:backup​

Create a one-off database backup using current config

vagaris db:backup [options]
OptionDescriptionDefault
-c, --config <path>Path to config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--dir <path>Backup output directory (overrides config)
--retention-days <days>Retention window used for pruning
--filename-prefix <prefix>Backup filename prefix"paperclip"
--jsonPrint backup metadata as JSON

vagaris allowed-hostname​

Allow a hostname for authenticated/private mode access

vagaris allowed-hostname [options] <host>
ArgumentRequiredDescription
hostyesHostname to allow (for example dotta-macbook-pro)
OptionDescriptionDefault
-c, --config <path>Path to config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)

vagaris run​

Bootstrap local setup (onboard + doctor) and run Vagaris

vagaris run [options]
OptionDescriptionDefault
-c, --config <path>Path to config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
-i, --instance <id>Local instance id (default: default)
--bind <mode>On first run, use onboarding reachability preset (loopback, lan, tailnet)
--repairAttempt automatic repairs during doctortrue
--no-repairDisable automatic repairs during doctor
--jsonOutput raw JSON

vagaris version​

Show the installed CLI version and whether an update is available

vagaris version [options]
OptionDescriptionDefault
--jsonOutput raw JSON

vagaris update​

Update the CLI to the latest (or a pinned) published version

vagaris update [options]
OptionDescriptionDefault
--to <version>Exact version to install
--dry-runShow what would change without applying
--jsonOutput raw JSON

vagaris rollback​

Revert the CLI to a previous recorded version

vagaris rollback [options]
OptionDescriptionDefault
--to <version>Exact version to revert to
--dry-runShow what would change without applying
--jsonOutput raw JSON

vagaris uninstall​

Remove all Vagaris artefacts, its data and configuration

vagaris uninstall [options]
OptionDescriptionDefault
-f, --forceSkip safety prompts
--dry-runShow what would be removed without removing anything
--jsonOutput raw JSON

vagaris heartbeat​

Heartbeat utilities

vagaris heartbeat <subcommand>

Subcommands: vagaris heartbeat run

vagaris heartbeat run​

Run one agent heartbeat and stream live logs

vagaris heartbeat run [options]
OptionDescriptionDefault
-a, --agent-id <agentId> (required)Agent ID to invoke
-c, --config <path>Path to config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris server API
--api-key <token>Bearer token for agent-authenticated calls
--source <source>Invocation source (timer | assignment | on_demand | automation)"on_demand"
--trigger <trigger>Trigger detail (manual | ping | callback | system)"manual"
--timeout-ms <ms>Max time to wait before giving up"0"
--jsonOutput raw JSON where applicable
--debugShow raw adapter stdout/stderr JSON chunks

vagaris context​

Manage CLI client context profiles

vagaris context <subcommand>

Subcommands: vagaris context link, vagaris context show, vagaris context list, vagaris context use, vagaris context set, vagaris context clear, vagaris context export

Link local context to existing organization, project, and repository (creates no server-side rows)

vagaris context link [options]
OptionDescriptionDefault
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>Profile name (default: current profile)
--org <id>Organization id (must already exist on server)
--project <id>Project id (must already exist on server)
--repo <url>Repository remote URL or local path
--branch <name>Branch name
--jsonOutput raw JSON

vagaris context show​

Show current context and, when the server is reachable, the live session it resolves to

vagaris context show [options]
OptionDescriptionDefault
--explainShow which layer supplied each value (flag, environment, manifest, profile, config)
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris context list​

List available context profiles

vagaris context list [options]
OptionDescriptionDefault
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--jsonOutput raw JSON

vagaris context use​

Set the active context profile — explicit by construction (the profile is a required argument). A non-interactive command does not inherit this selection; it must still pass its own --profile.

vagaris context use [options] <profile>
ArgumentRequiredDescription
profileyesProfile name
OptionDescriptionDefault
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--jsonOutput raw JSON

vagaris context set​

Set values on a profile

vagaris context set [options]
OptionDescriptionDefault
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>Profile name (default: current profile)
--api-base <url>Default API base URL
--company-id <id>Default company ID
--api-key-env-var-name <name>Env var containing API key (recommended)
--useSet this profile as active
--jsonOutput raw JSON

vagaris context clear​

Clear a profile's stored values, or --all to reset the entire context file. Clearing 'the active profile' implicitly (no profile named) is refused non-interactively — pass --profile explicitly.

vagaris context clear [options] [profile]
ArgumentRequiredDescription
profilenoProfile to clear (defaults to the active profile — refused when non-interactive)
OptionDescriptionDefault
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>Profile to clear (alternative to the positional argument)
--allReset the entire context file to defaults (every profile removed)
--jsonOutput raw JSON

vagaris context export​

Export context profiles with credential metadata redacted (every profile by default, or one with --profile)

vagaris context export [options]
OptionDescriptionDefault
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>Export only this profile (default: every profile)
--jsonOutput raw JSON

vagaris company​

Organization operations

vagaris company <subcommand>

Subcommands: vagaris company list, vagaris company get, vagaris company create, vagaris company update, vagaris company policy, vagaris company feedback:list, vagaris company feedback:export, vagaris company export, vagaris company import, vagaris company delete, vagaris company member, vagaris company invite

vagaris company list​

List companies

vagaris company list [options]
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris company get​

Get one company

vagaris company get [options] <companyId>
ArgumentRequiredDescription
companyIdyesCompany ID
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris company create​

Create a new organization

vagaris company create [options]
OptionDescriptionDefault
--name <name> (required)Organization name
--description <text>Organization description
--budget-monthly-cents <cents>Monthly budget in cents
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris company update​

Update an organization

vagaris company update [options] <companyId>
ArgumentRequiredDescription
companyIdyesCompany ID
OptionDescriptionDefault
--name <name>Organization name
--description <text>Organization description
--status <status>Lifecycle status (active|paused|archived|dormant)
--budget-monthly-cents <cents>Monthly budget in cents
--require-board-approval-for-new-agentsRequire board approval before new agents are hired
--no-require-board-approval-for-new-agentsDo not require board approval before new agents are hired
--brand-color <hex>Brand color, e.g. #336699
--logo-asset-id <id>Logo asset ID
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris company policy​

Show an organization's governance/autonomy policy summary

vagaris company policy [options] <companyId>
ArgumentRequiredDescription
companyIdyesCompany ID
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris company feedback:list​

List feedback traces for a company

vagaris company feedback:list [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
--target-type <type>Filter by target type
--vote <vote>Filter by vote value
--status <status>Filter by trace status
--project-id <id>Filter by project ID
--issue-id <id>Filter by issue ID
--from <iso8601>Only include traces created at or after this timestamp
--to <iso8601>Only include traces created at or before this timestamp
--shared-onlyOnly include traces eligible for sharing/export
--include-payloadInclude stored payload snapshots in the response
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris company feedback:export​

Export feedback traces for a company

vagaris company feedback:export [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
--target-type <type>Filter by target type
--vote <vote>Filter by vote value
--status <status>Filter by trace status
--project-id <id>Filter by project ID
--issue-id <id>Filter by issue ID
--from <iso8601>Only include traces created at or after this timestamp
--to <iso8601>Only include traces created at or before this timestamp
--shared-onlyOnly include traces eligible for sharing/export
--include-payloadInclude stored payload snapshots in the export
--out <path>Write export to a file path instead of stdout
--format <format>Export format: json or ndjson"ndjson"
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris company export​

Export a company into a portable markdown package

vagaris company export [options] <companyId>
ArgumentRequiredDescription
companyIdyesCompany ID
OptionDescriptionDefault
--out <path> (required)Output directory
--include <values>Comma-separated include set: company,agents,projects,issues,tasks,skills"company,agents"
--skills <values>Comma-separated skill slugs/keys to export
--projects <values>Comma-separated project shortnames/ids to export
--issues <values>Comma-separated issue identifiers/ids to export
--project-issues <values>Comma-separated project shortnames/ids whose issues should be exported
--expand-referenced-skillsVendor skill contents instead of exporting upstream references
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris company import​

Import a portable markdown company package from local path, URL, or GitHub

vagaris company import [options] <fromPathOrUrl>
ArgumentRequiredDescription
fromPathOrUrlyesSource path or URL
OptionDescriptionDefault
--include <values>Comma-separated include set: company,agents,projects,issues,tasks,skills
--target <mode>Target mode: new | existing
-C, --company-id <id>Existing target company ID
--new-company-name <name>Name override for --target new
--agents <list>Comma-separated agent slugs to import, or all"all"
--collision <mode>Collision strategy: rename | skip | replace"rename"
--ref <value>Git ref to use for GitHub imports (branch, tag, or commit)
--paperclip-url <url>Alias for --api-base on this command
--yesAccept default selection and skip the pre-import confirmation prompt
--dry-runRun preview only without applying
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris company delete​

Delete a company by ID or shortname/prefix (destructive)

vagaris company delete [options] <selector>
ArgumentRequiredDescription
selectoryesCompany ID or issue prefix (for example PAP)
OptionDescriptionDefault
--by <mode>Selector mode: auto | id | prefix"auto"
--yesRequired safety flag to confirm destructive action
--confirm <value>Required safety value: target company ID or shortname/prefix
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris company member​

Organization membership operations

vagaris company member <subcommand>

Subcommands: vagaris company member list, vagaris company member update

vagaris company member list​

List an organization's members

vagaris company member list [options] <companyId>
ArgumentRequiredDescription
companyIdyesCompany ID
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris company member update​

Update an organization member's role and/or status

vagaris company member update [options] <companyId> <memberId>
ArgumentRequiredDescription
companyIdyesCompany ID
memberIdyesMembership ID
OptionDescriptionDefault
--role <role>Membership role (owner|admin|operator|viewer)
--status <status>Membership status (pending|active|suspended)
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris company invite​

Organization invite operations

vagaris company invite <subcommand>

Subcommands: vagaris company invite create, vagaris company invite list, vagaris company invite revoke

vagaris company invite create​

Create an invite to join an organization

vagaris company invite create [options] <companyId>
ArgumentRequiredDescription
companyIdyesCompany ID
OptionDescriptionDefault
--allowed-join-types <type>Who may accept the invite (human|agent|both)"both"
--human-role <role>Role granted on human acceptance (owner|admin|operator|viewer)
--agent-message <text>Message shown to an accepting agent
--defaults <json>Defaults payload as a JSON object
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris company invite list​

List an organization's invites

vagaris company invite list [options] <companyId>
ArgumentRequiredDescription
companyIdyesCompany ID
OptionDescriptionDefault
--state <state>Filter by state (active|revoked|accepted|expired)
--limit <n>Max rows to return (default 20, max 100)
--offset <n>Rows to skip
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris company invite revoke​

Revoke an invite

vagaris company invite revoke [options] <inviteId>
ArgumentRequiredDescription
inviteIdyesInvite ID
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris issue​

Issue operations

vagaris issue <subcommand>

Subcommands: vagaris issue list, vagaris issue get, vagaris issue create, vagaris issue update, vagaris issue comment, vagaris issue feedback:list, vagaris issue feedback:export, vagaris issue checkout, vagaris issue release

vagaris issue list​

List issues for a company

vagaris issue list [options]
OptionDescriptionDefault
-C, --company-id <id>Company ID
--status <csv>Comma-separated statuses
--assignee-agent-id <id>Filter by assignee agent ID
--project-id <id>Filter by project ID
--match <text>Local text match on identifier/title/description
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris issue get​

Get an issue by UUID or identifier (e.g. ACM-12)

vagaris issue get [options] <idOrIdentifier>
ArgumentRequiredDescription
idOrIdentifieryesIssue ID or identifier
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris issue create​

