{"_id":"@amaretto-software-labs/cobalt-cli","_rev":"4-78125b1d417bf7ba4775b58cd417f09f","name":"@amaretto-software-labs/cobalt-cli","dist-tags":{"latest":"0.1.3"},"versions":{"0.1.0":{"name":"@amaretto-software-labs/cobalt-cli","version":"0.1.0","keywords":["cobalt","cli","coding-agent","developer-tools"],"license":"Apache-2.0","_id":"@amaretto-software-labs/cobalt-cli@0.1.0","maintainers":[{"name":"vlad_vasoftware","email":"vlad@vasoftware.co.uk"}],"homepage":"https://github.com/Amaretto-Software-Labs/cobalt-cli#readme","bugs":{"url":"https://github.com/Amaretto-Software-Labs/cobalt-cli/issues"},"bin":{"cobalt":"dist/main.js"},"dist":{"shasum":"90c741cf20af3e7cc7e7a402e3f3b08cb9139e5b","tarball":"https://registry.npmjs.org/@amaretto-software-labs/cobalt-cli/-/cobalt-cli-0.1.0.tgz","fileCount":52,"integrity":"sha512-Ew49RnBl2TIV32dptYV+vkZ8IXdurHaQ1cs4rmcqaYs5/gJ3Q3/S68duDeYtaS9eLdjLV7YzQKwl9KGA4y9p1A==","signatures":[{"sig":"MEUCIEjsCy7vtuT5/BquPnBICSF+q6aBJod01ItJM1/llai2AiEAnJD9n+ZLjeJy3Y18gGakrG3Wl33pYYqNbZy4gKKujXg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":473964},"type":"module","_from":"file:/Users/vlad/code/cobalt-cli/amaretto-software-labs-cobalt-cli-0.1.0.tgz","engines":{"node":">=22"},"_npmUser":{"name":"vlad_vasoftware","email":"vlad@vasoftware.co.uk"},"_resolved":"/Users/vlad/code/cobalt-cli/amaretto-software-labs-cobalt-cli-0.1.0.tgz","_integrity":"sha512-Ew49RnBl2TIV32dptYV+vkZ8IXdurHaQ1cs4rmcqaYs5/gJ3Q3/S68duDeYtaS9eLdjLV7YzQKwl9KGA4y9p1A==","repository":{"url":"git+https://github.com/Amaretto-Software-Labs/cobalt-cli.git","type":"git"},"_npmVersion":"11.16.0","description":"Official command-line interface for Cobalt.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"^4.3.6","jose":"^6.1.3","commander":"^14.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/cobalt-cli_0.1.0_1787950847199_0.5359157424227121","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@amaretto-software-labs/cobalt-cli","version":"0.1.1","keywords":["cobalt","cli","coding-agent","developer-tools"],"license":"Apache-2.0","_id":"@amaretto-software-labs/cobalt-cli@0.1.1","maintainers":[{"name":"vlad_vasoftware","email":"vlad@vasoftware.co.uk"}],"homepage":"https://github.com/Amaretto-Software-Labs/cobalt-cli#readme","bugs":{"url":"https://github.com/Amaretto-Software-Labs/cobalt-cli/issues"},"bin":{"cobalt":"dist/main.js"},"dist":{"shasum":"1da74a05eb93d83d9650781296e604d38687819c","tarball":"https://registry.npmjs.org/@amaretto-software-labs/cobalt-cli/-/cobalt-cli-0.1.1.tgz","fileCount":52,"integrity":"sha512-TKcuOfqW7G0PPnmsHpvyiZ1HZtq3ik4u99sOLGN6QENBn/xilkxUyf7rzPOrJAdlSQlO+y2GYv8Fj8+HAHZOYA==","signatures":[{"sig":"MEUCIFHAWqBX8ar94giUSbG2we2gMNaOe3Vczn2xMV3djTkYAiEA7BfRI5dvMkAgH/k85O+NEaqgHsmQsCpS0D8+SfWsRJU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@amaretto-software-labs%2fcobalt-cli@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":473964},"type":"module","_from":"file:/home/runner/work/cobalt-cli/cobalt-cli/package/amaretto-software-labs-cobalt-cli-0.1.1.tgz","engines":{"node":">=22"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:c05c4021-51e4-4e9a-8b3f-024e3bd0c754"}},"_resolved":"/home/runner/work/cobalt-cli/cobalt-cli/package/amaretto-software-labs-cobalt-cli-0.1.1.tgz","_integrity":"sha512-TKcuOfqW7G0PPnmsHpvyiZ1HZtq3ik4u99sOLGN6QENBn/xilkxUyf7rzPOrJAdlSQlO+y2GYv8Fj8+HAHZOYA==","repository":{"url":"git+https://github.com/Amaretto-Software-Labs/cobalt-cli.git","type":"git"},"_npmVersion":"11.17.0","description":"Official command-line interface for Cobalt.