Create an issue

vagaris issue create [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
--title <title> (required)Issue title
--description <text>Issue description
--status <status>Issue status
--priority <priority>Issue priority
--assignee-agent-id <id>Assignee agent ID
--project-id <id>Project ID
--goal-id <id>Goal ID
--parent-id <id>Parent issue ID
--request-depth <n>Request depth integer
--billing-code <code>Billing code
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris issue update​

Update an issue

vagaris issue update [options] <issueId>
ArgumentRequiredDescription
issueIdyesIssue ID
OptionDescriptionDefault
--title <title>Issue title
--description <text>Issue description
--status <status>Issue status
--priority <priority>Issue priority
--assignee-agent-id <id>Assignee agent ID
--project-id <id>Project ID
--goal-id <id>Goal ID
--parent-id <id>Parent issue ID
--request-depth <n>Request depth integer
--billing-code <code>Billing code
--comment <text>Optional comment to add with update
--hidden-at <iso8601|null>Set hiddenAt timestamp or literal 'null'
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris issue comment​

Add comment to issue

vagaris issue comment [options] <issueId>
ArgumentRequiredDescription
issueIdyesIssue ID
OptionDescriptionDefault
--body <text> (required)Comment body
--reopenReopen if issue is done/cancelled
--resumeRequest explicit follow-up and wake the assignee when resumable
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris issue feedback:list​

List feedback traces for an issue

vagaris issue feedback:list [options] <issueId>
ArgumentRequiredDescription
issueIdyesIssue ID
OptionDescriptionDefault
--target-type <type>Filter by target type
--vote <vote>Filter by vote value
--status <status>Filter by trace status
--from <iso8601>Only include traces created at or after this timestamp
--to <iso8601>Only include traces created at or before this timestamp
--shared-onlyOnly include traces eligible for sharing/export
--include-payloadInclude stored payload snapshots in the response
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris issue feedback:export​

Export feedback traces for an issue

vagaris issue feedback:export [options] <issueId>
ArgumentRequiredDescription
issueIdyesIssue ID
OptionDescriptionDefault
--target-type <type>Filter by target type
--vote <vote>Filter by vote value
--status <status>Filter by trace status
--from <iso8601>Only include traces created at or after this timestamp
--to <iso8601>Only include traces created at or before this timestamp
--shared-onlyOnly include traces eligible for sharing/export
--include-payloadInclude stored payload snapshots in the export
--out <path>Write export to a file path instead of stdout
--format <format>Export format: json or ndjson"ndjson"
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris issue checkout​

Checkout issue for an agent

vagaris issue checkout [options] <issueId>
ArgumentRequiredDescription
issueIdyesIssue ID
OptionDescriptionDefault
--agent-id <id> (required)Agent ID
--expected-statuses <csv>Expected current statuses"todo,backlog,blocked"
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris issue release​

Release issue back to todo and clear assignee

vagaris issue release [options] <issueId>
ArgumentRequiredDescription
issueIdyesIssue ID
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris agent​

Agent operations

vagaris agent <subcommand>

Subcommands: vagaris agent list, vagaris agent get, vagaris agent readiness, vagaris agent local-cli

vagaris agent list​

List agents for a company

vagaris agent list [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris agent get​

Get one agent

vagaris agent get [options] <agentId>
ArgumentRequiredDescription
agentIdyesAgent ID
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris agent readiness​

Show why a seat would or would not take work: the ten readiness axes, what blocks, and what nobody measured

vagaris agent readiness [options] <agentId>
ArgumentRequiredDescription
agentIdyesAgent ID
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris agent local-cli​

Create an agent API key and print shell exports; optionally (opt-in, with consent) symlink local Vagaris skills for Codex/Claude

vagaris agent local-cli [options] <agentRef>
ArgumentRequiredDescription
agentRefyesAgent ID or shortname/url-key
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
--key-name <name>API key label"local-cli"
--install-skillsSymlink Vagaris skills into ~/.codex/skills and ~/.claude/skills (other tools' home directories; off by default, requires --yes or an interactive confirmation)
--yesConsent to the skills install without prompting
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris feature​

Feature convergence operations (ADR-143)

vagaris feature <subcommand>

Subcommands: vagaris feature list, vagaris feature register, vagaris feature propose, vagaris feature show, vagaris feature gaps, vagaris feature context-pack, vagaris feature endstate, vagaris feature recommendation, vagaris feature definition, vagaris feature review, vagaris feature decide, vagaris feature promote, vagaris feature promote-proposal, vagaris feature prior-art, vagaris feature claims, vagaris feature evidence, vagaris feature commission, vagaris feature verify, vagaris feature recompute

vagaris feature list​

List features for a company

vagaris feature list [options]
OptionDescriptionDefault
--product <slug>Filter by OWNED_BY product slug
--capability <slug>Filter by CONSUMES capability slug
--q <text>Substring match on slug or title
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris feature register​

Register a feature from its catalogue row, and ATTACH ITS PROBE — the only CLI path to POST /features, and so the only way to give a feature the registered runbook the server's probe runner executes

vagaris feature register [options]
OptionDescriptionDefault
--catalogue-id <id> (required)Catalogue identity, e.g. VOI-021. The node slug derives from it, so a re-register is the SAME feature
--title <title> (required)Feature title
--source <source> (required)Where this feature came from — the catalogue row, spec or document
--source-hash <hash>Hash of the source row, so a changed source is detectable
--product <slug>OWNED_BY product slug
--capabilities <slugs>Comma-separated capability slugs this feature CONSUMES
--depends-on <ids>Comma-separated catalogue ids this feature DEPENDS_ON
--affects-customers <ids>Comma-separated customer ids this feature AFFECTS
--vendor-org-id <uuid>The company that owns this feature AS VENDOR
--visibility <visibility>internal | customer-specific | selected-customers | partner | public
--confidence <n>0..1; how much the catalogue row itself is trusted
--probe-file <path>The whole probe as JSON, from a file or - for stdin. Mutually exclusive with the --probe-* flags
--probe-url <url>Probe request URL
--probe-method <method>GET | HEAD | POST | OPTIONS (default GET)
--probe-expect-status <code>The status that makes this probe PASS
--probe-expect-body-regex <re>Also require the body to match — a status alone often cannot discriminate
--probe-control-url <url>POSITIVE CONTROL url. Required with any probe: see below
--probe-control-method <method>GET | HEAD | POST | OPTIONS (default GET)
--probe-control-expect-status <code>The status the control must return for the probe's result to mean anything
--probe-control-expect-body-regex <re>Also require the control's body to match
--probe-max-redirects <n>Redirect hops the MAIN step may follow (0-5, default 0)
--probe-on-pass <state>Observed state when the probe passes: ABSENT | SCHEMA_ONLY | API_ONLY | UI_ONLY | DORMANT | PARTIAL | GATED | LIVE | CLAIMED | EXTERNAL
--probe-on-fail <state>Observed state when the probe fails
--probe-dimension <n>The dimension this probe observes
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris feature propose​

Propose a feature that does not exist yet — an idea with (optionally) a checkable signal, before any definition is written. Idempotent on slug (C18).

vagaris feature propose [options]
OptionDescriptionDefault
--slug <slug> (required)Feature slug
--name <name> (required)Feature name
--product <slug>OWNED_BY product slug
--capability <slug>CONSUMES capability slug
--signal-kind <kind>customer_request | competitor | incident | roadmap | research | internal — requires --signal-summary and --signal-citation
--signal-summary <text>What the signal says
--signal-citation <ref>REQUIRED with a signal: a ticket URL, call id, incident number — something checkable
--signal-occurred-at <iso8601>When the signal occurred
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris feature show​

Get a feature by slug or id, with derived state (and maturity at a target)

vagaris feature show [options] <id>
ArgumentRequiredDescription
idyesFeature slug (e.g. voi-006) or full node id (feature:voi-006)
OptionDescriptionDefault
--target <maturity>Compute maturity against this target
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris feature gaps​

List gap dimension assessments (applicable/blocked) for a feature at a target

vagaris feature gaps [options] <id>
ArgumentRequiredDescription
idyesFeature slug or node id
OptionDescriptionDefault
--target <maturity> (required)Target maturity — a gap is always relative to a target
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris feature context-pack​

The CONTEXT PACK for one feature: derived state, what is blocked, what changed since a cursor, the next warranted action and why (derived on read, never stored), completeness, and pointers to the operations that expand each part

vagaris feature context-pack [options] <id>
ArgumentRequiredDescription
idyesFeature slug (e.g. voi-006) or full node id
OptionDescriptionDefault
--since <cursor>Only report changes after this cursor (identity.cursor from a previous pack)
--maturity <tier>Target maturity the evaluation behind next is computed against (default TENANT_ZERO_PROVEN)
--hold <dimension=holder>Declare that another lane holds a dimension's change site (repeatable; can only demote)[]
--detail <level>full (default) or summary (counts without items)
--limit-blocked <n>Most blocked items to include
--limit-changed <n>Most changed items to include
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris feature endstate​

How this feature SHOULD look — the full 47-dimension end-state (target → current → gap → proof, by layer) + connected execution

vagaris feature endstate [options] <id>
ArgumentRequiredDescription
idyesFeature slug (e.g. voi-006) or full node id
OptionDescriptionDefault
--target <maturity>Target maturity tier (TENANT_ZERO_PROVEN | PAID_PRODUCTION | ENTERPRISE; default TENANT_ZERO_PROVEN)
--seeded <mode>Set to 'exclude' to derive from the graph alone, ignoring hand-seeded rows (the discriminating test)
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris feature recommendation​

The RECOMMENDATION for a feature's definition — headline, why (evidence-backed), the proposed target, the four material decisions, risk, every build disposition considered (RESUME … BUILD) with the one chosen, and whether a Product department seat may ratify it autonomously or the Product Authority must

vagaris feature recommendation [options] <id>
ArgumentRequiredDescription
idyesFeature slug or node id
OptionDescriptionDefault
--target <maturity>Target maturity (default: TENANT_ZERO_PROVEN)
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris feature definition​

The Definition path: an immutable version chain per feature, reviewed and decided before it may be commissioned

vagaris feature definition <subcommand>

Subcommands: vagaris feature definition get, vagaris feature definition packet, vagaris feature definition authority, vagaris feature definition write

vagaris feature definition get​

Read the CURRENT definition version, or null if nobody has opened one yet

vagaris feature definition get [options] <id>
ArgumentRequiredDescription
idyesFeature slug or node id
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris feature definition packet​

Render the IMMUTABLE decision packet for one definition version — content, every review, dissent named separately, alternatives, and the content hash a decision must cite. The version is named, never resolved as 'current'

vagaris feature definition packet [options] <id>
ArgumentRequiredDescription
idyesFeature slug or node id
OptionDescriptionDefault
--version <uuid> (required)The definition_version_id the packet is rendered for
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris feature definition authority​

Preview, per decision kind, whether YOU may take it on this feature — the same check the decide door runs, read-only, deciding nothing. Ratify-family kinds need product:ratify_feature; RETURN_FOR_REVISION / DEFER / REJECT deliberately do not

vagaris feature definition authority [options] <id>
ArgumentRequiredDescription
idyesFeature slug or node id
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris feature definition write​

Append an immutable new definition version (POST, never PUT — editing a definition costs its reviews, so this never replaces one in place)

vagaris feature definition write [options] <id>
ArgumentRequiredDescription
idyesFeature slug or node id
OptionDescriptionDefault
--content-file <path> (required)JSON file for the definition content (product/experience/architecture/commercial/production/proof sections, all optional); use - to read stdin
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris feature review​

Reviews of a definition version, performed by the organization's own registered agents (C22)

vagaris feature review <subcommand>

Subcommands: vagaris feature review record, vagaris feature review list

vagaris feature review record​

Record a review — its proposed targets populate the 47 dimensions as PROPOSALS (D2); a review confers no authority by itself, a decision does

vagaris feature review record [options] <id>
ArgumentRequiredDescription
idyesFeature slug or node id
OptionDescriptionDefault
--definition-version <uuid> (required)The definition_version_id being reviewed
--agent <uuid> (required)The reviewing agent id — must be a real agent registered in this company
--lens <lens> (required)The question this review answers. One of: product, design, research, architecture, engineering, security, sre, gtm, finance, support, legal, data
--verdict <verdict> (required)One of: ready, not_ready, needs_evidence, reject
--summary <text>Review summary
--sections <csv>Comma-separated sections this review covers: product,experience,architecture,commercial,production,proof
--findings <csv>Comma-separated findings
--targets-file <path>JSON array of proposed targets ({dimension, target_maturity, target_requirement, target_rationale?, proof_requirement?, owner?, maturity_gate?}); use - to read stdin
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris feature review list​

List every review recorded against this feature's definition

vagaris feature review list [options] <id>
ArgumentRequiredDescription
idyesFeature slug or node id
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris feature decide​

The stored authority event over a definition (RATIFY family / MERGE / MOVE / ADOPT_EXTERNAL / REJECT / DEFER / NEEDS_EVIDENCE / RETURN_FOR_REVISION). Ratify-family kinds require a HUMAN principal holding product:ratify_feature

vagaris feature decide [options] <id>
ArgumentRequiredDescription
idyesFeature slug or node id
OptionDescriptionDefault
--kind <kind> (required)One of: RATIFY, RATIFY_AS_EXPERIMENT, RATIFY_FOR_LATER_MATURITY, MERGE, MOVE_TO_CAPABILITY, MOVE_TO_PRODUCT, ADOPT_EXTERNAL, REJECT, DEFER, NEEDS_EVIDENCE, RETIRE_LEGACY_SPEC, RETURN_FOR_REVISION, APPROVE_RELEASE
--definition-version <uuid>The definition_version_id this decision is about
--target <maturity>Target maturity — required when --ratified-dimensions names any dimension
--ratified-dimensions <csv>Comma-separated dimension numbers this decision confers authority over — not "all 47"
--target-selections-file <path>JSON array of {dimension, review_id} — the tie-break when two reviews propose different targets for one dimension; use - to read stdin
--merged-into <featureNodeId>MERGE: the feature that survives
--moved-to <subjectId>MOVE_TO_CAPABILITY / MOVE_TO_PRODUCT: the new owner
--deferred-trigger <condition>DEFER: a named condition, never a date
--mandate-obligation-kind <kind>ADOPT_EXTERNAL: contract | regulation | standard | exception
--mandate-reference <ref>ADOPT_EXTERNAL: the obligation being adopted
--mandate-citation <text>ADOPT_EXTERNAL: citation for the obligation
--rationale <text>Why
--supersedes <decisionId>A reversal: the decision this one replaces
-y, --yesWhen the server answers step_up_required, run the step-up re-authentication and retry once without asking
--experiment-spend <amount>RATIFY_AS_EXPERIMENT: the spend the experiment commits — compared against a Product department seat's delegated create_experiments_below threshold
--experiment-currency <iso4217>RATIFY_AS_EXPERIMENT: ISO-4217 currency of --experiment-spend (e.g. INR)
--release-commit-sha <sha>APPROVE_RELEASE: the full 40-character commit the candidate was built from — an abbreviation is a prefix and is refused
--release-image-digest <digest>APPROVE_RELEASE: the OCI digest the candidate IS, sha256: followed by 64 hex characters. Omit it where the release produces no image
--release-image-absentAPPROVE_RELEASE: state that this release produces NO image, recording image_digest as null — a different fact from omitting the digest
--release-environment <slug>APPROVE_RELEASE: which environment this approval is for, e.g. production
--packet-content-hash <sha256>The 64-hex content hash of the decision packet the human actually read, binding this decision to that exact version. Omit it when no packet was rendered
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris feature promote​

Promote a ratified definition to the initiative the commission flow already understands — creates an opportunity, confers no new authority

vagaris feature promote [options] <id>
ArgumentRequiredDescription
idyesFeature slug or node id
OptionDescriptionDefault
--decision <decisionId> (required)The RATIFY-family decision authorising this promotion
--target <maturity> (required)Target maturity
--thesis <text>Why this is worth building now
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris feature promote-proposal​

Promote ONE uncontested review proposal to the target row the organization holds (D2). Confers no authority — the row derives PROPOSED and is not actionable; a contested dimension is refused and belongs at decide

vagaris feature promote-proposal [options] <id>
ArgumentRequiredDescription
idyesFeature slug or node id
OptionDescriptionDefault
--dimension <n> (required)The dimension number whose uncontested proposal is promoted
--target <maturity> (required)The target maturity the proposal was made against
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris feature prior-art​

Prior art as a real search with citations (C24) — what already exists, and whether it discharges a gap

vagaris feature prior-art <subcommand>

Subcommands: vagaris feature prior-art list, vagaris feature prior-art search, vagaris feature prior-art record

vagaris feature prior-art list​

List prior-art candidates recorded against this feature

vagaris feature prior-art list [options] <id>
ArgumentRequiredDescription
idyesFeature slug or node id
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

Search the organization's own estate for prior art — what already exists that this feature could reuse

vagaris feature prior-art search [options] <id>
ArgumentRequiredDescription
idyesFeature slug or node id
OptionDescriptionDefault
--q <text> (required)Search text
--limit <n>Maximum candidates to return
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris feature prior-art record​

Record a prior-art candidate — a citation is required even for kind=none (it records WHERE you looked and found nothing)

vagaris feature prior-art record [options] <id>
ArgumentRequiredDescription
idyesFeature slug or node id
OptionDescriptionDefault
--kind <kind> (required)One of: internal_code, internal_capability, other_product, oss, managed, none
--name <name> (required)Candidate name
--citation <ref> (required)Something checkable — a repo, a doc, a vendor page
--evidence <csv>Comma-separated evidence notes
--recommendation <rec>One of: NO_WORK, RESUME, UPGRADE, WIRE, CONVERGE_DUPLICATES, EXTRACT_TO_CAPABILITY, HARVEST_OSS, ADOPT_OSS, ADOPT_MANAGED, BUILD_DELTA, RETIRE
--rationale <text>Why
--chosenMark this candidate as the chosen one (at most one per feature)
--discharges-dimension <n>The dimension number this candidate discharges
--discharges-claim-evidence-id <id>The claim evidence id this candidate discharges
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris feature claims​

List claims (what someone SAYS is true) for a feature

vagaris feature claims [options] <id>
ArgumentRequiredDescription
idyesFeature slug or node id
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris feature evidence​

List all evidence (claims, assertions, findings, maturity snapshots) for a feature

vagaris feature evidence [options] <id>
ArgumentRequiredDescription
idyesFeature slug or node id
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris feature commission​

Raise an opportunity to close one or more gap assessments on a feature

vagaris feature commission [options] <id>
ArgumentRequiredDescription
idyesFeature slug or node id
OptionDescriptionDefault
--target <maturity> (required)Target maturity the commission is against
--gaps <ids> (required)Comma-separated gap_assessment_id list (dimension assessment UUIDs)
--thesis <text>Why this gap is worth closing
--disposition <disposition>Advisory suggested_disposition — does not decide anything (see opportunity decide)
--experiment <decision-id>A RATIFY_AS_EXPERIMENT decision id authorising this commission despite its targets not being ratified. The server verifies it names a live experiment on THIS feature, at THIS maturity, covering every named dimension — this flag transmits the pointer, it does not assert anything.
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris feature verify​

Trigger the server's own probe against a feature's registered probe (board/operator actors only)

vagaris feature verify [options] <id>
ArgumentRequiredDescription
idyesFeature slug or node id
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris feature recompute​

Recompute + persist a maturity snapshot for a feature at a target

vagaris feature recompute [options] <id>
ArgumentRequiredDescription
idyesFeature slug or node id
OptionDescriptionDefault
--target <maturity> (required)Target maturity to recompute against
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris assimilation​

What every source says about a product, capability or feature (source-assimilation contract §8)

vagaris assimilation <subcommand>

Subcommands: vagaris assimilation corpus, vagaris assimilation sources, vagaris assimilation source, vagaris assimilation occurrence, vagaris assimilation feature, vagaris assimilation candidates, vagaris assimilation review-queue, vagaris assimilation confirm-binding, vagaris assimilation reject-binding, vagaris assimilation import, vagaris assimilation import-approval, vagaris assimilation imports, vagaris assimilation import-result, vagaris assimilation feature-sources

vagaris assimilation corpus​

The corpus accounting: discovered, classified, segmented, extracted, bound, ambiguous, unbound

vagaris assimilation corpus [options]
OptionDescriptionDefault
--repository <name>Filter by repository
--source-class <class>adr | plan | spec | audit | ledger | runbook | generated_view | status | narrative | contract | evidence | unclassified
--disposition <value>A §5 ingestion disposition
--entity-kind <kind>feature | product | capability | service | surface (requires --entity-id)
--entity-id <id>Sources whose spans bind to this entity
--claim-authority-tier <tier>Sources carrying at least one claim at this rung of the §4 ladder
--captured-after <iso8601>Freshness bound on the artifact's capture time
--min-binding-confidence <n>Sources with a binding at or above this confidence (0-1)
--ingestion-run <uuid>Sources this run FIRST CAPTURED (not the corpus as that run saw it)
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris assimilation sources​

The sources themselves, under the same filters as corpus

vagaris assimilation sources [options]
OptionDescriptionDefault
--repository <name>Filter by repository
--source-class <class>adr | plan | spec | audit | ledger | runbook | generated_view | status | narrative | contract | evidence | unclassified
--disposition <value>A §5 ingestion disposition
--entity-kind <kind>feature | product | capability | service | surface (requires --entity-id)
--entity-id <id>Sources whose spans bind to this entity
--claim-authority-tier <tier>Sources carrying at least one claim at this rung of the §4 ladder
--captured-after <iso8601>Freshness bound on the artifact's capture time
--min-binding-confidence <n>Sources with a binding at or above this confidence (0-1)
--ingestion-run <uuid>Sources this run FIRST CAPTURED (not the corpus as that run saw it)
--limit <n>Rows per page (default 50, max 500)
--offset <n>Rows to skip
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris assimilation source​

One source: its versions, spans, claims, linked entities and findings

vagaris assimilation source [options]
OptionDescriptionDefault
--id <artifactId> (required)Source artifact id
--limit <n>Spans to return (default 200, max 1000)
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris assimilation occurrence​

Open one exact span — the thing a claim points at, rather than the file it sits in

vagaris assimilation occurrence [options]
OptionDescriptionDefault
--id <occurrenceId> (required)Source occurrence id
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris assimilation feature​

What sources say about one feature: claims, sources, near-misses, evidence basis, contradictions

vagaris assimilation feature [options]
OptionDescriptionDefault
--id <featureId> (required)Feature id as claims name it
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris assimilation candidates​

Weigh EVERY assessment of one feature against the RUNNING artifact: one deficiency class and one response (RELEASE · VERIFY · RECONCILE · RESUME · WAIT_LINK · INVESTIGATE · DEFINE · IMPLEMENT · DECLINE) per dimension, evidence bound to feature · organization · environment · surface · revisions · artifacts · time, existing work, ONE bounded action or a decline naming the next legitimate action, and whether the assessment is complete (canonical dimension ids + model version)

vagaris assimilation candidates [options] <featureId>
ArgumentRequiredDescription
featureIdyesFeature id as the assessments name it (feature:<slug>)
OptionDescriptionDefault
--maturity <tier>Target maturity the classes are computed against (default TENANT_ZERO_PROVEN)
--hold <dimension=holder>Declare that another lane holds a dimension's change site (repeatable; a declared fact, never probed)[]
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris assimilation review-queue​

The spans that need human judgment, by reason, with what each reason means

vagaris assimilation review-queue [options]
OptionDescriptionDefault
--reason <reason>One §8 review reason
--limit <n>Items to return (default 100, max 500)
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris assimilation confirm-binding​

Confirm the candidate a binder would not guess at: the span becomes bound by human review

vagaris assimilation confirm-binding [options]
OptionDescriptionDefault
--occurrence <occurrenceId> (required)The span from the review queue
--method <method>Required only when two methods hold a pending candidate on this span
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris assimilation reject-binding​

Reject the candidate: the pair is recorded as refused so the binder will not re-propose it

vagaris assimilation reject-binding [options]
OptionDescriptionDefault
--occurrence <occurrenceId> (required)The span from the review queue
--reason <text> (required)Why the pair is wrong — the next reader needs it
--method <method>Required only when two methods hold a pending candidate on this span
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris assimilation import​

Propose (the product prepares the manifest), preview, approve and run a pinned selection of sources for one subject through the product import operation; approving a proposed manifest runs its import

vagaris assimilation import [options]
OptionDescriptionDefault
--subject <entityId>The subject entity id, e.g. feature:voi-006 (or subjectEntityId in the manifest)
--source <selector><repository>:<path>@<revision>[#<sha256>] — repeatable; every source is pinned[]
--manifest <file>A JSON file shaped like the manifest: { subjectEntityId, sources, expected?, note? }
--expected-occurrences <n>The expected span count — an expectation the result explains against, never a quota
--expected-claims <n>The expected claim count — recorded with --expected-occurrences
--note <text>A human note carried in the run's lineage; never interpreted
--proposeHave the product PREPARE the manifest for --subject from the declared corpus (or re-propose a prior run's with --from-run), preview it, and file the mission that waits for the approval
--from-run <runId>With --propose: re-propose the pinned manifest that run recorded (a re-import), instead of discovering
--previewShow what the import would do (sources, statements, related records, supersessions, unresolved, permissions, expected writes, prohibited effects) and the manifest hash; writes nothing
--approve <manifestHash>Record your approval of this manifest — the hash a --preview printed. Human-borne credential only
--approval <approvalId>Run the import under a recorded approval; prints the receipt
--decision-note <text>With --approve: your note on the approval; never interpreted
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris assimilation import-approval​

One import approval: the manifest hash it binds, who recorded it, what it authorizes and prohibits, and the runs that used it

vagaris assimilation import-approval [options]
OptionDescriptionDefault
--id <approvalId> (required)Approval id
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris assimilation imports​

Every import run in this organization, newest first

vagaris assimilation imports [options]
OptionDescriptionDefault
--limit <n>Rows per page (default 50, max 500)
--offset <n>Rows to skip
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris assimilation import-result​

One import as persisted: pinned sources, lineage, claims, statement lineages, differences, findings

vagaris assimilation import-result [options]
OptionDescriptionDefault
--id <runId> (required)Import run id
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris assimilation feature-sources​

The owner view of one feature: selected versions, statements, conflicts, unresolved interpretations, import history

vagaris assimilation feature-sources [options]
OptionDescriptionDefault
--id <featureId> (required)Feature id as claims name it
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris definition​

Definition-package operations (the forward path, ADR-143)

vagaris definition <subcommand>

Subcommands: vagaris definition render, vagaris definition get, vagaris definition authority, vagaris definition write, vagaris definition decide

vagaris definition render​

Render the Markdown end-state specification for a feature/product/capability's definition package

vagaris definition render [options] <kind> <id>
ArgumentRequiredDescription
kindyesSubject kind: feature | product | capability
idyesFeature slug/node id, or product/capability slug
OptionDescriptionDefault
--target <maturity>Target maturity tier (TENANT_ZERO_PROVEN | PAID_PRODUCTION | ENTERPRISE; default TENANT_ZERO_PROVEN)
--out <file>Write the rendered markdown to this file instead of stdout
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris definition get​

Read the CURRENT definition version of a feature, product or capability — or null if nobody has opened one yet

vagaris definition get [options] <kind> <id>
ArgumentRequiredDescription
kindyesSubject kind: feature | product | capability
idyesFeature slug/node id, or product/capability slug
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris definition authority​

Preview, per decision kind, whether YOU may take it on this feature, product or capability — the same check the decide door runs, read-only, deciding nothing. Ratify-family kinds need product:ratify_feature (org-wide for a capability); RETURN_FOR_REVISION / DEFER / REJECT deliberately do not

vagaris definition authority [options] <kind> <id>
ArgumentRequiredDescription
kindyesSubject kind: feature | product | capability
idyesFeature slug/node id, or product/capability slug
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris definition write​

Append an immutable new definition version for a feature, product or capability (POST, never PUT — a baseline's reviews are bound to the version they reviewed)

vagaris definition write [options] <kind> <id>
ArgumentRequiredDescription
kindyesSubject kind: feature | product | capability
idyesFeature slug/node id, or product/capability slug
OptionDescriptionDefault
--content-file <path> (required)JSON file for the definition content (product/experience/architecture/commercial/production/proof sections, all optional); use - to read stdin
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris definition decide​

The stored authority event over a feature, product or capability definition. A product/capability RATIFY is what makes a BASELINE target the organization holds; ratify-family kinds require a HUMAN principal holding product:ratify_feature

vagaris definition decide [options] <kind> <id>
ArgumentRequiredDescription
kindyesSubject kind: feature | product | capability
idyesFeature slug/node id, or product/capability slug
OptionDescriptionDefault
--kind <kind> (required)One of: RATIFY, RATIFY_AS_EXPERIMENT, RATIFY_FOR_LATER_MATURITY, MERGE, MOVE_TO_CAPABILITY, MOVE_TO_PRODUCT, ADOPT_EXTERNAL, REJECT, DEFER, NEEDS_EVIDENCE, RETIRE_LEGACY_SPEC, RETURN_FOR_REVISION, APPROVE_RELEASE
--definition-version <uuid>The definition_version_id this decision is about
--target <maturity>Target maturity — required when --ratified-dimensions names any dimension
--ratified-dimensions <csv>Comma-separated dimension numbers this decision confers authority over — not "all 47"
--target-selections-file <path>JSON array of {dimension, review_id} — the tie-break when two reviews propose different targets for one dimension; use - to read stdin
--merged-into <featureNodeId>MERGE: the feature that survives
--moved-to <subjectId>MOVE_TO_CAPABILITY / MOVE_TO_PRODUCT: the new owner
--deferred-trigger <condition>DEFER: a named condition, never a date
--mandate-obligation-kind <kind>ADOPT_EXTERNAL: contract | regulation | standard | exception
--mandate-reference <ref>ADOPT_EXTERNAL: the obligation being adopted
--mandate-citation <text>ADOPT_EXTERNAL: citation for the obligation
--rationale <text>Why
--supersedes <decisionId>A reversal: the decision this one replaces
-y, --yesWhen the server answers step_up_required, run the step-up re-authentication and retry once without asking
--experiment-spend <amount>RATIFY_AS_EXPERIMENT: the spend the experiment commits — compared against a Product department seat's delegated create_experiments_below threshold
--experiment-currency <iso4217>RATIFY_AS_EXPERIMENT: ISO-4217 currency of --experiment-spend (e.g. INR)
--release-commit-sha <sha>APPROVE_RELEASE: the full 40-character commit the candidate was built from — an abbreviation is a prefix and is refused
--release-image-digest <digest>APPROVE_RELEASE: the OCI digest the candidate IS, sha256: followed by 64 hex characters. Omit it where the release produces no image
--release-image-absentAPPROVE_RELEASE: state that this release produces NO image, recording image_digest as null — a different fact from omitting the digest
--release-environment <slug>APPROVE_RELEASE: which environment this approval is for, e.g. production
--packet-content-hash <sha256>The 64-hex content hash of the decision packet the human actually read, binding this decision to that exact version. Omit it when no packet was rendered
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris governance​

Governance authority operations for the selected company

vagaris governance <subcommand>

Subcommands: vagaris governance verify-step-up, vagaris governance step-up-policy

vagaris governance verify-step-up​

Run the ratification step-up policy property (OW-1076): drives the real decide door with six in-process credentials — board key denied, stale MFA denied, single-factor denied, wrong org denied, wrong authority denied, fresh MFA allowed — and records ONE evidence record ratification.step_up_policy on the organization. The actor is injected past bearer verification (token_signature_verified: false on the record); requires product:ratify_feature or instance admin

vagaris governance verify-step-up [options]
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris governance step-up-policy​

Show the latest recorded run of the ratification step-up policy property, without running it

vagaris governance step-up-policy [options]
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris dev​

Host a run locally under a server-issued lease (claim → verify → worktree → baseline → governed spawn → evidence)

vagaris dev [options]
OptionDescriptionDefault
-a, --agent-id <agentId> (required)Agent id whose run to claim
-r, --run-id <runId> (required)Heartbeat run id to claim (must be queued)
-i, --issue-id <issueId>Issue being worked (if any)
--scope <scope>Scope the CLI is working in (if known)
--adapter <type>Executor adapter (default claude-local)
--node-id <id>Machine node id presented (registered node / enrollment)
--agentDelegated agent mode: run the native frontend inside a Vagaris session envelope
--nativeNative mode: same envelope, metadata.delegated=false
--no-spawnResolve the claim+lease+envelope+governance decision but do not execute the child
--no-worktreeDo not create an isolated per-run worktree
--no-baselineSkip the pre-run baseline control capture
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris approval​

Approval operations

vagaris approval <subcommand>

Subcommands: vagaris approval list, vagaris approval get, vagaris approval create, vagaris approval approve, vagaris approval explain, vagaris approval reject, vagaris approval request-revision, vagaris approval supersede, vagaris approval resubmit, vagaris approval comment

vagaris approval list​

List approvals for a company

vagaris approval list [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
--status <status>Status filter
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris approval get​

Get one approval

vagaris approval get [options] <approvalId>
ArgumentRequiredDescription
approvalIdyesApproval ID
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris approval create​

Create an approval request

vagaris approval create [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
--type <type> (required)Approval type (hire_agent|approve_ceo_strategy)
--payload <json> (required)Approval payload as JSON object
--requested-by-agent-id <id>Requesting agent ID
--issue-ids <csv>Comma-separated linked issue IDs
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris approval approve​

Approve an approval request

vagaris approval approve [options] <approvalId>
ArgumentRequiredDescription
approvalIdyesApproval ID
OptionDescriptionDefault
--decision-note <text>Decision note
--chosen-owner <owner>The accountable owner an ownership_decision names; the server refuses an ownership decision without one
--off-list-reason <text>Why the chosen owner is not one of the proposed candidates
--decided-by-user-id <id>Ignored: the server records the authenticated principal as the decider
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris approval explain​

Explain which proof of authority you would present for an approval, whether the server would accept it, and why. Decides nothing

vagaris approval explain [options] <approvalId>
ArgumentRequiredDescription
approvalIdyesApproval ID
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris approval reject​

Reject an approval request

vagaris approval reject [options] <approvalId>
ArgumentRequiredDescription
approvalIdyesApproval ID
OptionDescriptionDefault
--decision-note <text>Decision note
--decided-by-user-id <id>Ignored: the server records the authenticated principal as the decider
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris approval request-revision​

Request revision for an approval

vagaris approval request-revision [options] <approvalId>
ArgumentRequiredDescription
approvalIdyesApproval ID
OptionDescriptionDefault
--decision-note <text>Decision note
--decided-by-user-id <id>Ignored: the server records the authenticated principal as the decider
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris approval supersede​

Settle an approval whose premise expired - not a decision, records no decider

vagaris approval supersede [options] <approvalId>
ArgumentRequiredDescription
approvalIdyesApproval ID
OptionDescriptionDefault
--reason <text>Why the question stopped being live (min 24 chars)
--superseded-by <approvalId>The open approval that carries this question forward
--ruling-ref <ref>The ruling that resolved it
--retirement-ref <ref>The retirement record that voided the premise
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris approval resubmit​

Resubmit an approval (optionally with new payload)

vagaris approval resubmit [options] <approvalId>
ArgumentRequiredDescription
approvalIdyesApproval ID
OptionDescriptionDefault
--payload <json>Payload JSON object
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris approval comment​

Add comment to an approval

vagaris approval comment [options] <approvalId>
ArgumentRequiredDescription
approvalIdyesApproval ID
OptionDescriptionDefault
--body <text> (required)Comment body
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris activity​

Activity log operations

vagaris activity <subcommand>

Subcommands: vagaris activity list

vagaris activity list​

List company activity log entries

vagaris activity list [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
--agent-id <id>Filter by agent ID
--entity-type <type>Filter by entity type
--entity-id <id>Filter by entity ID
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris plan​

Produce a server-derived plan for a mutation, and print its preview

vagaris plan [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
--namespace <name> (required)Operation namespace (e.g. company)
--operation <name> (required)Operation name (e.g. update)
--target <id>Target id; defaults to the company id
--set <field=value...>Field to change; repeatable
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris apply​

Apply a plan produced by vagaris plan; refused if the state has moved since

vagaris apply [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
--token <planToken> (required)The planToken printed by vagaris plan
-y, --yesSkip the confirmation prompt (does NOT grant permission)
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris access​

Company member access — list, grant and revoke permissions

vagaris access <subcommand>

Subcommands: vagaris access members, vagaris access grant, vagaris access grants, vagaris access revoke

vagaris access members​

List company members with their roles and permission grants

vagaris access members [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris access grant​

Grant a member a permission, preserving every grant they already hold

vagaris access grant [options] <memberId>
ArgumentRequiredDescription
memberIdyesCompany membership id (see access members)
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
--permission <key> (required)Permission key. One of: agents:create, environments:manage, users:invite, users:manage_permissions, tasks:assign, tasks:assign_scope, tasks:manage_active_checkouts, joins:approve, governance:decide_ownership, product:ratify_feature, product:reject_feature, product:return_for_revision, product:defer_feature, capability:ratify_contract, architecture:ratify_contract, release:approve_production, commercial:approve_offer, pricing:approve, gtm:publish_claim, gtm:publish_roadmap_commitment, assimilation:import, runs:claim
--scope-json <json>Raw JSON scope object, merged under the structured flags below
--reason <text>Why this authority is held (required for a decision-class permission)
--retires-when <condition>The deterministic revoke trigger — the named condition that ends this authority (role change, replacement, departure, scope transfer); a condition, never a date (required for a decision-class permission)
--review-by <YYYY-MM-DD>Date someone undertakes to review this grant by — a review date, NOT an expiry: past it the grant still authorizes and every surface reports the review as overdue (required for a decision-class permission)
--products <csv>Product slugs this grant is scoped to. A DECISION-CLASS permission takes ONE product per grant — run the command once per product; '*' spells org-wide breadth
--features <csv>Comma-separated feature ids this grant is scoped to
--environment <csv>Environment slugs a release:approve_production grant is narrowed to, e.g. production. Absent means the authority is NOT narrowed by environment — it reaches every one
--max-target-maturity <maturity>Ceiling on the target maturity this grant may decide toward
--bootstrap-exception <kind>Record the single-human bootstrap exception on a product:ratify_feature grant ('single_human'): the instance root (or the org owner) ratifies under it, with step-up on every use, until a second eligible named human Product Authority is onboarded (operator ruling 2026-09-07 §6, option 5). Requires --reason; the server stamps who recorded it and when
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris access grants​

List one member's permission grants in full — scope, who conferred each, and any single-human bootstrap exception with its recorded state

vagaris access grants [options] <memberId>
ArgumentRequiredDescription
memberIdyesCompany membership id (see access members)
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris access revoke​

Revoke a permission from a member, preserving every other grant they hold

vagaris access revoke [options] <memberId>
ArgumentRequiredDescription
memberIdyesCompany membership id (see access members)
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
--permission <key> (required)Permission key. One of: agents:create, environments:manage, users:invite, users:manage_permissions, tasks:assign, tasks:assign_scope, tasks:manage_active_checkouts, joins:approve, governance:decide_ownership, product:ratify_feature, product:reject_feature, product:return_for_revision, product:defer_feature, capability:ratify_contract, architecture:ratify_contract, release:approve_production, commercial:approve_offer, pricing:approve, gtm:publish_claim, gtm:publish_roadmap_commitment, assimilation:import, runs:claim
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris machine-access​

Confer, read and contain workload trust bindings — the machine identities core will honour

vagaris machine-access <subcommand>

Subcommands: vagaris machine-access list, vagaris machine-access show, vagaris machine-access confer, vagaris machine-access approve, vagaris machine-access reject, vagaris machine-access revoke, vagaris machine-access grants, vagaris machine-access grant, vagaris machine-access revoke-grant, vagaris machine-access declare-exception

vagaris machine-access list​

List this organization's workload trust bindings, as core reports them

vagaris machine-access list [options]
OptionDescriptionDefault
--status <status>only bindings in this status (e.g. pending_approval, active, revoked)
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris machine-access show​

Show one binding with the governance events recorded against it

vagaris machine-access show [options] <bindingId>
ArgumentRequiredDescription
bindingIdyes
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris machine-access confer​

Confer a workload trust binding. Carries you through a real core authentication with a fresh step-up; core verifies the human, the organization, the client and the scope, then records the act.

vagaris machine-access confer [options]
OptionDescriptionDefault
--issuer <url> (required)the workload's own token issuer (e.g. the Actions OIDC issuer)
--audience <aud>audience the workload's token must carry (repeatable)
--repository-owner <owner> (required)repository owner the workload runs under
--repository-owner-id <id>repository owner id, where the issuer stamps one
--repository <name> (required)repository the workload runs in
--repository-id <id>repository id, where the issuer stamps one
--refs <ref>git ref the workload may run from (repeatable)
--environments <name>environment the binding pins (repeatable)
--no-environmentsthe binding pins no environment at all (sends null, not an empty list)
--job-workflow-ref <ref> (required)workflow ref the workload's token must carry
--subject <sub> (required)subject claim the workload's token carries
--service-identity <id> (required)the service principal this workload acts as
--organization-id <id> (required)organization the binding is conferred in (your own)
--project-id <id> (required)project scope
--environment-id <id> (required)environment scope
--capability <name> (required)capability ceiling the binding may reach
--scope <scope>capability scope the binding may exercise (repeatable)
--ttl-seconds <n> (required)lifetime of the sessions this binding mints
--risk-class <class> (required)risk class — it decides which ceremony core applies
--reason <text> (required)why this binding is conferred — recorded on the act
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris machine-access approve​

Approve a pending binding as the second human, where its risk class requires dual control

vagaris machine-access approve [options] <bindingId>
ArgumentRequiredDescription
bindingIdyes
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris machine-access reject​

Reject a pending binding

vagaris machine-access reject [options] <bindingId>
ArgumentRequiredDescription
bindingIdyes
OptionDescriptionDefault
--reason <text> (required)why it is rejected — recorded on the act
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris machine-access revoke​

Revoke an active binding — core returns only once federation no longer honours it

vagaris machine-access revoke [options] <bindingId>
ArgumentRequiredDescription
bindingIdyes
OptionDescriptionDefault
--reason <text> (required)why it is revoked — recorded on the act
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris machine-access grants​

List the workload-binding grants held in your organization

vagaris machine-access grants [options]
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris machine-access grant​

Grant a workload-binding grant to an EXISTING human in your organization. Requires provider:workload_bindings:approve — or, in an organization with no approver yet, owner standing and the grant provider:workload_bindings:bootstrap_exception for yourself (the one permitted self-row).

vagaris machine-access grant [options]
OptionDescriptionDefault
--grantee-user-id <id> (required)the human receiving the grant (must already hold owner/admin membership)
--organization-id <id> (required)organization the grant is pinned to (your own)
--grant <name> (required)provider:workload_bindings:request | approve | bootstrap_exception
--reason <text> (required)must name the ruling, ticket or successor (>= 12 chars); free text is refused
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris machine-access revoke-grant​

Revoke a workload-binding grant held by a human in your organization (narrows authority; requires approve)

vagaris machine-access revoke-grant [options]
OptionDescriptionDefault
--grantee-user-id <id> (required)the human losing the grant
--organization-id <id> (required)organization the grant is pinned to (your own)
--grant <name> (required)provider:workload_bindings:request | approve | bootstrap_exception
--reason <text> (required)why (>= 12 chars)
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris machine-access declare-exception​

Declare a temporary single-human exception to dual control for your organization, with its retirement predicate and expiry. Requires provider:workload_bindings:bootstrap_exception. It governs the CEREMONY of a keystone binding: one human may activate what would otherwise wait for a distinct second approver.

vagaris machine-access declare-exception [options]
OptionDescriptionDefault
--organization-id <id> (required)organization the exception covers (your own)
--reason <text> (required)why dual control is not yet possible here
--retirement-predicate <text> (required)the condition under which this exception retires, in words
--retire-when-approvers-at-least <n> (required)retire once this many DISTINCT approvers exist
--expires-at <epoch-ms> (required)hard expiry, epoch milliseconds
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris service-principal​

Service principals — non-human organizational identities a workload binding is conferred onto

vagaris service-principal <subcommand>

Subcommands: vagaris service-principal create

vagaris service-principal create​

Create a service principal. It holds NO authority until a binding is separately conferred onto it

vagaris service-principal create [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
--name <name> (required)What this principal is, as every audit line will name it (e.g. 'Vagaris Spine Executor')
--email <email> (required)Its address — a stable human-readable LABEL, not the identity. Canonical first-party namespace: <role>@workloads.vagarylabs.com. No mailbox, never marked verified, no interactive login
--principal-id <uuid>Resolve an EXISTING principal instead of minting one — the re-run key. Conferral idempotency is organization + principal, never the address, so repeating a partly-failed sequence cannot mint a duplicate
-y, --yesWhen the server answers step_up_required, run the step-up re-authentication and retry once without asking
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris dashboard​

Dashboard summary operations

vagaris dashboard <subcommand>

Subcommands: vagaris dashboard get

vagaris dashboard get​

Get dashboard summary for a company

vagaris dashboard get [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris routines​

Local routine maintenance commands

vagaris routines <subcommand>

Subcommands: vagaris routines disable-all

vagaris routines disable-all​

Pause all non-archived routines in the configured local instance for one company

vagaris routines disable-all [options]
OptionDescriptionDefault
-c, --config <path>Path to config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
-C, --company-id <id>Company ID
--jsonOutput raw JSON

vagaris feedback​

Inspect and export local feedback traces

vagaris feedback <subcommand>

Subcommands: vagaris feedback report, vagaris feedback export

vagaris feedback report​

Render a terminal report for company feedback traces

vagaris feedback report [options]
OptionDescriptionDefault
-C, --company-id <id>Company ID (overrides context default)
--target-type <type>Filter by target type
--vote <vote>Filter by vote value
--status <status>Filter by trace status
--project-id <id>Filter by project ID
--issue-id <id>Filter by issue ID
--from <iso8601>Only include traces created at or after this timestamp
--to <iso8601>Only include traces created at or before this timestamp
--shared-onlyOnly include traces eligible for sharing/export
--payloadsInclude raw payload dumps in the terminal report
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris feedback export​

Export feedback votes and raw trace bundles into a folder plus zip archive

vagaris feedback export [options]
OptionDescriptionDefault
-C, --company-id <id>Company ID (overrides context default)
--target-type <type>Filter by target type
--vote <vote>Filter by vote value
--status <status>Filter by trace status
--project-id <id>Filter by project ID
--issue-id <id>Filter by issue ID
--from <iso8601>Only include traces created at or after this timestamp
--to <iso8601>Only include traces created at or before this timestamp
--shared-onlyOnly include traces eligible for sharing/export
--out <path>Output directory (default: ./feedback-export-<timestamp>)
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris secrets​

Secret declaration and provider operations

vagaris secrets <subcommand>

Subcommands: vagaris secrets list, vagaris secrets declarations, vagaris secrets create, vagaris secrets link, vagaris secrets doctor, vagaris secrets providers, vagaris secrets migrate-inline-env

vagaris secrets list​

List secret metadata for a company

vagaris secrets list [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris secrets declarations​

List portable env declarations emitted by company export

vagaris secrets declarations [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
--include <values>Comma-separated include set: company,agents,projects,issues,tasks,skills"company,agents,projects"
--kind <kind>Filter declarations: all | secret | plain"all"
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris secrets create​

Create a Vagaris-managed secret

vagaris secrets create [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
--name <name> (required)Secret display name
--key <key>Portable secret key
--provider <provider>Secret provider id
--value <value>Secret value
--value-env <name>Read secret value from an environment variable
--description <text>Description
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

Link an external provider-owned secret without storing its value in Vagaris

vagaris secrets link [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
--name <name> (required)Secret display name
--provider <provider> (required)Secret provider id
--external-ref <ref> (required)Provider secret ARN/name/path/reference
--key <key>Portable secret key
--provider-version-ref <ref>Provider version id or label
--description <text>Description
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris secrets doctor​

Run secret provider health checks through the Vagaris API

vagaris secrets doctor [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris secrets providers​

List configured secret provider descriptors

vagaris secrets providers [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris secrets migrate-inline-env​

Migrate inline sensitive agent env values into secret references

vagaris secrets migrate-inline-env [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
--applyPersist changes; default is a dry run
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris cloud​

Vagaris Cloud upstream sync commands

vagaris cloud <subcommand>

Subcommands: vagaris cloud connect, vagaris cloud push

vagaris cloud connect​

Authorize this local instance to push into a Vagaris Cloud stack

vagaris cloud connect [options] <remote-url>
ArgumentRequiredDescription
remote-urlyesVagaris Cloud stack URL
OptionDescriptionDefault
--no-browserUse the device-code flow instead of opening a browser
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris cloud push​

Preview or apply a local company push into the connected Vagaris Cloud stack

vagaris cloud push [options]
OptionDescriptionDefault
--company <local-company-id> (required)Local company ID to export
--remote-url <remote-url>Use a specific stored cloud connection
--dry-runPreview without applying
--max-entities-per-chunk <count>Chunk size for upstream uploads100
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris skills​

Company and agent skill operations

vagaris skills <subcommand>

Subcommands: vagaris skills browse, vagaris skills search, vagaris skills inspect, vagaris skills install, vagaris skills list, vagaris skills show, vagaris skills file, vagaris skills import, vagaris skills create, vagaris skills scan-projects, vagaris skills check, vagaris skills update, vagaris skills audit, vagaris skills reset, vagaris skills remove, vagaris skills agent

vagaris skills browse​

Browse app-shipped catalog skills without installing them

vagaris skills browse [options]
OptionDescriptionDefault
--kind <kind>Catalog kind filter (bundled or optional)
--category <slug>Catalog category filter
--query <text>Search catalog text
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

Search app-shipped catalog skills without installing them

vagaris skills search [options] <query>
ArgumentRequiredDescription
queryyesSearch text
OptionDescriptionDefault
--kind <kind>Catalog kind filter (bundled or optional)
--category <slug>Catalog category filter
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris skills inspect​

Inspect an app-shipped catalog skill before installing it

vagaris skills inspect [options] <catalogRef>
ArgumentRequiredDescription
catalogRefyesCatalog skill ID, key, or unique slug
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris skills install​

Install a catalog skill into the company skill library; does not attach it to agents

vagaris skills install [options] <catalogRef>
ArgumentRequiredDescription
catalogRefyesCatalog skill ID, key, or unique slug
OptionDescriptionDefault
--as <slug>Company skill slug override
--forceReplace a same-key catalog-managed skill when the server allows it
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris skills list​

List company skills

vagaris skills list [options]
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris skills show​

Show company skill details

vagaris skills show [options] <skillRef>
ArgumentRequiredDescription
skillRefyesCompany skill ID, key, or unique slug
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris skills file​

Print a company skill file

vagaris skills file [options] <skillRef>
ArgumentRequiredDescription
skillRefyesCompany skill ID, key, or unique slug
OptionDescriptionDefault
--path <path>Relative file path"SKILL.md"
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris skills import​

Import company skills from a local path, GitHub, skills.sh, or URL source

vagaris skills import [options] <source>
ArgumentRequiredDescription
sourceyesSkill source
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris skills create​

Create a managed local company skill

vagaris skills create [options]
OptionDescriptionDefault
--name <name> (required)Skill name
--slug <slug>Skill slug
--description <text>Skill description
--body-file <path>Markdown body file; use - to read stdin
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris skills scan-projects​

Scan project workspaces for skills

vagaris skills scan-projects [options]
OptionDescriptionDefault
--project-id <id>Project ID to scan; may be repeated[]
--workspace-id <id>Workspace ID to scan; may be repeated[]
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris skills check​

Check company skill update status

vagaris skills check [options] [skillRef]
ArgumentRequiredDescription
skillRefnoCompany skill ID, key, or unique slug
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris skills update​

Install company skill updates

vagaris skills update [options] [skillRef]
ArgumentRequiredDescription
skillRefnoCompany skill ID, key, or unique slug
OptionDescriptionDefault
--allCheck all skills and install available updates
--forceDiscard local-modification or soft-audit holds; hard-stop audit findings still fail
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris skills audit​

Audit installed company skill bytes without executing them

vagaris skills audit [options] [skillRef]
ArgumentRequiredDescription
skillRefnoCompany skill ID, key, or unique slug
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris skills reset​

Reset a catalog-managed company skill to its pinned installed origin

vagaris skills reset [options] <skillRef>
ArgumentRequiredDescription
skillRefyesCompany skill ID, key, or unique slug
OptionDescriptionDefault
--yesConfirm reset without prompting
--forceDiscard local modifications or accept soft audit warnings; hard-stop audit findings still fail
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris skills remove​

Remove a company skill

vagaris skills remove [options] <skillRef>
ArgumentRequiredDescription
skillRefyesCompany skill ID, key, or unique slug
OptionDescriptionDefault
--yesConfirm removal without prompting
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris skills agent​

Agent desired-skill and runtime sync operations

vagaris skills agent <subcommand>

Subcommands: vagaris skills agent list, vagaris skills agent sync, vagaris skills agent clear

vagaris skills agent list​

List an agent runtime skill snapshot

vagaris skills agent list [options] <agentRef>
ArgumentRequiredDescription
agentRefyesAgent ID or shortname/url-key
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris skills agent sync​

Replace an agent's non-required desired company skills and sync runtime state

vagaris skills agent sync [options] <agentRef>
ArgumentRequiredDescription
agentRefyesAgent ID or shortname/url-key
OptionDescriptionDefault
--skill <skillRef>Desired company skill ID, key, or slug; may be repeated[]
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris skills agent clear​

Clear an agent's non-required desired company skills and sync runtime state

vagaris skills agent clear [options] <agentRef>
ArgumentRequiredDescription
agentRefyesAgent ID or shortname/url-key
OptionDescriptionDefault
--yesConfirm clear without prompting
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris worktree​

Worktree-local Vagaris instance helpers

vagaris worktree <subcommand>

Subcommands: vagaris worktree init, vagaris worktree env, vagaris worktree reseed, vagaris worktree repair

vagaris worktree init​

Create repo-local config/env and an isolated instance for this worktree

vagaris worktree init [options]
OptionDescriptionDefault
--name <name>Display name used to derive the instance id
--instance <id>Explicit isolated instance id
--home <path>Home root for worktree instances (env: PAPERCLIP_WORKTREES_DIR, default: ~/.paperclip-worktrees)
--from-config <path>Source config.json to seed from
--from-data-dir <path>Source PAPERCLIP_HOME used when deriving the source config
--from-instance <id>Source instance id when deriving the source config"default"
--server-port <port>Preferred server port
--db-port <port>Preferred embedded Postgres port
--seed-mode <mode>Seed profile: minimal or full (default: minimal)"minimal"
--preserve-live-workDo not quarantine copied agent timers or assigned open issues in the seeded worktree
--no-seedSkip database seeding from the source instance
--forceReplace existing repo-local config and isolated instance data

vagaris worktree env​

Print shell exports for the current worktree-local Vagaris instance

vagaris worktree env [options]
OptionDescriptionDefault
-c, --config <path>Path to config file
--jsonPrint JSON instead of shell exports

vagaris worktree reseed​

Re-seed an existing worktree-local instance from another Vagaris instance or worktree

vagaris worktree reseed [options]
OptionDescriptionDefault
--from <worktree>Source worktree path, directory name, branch name, or current
--to <worktree>Target worktree path, directory name, branch name, or current (defaults to current)
--from-config <path>Source config.json to seed from
--from-data-dir <path>Source PAPERCLIP_HOME used when deriving the source config
--from-instance <id>Source instance id when deriving the source config
--seed-mode <mode>Seed profile: minimal or full (default: full)"full"
--preserve-live-workDo not quarantine copied agent timers or assigned open issues in the seeded worktree
--yesSkip the destructive confirmation prompt
--allow-live-targetOverride the guard that requires the target worktree DB to be stopped first

vagaris worktree repair​

Create or repair a linked worktree-local Vagaris instance without touching the primary checkout

vagaris worktree repair [options]
OptionDescriptionDefault
--branch <name>Existing branch/worktree selector to repair, or a branch name to create under .paperclip/worktrees
--home <path>Home root for worktree instances (env: PAPERCLIP_WORKTREES_DIR, default: ~/.paperclip-worktrees)
--from-config <path>Source config.json to seed from
--from-data-dir <path>Source PAPERCLIP_HOME used when deriving the source config
--from-instance <id>Source instance id when deriving the source config (default: default)
--seed-mode <mode>Seed profile: minimal or full (default: minimal)"minimal"
--preserve-live-workDo not quarantine copied agent timers or assigned open issues in the seeded worktree
--no-seedRepair metadata only and skip reseeding when bootstrapping a missing worktree config
--allow-live-targetOverride the guard that requires the target worktree DB to be stopped first

vagaris worktree:make​

Create ~/NAME as a git worktree, then initialize an isolated Vagaris instance inside it

vagaris worktree:make [options] <name>
ArgumentRequiredDescription
nameyesWorktree name — auto-prefixed with paperclip- if needed (created at ~/paperclip-NAME)
OptionDescriptionDefault
--start-point <ref>Remote ref to base the new branch on (env: PAPERCLIP_WORKTREE_START_POINT)
--instance <id>Explicit isolated instance id
--home <path>Home root for worktree instances (env: PAPERCLIP_WORKTREES_DIR, default: ~/.paperclip-worktrees)
--from-config <path>Source config.json to seed from
--from-data-dir <path>Source PAPERCLIP_HOME used when deriving the source config
--from-instance <id>Source instance id when deriving the source config"default"
--server-port <port>Preferred server port
--db-port <port>Preferred embedded Postgres port
--seed-mode <mode>Seed profile: minimal or full (default: minimal)"minimal"
--preserve-live-workDo not quarantine copied agent timers or assigned open issues in the seeded worktree
--no-seedSkip database seeding from the source instance
--forceReplace existing repo-local config and isolated instance data

vagaris worktree:list​

List git worktrees visible from this repo and whether they look like Vagaris worktrees

vagaris worktree:list [options]
OptionDescriptionDefault
--jsonPrint JSON instead of text output

vagaris worktree:merge-history​

Preview or import issue/comment history from another worktree into the current instance

vagaris worktree:merge-history [options] [source]
ArgumentRequiredDescription
sourcenoOptional source worktree path, directory name, or branch name (back-compat alias for --from)
OptionDescriptionDefault
--from <worktree>Source worktree path, directory name, branch name, or current
--to <worktree>Target worktree path, directory name, branch name, or current (defaults to current)
--company <id-or-prefix>Shared company id or issue prefix inside the chosen source/target instances
--scope <items>Comma-separated scopes to import (issues, comments)"issues,comments"
--applyApply the import after previewing the plan
--dryPreview only and do not import anything
--yesSkip the interactive confirmation prompt when applying

vagaris worktree:cleanup​

Safely remove a worktree, its branch, and its isolated instance data

vagaris worktree:cleanup [options] <name>
ArgumentRequiredDescription
nameyesWorktree name — auto-prefixed with paperclip- if needed
OptionDescriptionDefault
--instance <id>Explicit instance id (if different from the worktree name)
--home <path>Home root for worktree instances (env: PAPERCLIP_WORKTREES_DIR, default: ~/.paperclip-worktrees)
--forceBypass safety checks (uncommitted changes, unique commits)

vagaris env-lab​

Deterministic local environment fixtures

vagaris env-lab <subcommand>

Subcommands: vagaris env-lab up, vagaris env-lab status, vagaris env-lab down, vagaris env-lab doctor

vagaris env-lab up​

Start the default SSH env-lab fixture

vagaris env-lab up [options]
OptionDescriptionDefault
-i, --instance <id>Vagaris instance id (default: current/default)
--jsonPrint machine-readable fixture details

vagaris env-lab status​

Show the current SSH env-lab fixture state

vagaris env-lab status [options]
OptionDescriptionDefault
-i, --instance <id>Vagaris instance id (default: current/default)
--jsonPrint machine-readable fixture details

vagaris env-lab down​

Stop the default SSH env-lab fixture

vagaris env-lab down [options]
OptionDescriptionDefault
-i, --instance <id>Vagaris instance id (default: current/default)
--jsonPrint machine-readable stop details

vagaris env-lab doctor​

Check SSH fixture prerequisites and current status

vagaris env-lab doctor [options]
OptionDescriptionDefault
-i, --instance <id>Vagaris instance id (default: current/default)
--jsonPrint machine-readable diagnostic details

vagaris plugin​

Plugin lifecycle management

vagaris plugin <subcommand>

Subcommands: vagaris plugin init, vagaris plugin list, vagaris plugin install, vagaris plugin uninstall, vagaris plugin enable, vagaris plugin disable, vagaris plugin inspect, vagaris plugin examples

vagaris plugin init​

Scaffold a local Vagaris plugin project

vagaris plugin init [options] <packageName>
ArgumentRequiredDescription
packageNameyes
OptionDescriptionDefault
--output <dir>Directory to create the plugin folder in
--template <template>Starter template"default"
--category <category>Manifest category
--display-name <name>Manifest display name
--description <description>Manifest description
--author <author>Manifest author
--sdk-path <path>Local @vagarylabs/plugin-sdk package path
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris plugin list​

List installed plugins

vagaris plugin list [options]
OptionDescriptionDefault
--status <status>Filter by status (ready, error, disabled, installed, upgrade_pending)
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris plugin install​

Install a plugin from a local path or npm package. Examples: vagaris plugin install ./my-plugin # local path vagaris plugin install @acme/plugin-linear # npm package vagaris plugin install @acme/plugin-linear@1.2 # pinned version

vagaris plugin install [options] <package>
ArgumentRequiredDescription
packageyes
OptionDescriptionDefault
-l, --localTreat <package> as a local filesystem path
--version <version>Specific npm version to install (npm packages only)
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris plugin uninstall​

Uninstall a plugin by its plugin key or database ID. Use --force to hard-purge all state and config.

vagaris plugin uninstall [options] <pluginKey>
ArgumentRequiredDescription
pluginKeyyes
OptionDescriptionDefault
--forcePurge all plugin state and config (hard delete)
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris plugin enable​

Enable a disabled or errored plugin

vagaris plugin enable [options] <pluginKey>
ArgumentRequiredDescription
pluginKeyyes
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris plugin disable​

Disable a running plugin without uninstalling it

vagaris plugin disable [options] <pluginKey>
ArgumentRequiredDescription
pluginKeyyes
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris plugin inspect​

Show full details for an installed plugin

vagaris plugin inspect [options] <pluginKey>
ArgumentRequiredDescription
pluginKeyyes
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris plugin examples​

List bundled example plugins available for local install

vagaris plugin examples [options]
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris node​

Node identity and enrolment

vagaris node <subcommand>

Subcommands: vagaris node enroll, vagaris node approve-enrolment, vagaris node status, vagaris node doctor, vagaris node revoke, vagaris node capabilities

vagaris node enroll​

Enrol this machine as a node

vagaris node enroll [options]
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris node approve-enrolment​

Approve a pending node enrolment as the signed-in operator

vagaris node approve-enrolment [options] [approval]
ArgumentRequiredDescription
approvalnoThe challenge id (with --token-stdin); the approval link belongs on stdin (--link-stdin)
OptionDescriptionDefault
--link-stdinRead the whole approval link from stdin (the primary form: keeps its secret out of shell history and ps)
--token-stdinRead the challenge token from stdin, when passing a bare challenge id
--yesApprove without the confirmation prompt
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris node status​

Show this node's enrolment status and health

vagaris node status [options]
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris node doctor​

Run node-specific health checks

vagaris node doctor [options]
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris node revoke​

Revoke this node's attestation

vagaris node revoke [options]
OptionDescriptionDefault
--reason <reason>Reason for revocation
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris node capabilities​

List this machine's capabilities

vagaris node capabilities [options]
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris tui-demo​

Render a hello-world TUI to prove the ANSI renderer survives bundling

vagaris tui-demo [options]
OptionDescriptionDefault
--no-animationSkip spinner animation (for non-TTY testing)

vagaris runctl​

Run control: status, attach, pause, cancel, resume, history

vagaris runctl <subcommand>

Subcommands: vagaris runctl status, vagaris runctl attach, vagaris runctl pause, vagaris runctl cancel, vagaris runctl resume, vagaris runctl history, vagaris runctl scope-request, vagaris runctl privileged

vagaris runctl status​

Fetch the current status and transcript tail of a run

vagaris runctl status [options]
OptionDescriptionDefault
--run-id <runId> (required)Heartbeat run id
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris runctl attach​

Attach to a live run's transcript (polling; read-only; Ctrl+C detaches)

vagaris runctl attach [options]
OptionDescriptionDefault
--run-id <runId> (required)Heartbeat run id
--poll-interval <ms>Polling interval in ms"1000"
--timeout <ms>Max attach duration in ms"1800000"
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris runctl pause​

Pause a live run at run scope (resumable; server governance chain)

vagaris runctl pause [options]
OptionDescriptionDefault
--run-id <runId> (required)Heartbeat run id
--reason <text>Optional pause reason
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris runctl cancel​

Cancel a run through the kill-switch integrity gate

vagaris runctl cancel [options]
OptionDescriptionDefault
--run-id <runId> (required)Heartbeat run id
--reason <text>Optional cancellation reason
--no-waitDo not poll for the kill-switch verdict
--kill-switch-timeout <ms>Kill-switch verification timeout in ms"10000"
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris runctl resume​

Resume a paused run (re-queues it through the server's spawn funnel)

vagaris runctl resume [options]
OptionDescriptionDefault
--run-id <runId> (required)Heartbeat run id
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris runctl history​

List recent runs for the company (last 20)

vagaris runctl history [options]
OptionDescriptionDefault
--agent-id <agentId>Filter by agent id
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris runctl scope-request​

Request governed scope expansion for a live run (denial keeps the run bounded)

vagaris runctl scope-request [options]
OptionDescriptionDefault
--run-id <runId> (required)Heartbeat run id
--lease-id <leaseId> (required)Lease id the run is executing under
--entity <entity> (required)Entity being requested (file path, service, table…)
--entity-kind <kind> (required)Entity kind (file, service, domain, table…)
--reason <text> (required)Why the executor needs this entity
--current-scope <scope...>Scopes the executor already holds[]
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris runctl privileged​

Route a privileged act through the broker (git_push_main, deployment, production_db_write, infrastructure_mutation, secret_access, billing_mutation)

vagaris runctl privileged [options]
OptionDescriptionDefault
--act-class <class> (required)Privileged act class
--run-id <runId> (required)Heartbeat run id
--lease-id <leaseId> (required)Lease id the run is executing under
--reason <text> (required)Why this act is needed
--payload <json>Act payload as JSON"{}"
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris support-bundle​

Collect a redacted diagnostic bundle for Vagaris support

vagaris support-bundle [options]
OptionDescriptionDefault
-c, --config <path>Path to config file
-d, --data-dir <path>Vagaris data directory root
--api-base <url>API base to probe (defaults to the client-command resolution)
-o, --out <file>Write the bundle to a file instead of stdout
--log-lines <n>How many recent log lines to include500
--jsonOutput raw JSON (default when writing to stdout)

vagaris project​

Project operations

vagaris project <subcommand>

Subcommands: vagaris project init, vagaris project list, vagaris project get, vagaris project create, vagaris project update, vagaris project archive, vagaris project unarchive, vagaris project delete

vagaris project init​

Write a vagary.json project manifest so a checkout reproduces this project's context

vagaris project init [options]
OptionDescriptionDefault
--organization <id>Organization this project belongs to
--project-name <name>Project within that organization
--environment <name>Environment this checkout targets
--endpoint <url>API endpoint OVERRIDE - only for self-hosted, on-prem or local
--region <name>Placement preference
--dir <path>Directory to write into (default: current directory)
--forceOverwrite an existing manifest
--jsonOutput raw JSON

vagaris project list​

List projects for a company

vagaris project list [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris project get​

Get one project

vagaris project get [options] <projectId>
ArgumentRequiredDescription
projectIdyesProject ID or shortname
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris project create​

Create a project

vagaris project create [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
--name <name> (required)Project name
--description <text>Project description
--status <status>Project status (backlog|planned|in_progress|completed|cancelled)
--lead-agent-id <id>Lead agent ID
--target-date <date>Target date (ISO)
--color <color>Display color
--goal-ids <csv>Comma-separated goal IDs
--product-slug <slug>Genome product slug this project realizes
--company-defaultMake this the company's default project
--env <json>Env bindings as a JSON object
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris project update​

Update a project

vagaris project update [options] <projectId>
ArgumentRequiredDescription
projectIdyesProject ID or shortname
OptionDescriptionDefault
--name <name>Project name
--description <text>Project description
--status <status>Project status (backlog|planned|in_progress|completed|cancelled)
--lead-agent-id <id>Lead agent ID
--target-date <date>Target date (ISO)
--color <color>Display color
--goal-ids <csv>Comma-separated goal IDs
--product-slug <slug>Genome product slug this project realizes
--company-defaultMake this the company's default project
--env <json>Env bindings as a JSON object
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris project archive​

Archive a project (sets archivedAt)

vagaris project archive [options] <projectId>
ArgumentRequiredDescription
projectIdyesProject ID or shortname
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris project unarchive​

Unarchive a project (clears archivedAt)

vagaris project unarchive [options] <projectId>
ArgumentRequiredDescription
projectIdyesProject ID or shortname
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris project delete​

Delete a project

vagaris project delete [options] <projectId>
ArgumentRequiredDescription
projectIdyesProject ID or shortname
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris product​

Fleet product-capability catalog (privileged; renders GET /api/product-catalog)

vagaris product <subcommand>

Subcommands: vagaris product list, vagaris product get

vagaris product list​

List the fleet-wide product-capability catalog

vagaris product list [options]
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris product get​

Get one product-capability entry by id or title

vagaris product get [options] <id>
ArgumentRequiredDescription
idyesCapability id (contract dir name) or title
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris entitlement​

This company's capability entitlement state (plan × capability, product-tier slice)

vagaris entitlement <subcommand>

Subcommands: vagaris entitlement list, vagaris entitlement show, vagaris entitlement effective

vagaris entitlement list​

List this company's capability entitlements

vagaris entitlement list [options]
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris entitlement show​

Show one capability's entitlement verdict (plan gate + product-tier slice)

vagaris entitlement show [options] <capability>
ArgumentRequiredDescription
capabilityyesCapability id (e.g. governed_act, agent_seat, external_secret_provider, cloud_federation)
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris entitlement effective​

Show the full effective entitlement state — plan, account plan, and every capability verdict

vagaris entitlement effective [options]
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris offer​

Commercial offers this company has asked for (ADR-127)

vagaris offer <subcommand>

Subcommands: vagaris offer agreement

vagaris offer agreement​

Commercial-intent records — the durable ask behind an offer (requested -> qualified/declined/withdrawn)

vagaris offer agreement <subcommand>

Subcommands: vagaris offer agreement list, vagaris offer agreement create, vagaris offer agreement update

vagaris offer agreement list​

List this company's commercial-intent records, newest first

vagaris offer agreement list [options]
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris offer agreement create​

Record a commercial intent — what this company is asking for

vagaris offer agreement create [options]
OptionDescriptionDefault
--requested-offer <offer> (required)Offer/plan id being asked for (a billing-metering /v1/plans id)
--intent-type <type> (required)Why the ask exists — one of: acquisition, expansion, downgrade, renewal, reactivation, qualification
--origin-surface <surface> (required)Where it originated — one of: vagaris.org, vagaryvoice.cloud, vagarylabs.com, console, api, sales-assisted
--source <source>Provenance of this ask (e.g. product, console); defaults server-side to 'product'
--origin-product <product>Product surface the ask originated on
--requested-product <product>Product the offer is for, if different from the origin
--next-action <action>What the organization believes happens next
--note <note>Free-text note
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris offer agreement update​

Move a commercial intent's qualification status

vagaris offer agreement update [options] <id>
ArgumentRequiredDescription
idyesCommercial-intent id
OptionDescriptionDefault
--status <status> (required)One of: qualified, declined, withdrawn (settlement is never client-settable)
--note <note>Reason the status moved
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris usage​

Consumption, cost and budget operations (token usage — not billing)

vagaris usage <subcommand>

Subcommands: vagaris usage summary, vagaris usage by-agent, vagaris usage by-agent-model, vagaris usage by-provider, vagaris usage by-biller, vagaris usage by-project, vagaris usage window-spend, vagaris usage quota-windows, vagaris usage budget, vagaris usage finance

vagaris usage summary​

Company spend vs. budget for the period (routes/costs.ts:142)

vagaris usage summary [options]
OptionDescriptionDefault
--from <iso8601>Only include events at or after this timestamp
--to <iso8601>Only include events at or before this timestamp
-C, --company-id <id> (required)Company ID
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris usage by-agent​

Spend grouped by agent (routes/costs.ts:178)

vagaris usage by-agent [options]
OptionDescriptionDefault
--from <iso8601>Only include events at or after this timestamp
--to <iso8601>Only include events at or before this timestamp
-C, --company-id <id> (required)Company ID
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris usage by-agent-model​

Spend grouped by agent + provider + model (routes/costs.ts:186)

vagaris usage by-agent-model [options]
OptionDescriptionDefault
--from <iso8601>Only include events at or after this timestamp
--to <iso8601>Only include events at or before this timestamp
-C, --company-id <id> (required)Company ID
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris usage by-provider​

Spend grouped by provider + biller + model (routes/costs.ts:194)

vagaris usage by-provider [options]
OptionDescriptionDefault
--from <iso8601>Only include events at or after this timestamp
--to <iso8601>Only include events at or before this timestamp
-C, --company-id <id> (required)Company ID
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris usage by-biller​

Spend grouped by biller (routes/costs.ts:202)

vagaris usage by-biller [options]
OptionDescriptionDefault
--from <iso8601>Only include events at or after this timestamp
--to <iso8601>Only include events at or before this timestamp
-C, --company-id <id> (required)Company ID
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris usage by-project​

Spend attributed to a project via the run → issue → project chain (routes/costs.ts:297)

vagaris usage by-project [options]
OptionDescriptionDefault
--from <iso8601>Only include events at or after this timestamp
--to <iso8601>Only include events at or before this timestamp
-C, --company-id <id> (required)Company ID
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris usage window-spend​

Rolling 5h/24h/7d spend per provider (routes/costs.ts:243)

vagaris usage window-spend [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris usage quota-windows​

Live provider rate-limit windows (board-scoped; routes/costs.ts:250)

vagaris usage quota-windows [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris usage budget​

Budget overview and monthly-cap writes

vagaris usage budget <subcommand>

Subcommands: vagaris usage budget overview, vagaris usage budget set-company, vagaris usage budget set-agent

vagaris usage budget overview​

Policies, active incidents and pause counts for a company (routes/costs.ts:265)

vagaris usage budget overview [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris usage budget set-company​

Set a company's monthly budget cap in cents (board-only; routes/costs.ts:305)

vagaris usage budget set-company [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
--budget-monthly-cents <n> (required)New monthly cap, in cents
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris usage budget set-agent​

Set an agent's monthly budget cap in cents (board-only; routes/costs.ts:339)

vagaris usage budget set-agent [options]
OptionDescriptionDefault
--agent-id <id> (required)Agent ID
--budget-monthly-cents <n> (required)New monthly cap, in cents
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris usage finance​

Self-reported finance ledger (debit/credit events; not an invoice)

vagaris usage finance <subcommand>

Subcommands: vagaris usage finance summary, vagaris usage finance by-biller, vagaris usage finance by-kind, vagaris usage finance events

vagaris usage finance summary​

Debit/credit/net totals for the period (routes/costs.ts:210)

vagaris usage finance summary [options]
OptionDescriptionDefault
--from <iso8601>Only include events at or after this timestamp
--to <iso8601>Only include events at or before this timestamp
-C, --company-id <id> (required)Company ID
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris usage finance by-biller​

Debit/credit totals grouped by biller (routes/costs.ts:218)

vagaris usage finance by-biller [options]
OptionDescriptionDefault
--from <iso8601>Only include events at or after this timestamp
--to <iso8601>Only include events at or before this timestamp
-C, --company-id <id> (required)Company ID
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris usage finance by-kind​

Debit/credit totals grouped by event kind (routes/costs.ts:226)

vagaris usage finance by-kind [options]
OptionDescriptionDefault
--from <iso8601>Only include events at or after this timestamp
--to <iso8601>Only include events at or before this timestamp
-C, --company-id <id> (required)Company ID
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris usage finance events​

Raw finance ledger rows, newest first (routes/costs.ts:234)

vagaris usage finance events [options]
OptionDescriptionDefault
--from <iso8601>Only include events at or after this timestamp
--to <iso8601>Only include events at or before this timestamp
-C, --company-id <id> (required)Company ID
--limit <n>Max rows (server clamps to 1-500; default 100)
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris audit​

Governed-act audit trail: who, what, why, authority, result

vagaris audit <subcommand>

Subcommands: vagaris audit list, vagaris audit verify, vagaris audit decisions, vagaris audit explain, vagaris audit evidence, vagaris audit export, vagaris audit evidence-export

vagaris audit list​

List a company's governed-act audit rows, newest first (routes/companies.ts:575)

vagaris audit list [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
--limit <n>Max rows, 1-500 (server clamps; default 100)
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris audit verify​

Recompute and report the hash-chain integrity verdict for a company (routes/companies.ts:582-583)

vagaris audit verify [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris audit decisions​

The company's recent governed decisions — the index into audit explain (routes/explain.ts:25)

vagaris audit decisions [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
--limit <n>Max rows, 1-200 (server clamps; default 50)
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris audit explain​

The causal trace for one governed act — world-change, impact, ownership, action (routes/explain.ts:67,75)

vagaris audit explain [options] [actId]
ArgumentRequiredDescription
actIdnoAct ID (omit and use a --run/--issue/--approval/--entity selector instead)
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
--run <runId>Resolve the most recent act correlated to this run
--issue <issueId>Resolve the most recent act correlated to this issue
--approval <approvalId>Resolve the most recent act correlated to this approval
--entity <type:id>Resolve the most recent act correlated to this entity
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris audit evidence​

Index of tenant evidence across every append-only plane — structured columns only, no payload bodies (routes/explain.ts:41)

vagaris audit evidence [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
--limit <n>Max rows, 1-200 (server clamps; default 50)
--stream <name>Filter to one evidence stream
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris audit export​

NDJSON export of governed-act audit rows. GAP: bounded to one page (max 500, no cursor) — see the file header.

vagaris audit export [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
--limit <n>Max rows, 1-500 (server clamps; default 100)
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris audit evidence-export​

NDJSON export of the tenant evidence index. GAP: bounded to one page (max 200, no cursor) — see the file header.

vagaris audit evidence-export [options]
OptionDescriptionDefault
-C, --company-id <id> (required)Company ID
--limit <n>Max rows, 1-200 (server clamps; default 50)
--stream <name>Filter to one evidence stream
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris auth​

Authentication and bootstrap utilities

vagaris auth <subcommand>

Subcommands: vagaris auth bootstrap-ceo, vagaris auth login, vagaris auth step-up, vagaris auth logout, vagaris auth whoami

vagaris auth bootstrap-ceo​

Create a one-time bootstrap invite URL for first instance admin

vagaris auth bootstrap-ceo [options]
OptionDescriptionDefault
-c, --config <path>Path to config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--forceCreate new invite even if admin already exists
--expires-hours <hours>Invite expiration window in hours
--base-url <url>Public base URL used to print invite link

vagaris auth login​

Authenticate the CLI through fleet identity for board-user access

vagaris auth login [options]
OptionDescriptionDefault
--operatorUse the configured canonical platform/operator sign-in
--instance-adminRequire the authenticated identity to already hold instance-admin
--deviceSign in with a short code from ANY browser (RFC 8628) — no localhost callback to race; for servers, containers and remote shells
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON
-C, --company-id <id>Company ID (overrides context default)

vagaris auth step-up​

Re-authenticate for a sensitive action (operator ruling 2026-09-07 §4): the same browser sign-in with prompt=login and max_age=0, so the refreshed credential's auth_time is now. Whether the sign-in includes a second factor is the organization's login policy at the identity issuer, not a CLI option. The token is stored, never printed

vagaris auth step-up [options]
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris auth logout​

Remove the stored board-user credential for this API base

vagaris auth logout [options]
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON

vagaris auth whoami​

Show the current board-user identity for this API base

vagaris auth whoami [options]
OptionDescriptionDefault
-c, --config <path>Path to Vagaris config file
-d, --data-dir <path>Vagaris data directory root — overrides the default ~/.vagris (and the legacy ~/.paperclip root, used only when it still holds the data)
--context <path>Path to CLI context file
--profile <name>CLI context profile name
--api-base <url>Base URL for the Vagaris API
--api-key <token>Bearer token for agent-authenticated calls
--jsonOutput raw JSON