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"zod":"^4.3.6","jose":"^6.1.3","commander":"^14.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/cobalt-cli_0.1.1_1787953758223_0.7388575240466908","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@amaretto-software-labs/cobalt-cli","version":"0.1.2","keywords":["cobalt","cli","coding-agent","developer-tools"],"license":"Apache-2.0","_id":"@amaretto-software-labs/cobalt-cli@0.1.2","maintainers":[{"name":"vlad_vasoftware","email":"vlad@vasoftware.co.uk"}],"homepage":"https://github.com/Amaretto-Software-Labs/cobalt-cli#readme","bugs":{"url":"https://github.com/Amaretto-Software-Labs/cobalt-cli/issues"},"bin":{"cobalt":"dist/main.js"},"dist":{"shasum":"27672b0d3edc668c886a191982d28e077a6e0001","tarball":"https://registry.npmjs.org/@amaretto-software-labs/cobalt-cli/-/cobalt-cli-0.1.2.tgz","fileCount":55,"integrity":"sha512-AxmYZlFnEv4lPvqpn3XlIwol9fzHTGbUiUrt6YJeYW7Axy8J+tzlos12dafxUph4dFx9zA0IgDjiKGlC+TaeRA==","signatures":[{"sig":"MEQCIGlt4opeTZ+1eZV2WQ1UIgTb9zKoQLWL9xyKJyounJ6bAiBHJH64nTAXQl/enkci9V7E3ss5KR9Mdtz4hYoOhNSdQA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@amaretto-software-labs%2fcobalt-cli@0.1.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":495550},"type":"module","_from":"file:/home/runner/work/cobalt-cli/cobalt-cli/package/amaretto-software-labs-cobalt-cli-0.1.2.tgz","engines":{"node":">=22"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:c05c4021-51e4-4e9a-8b3f-024e3bd0c754"}},"_resolved":"/home/runner/work/cobalt-cli/cobalt-cli/package/amaretto-software-labs-cobalt-cli-0.1.2.tgz","_integrity":"sha512-AxmYZlFnEv4lPvqpn3XlIwol9fzHTGbUiUrt6YJeYW7Axy8J+tzlos12dafxUph4dFx9zA0IgDjiKGlC+TaeRA==","repository":{"url":"git+https://github.com/Amaretto-Software-Labs/cobalt-cli.git","type":"git"},"_npmVersion":"11.17.0","description":"Official command-line interface for Cobalt.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"zod":"^4.3.6","jose":"^6.1.3","commander":"^14.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/cobalt-cli_0.1.2_1788086592838_0.0822696469351143","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@amaretto-software-labs/cobalt-cli","version":"0.1.3","description":"Official command-line interface for Cobalt.","license":"Apache-2.0","type":"module","repository":{"type":"git","url":"git+https://github.com/Amaretto-Software-Labs/cobalt-cli.git"},"homepage":"https://github.com/Amaretto-Software-Labs/cobalt-cli#readme","bugs":{"url":"https://github.com/Amaretto-Software-Labs/cobalt-cli/issues"},"bin":{"cobalt":"dist/main.js"},"exports":{"./oauth-callback":{"types":"./dist/oauth-callback.d.ts","import":"./dist/oauth-callback.js"}},"engines":{"node":">=22"},"dependencies":{"commander":"^14.0.3","jose":"^6.1.3","zod":"^4.3.6"},"keywords":["cobalt","cli","coding-agent","developer-tools"],"publishConfig":{"access":"public"},"_id":"@amaretto-software-labs/cobalt-cli@0.1.3","_integrity":"sha512-fYe6g0rvU5hBPICovT7QnikTvLVT947KBmEw2xUGmHXQaTCyLj9yK9F6Telrdw+AiqH19nDZhra740ntJEJJlg==","_resolved":"/home/runner/work/cobalt-cli/cobalt-cli/package/amaretto-software-labs-cobalt-cli-0.1.3.tgz","_from":"file:/home/runner/work/cobalt-cli/cobalt-cli/package/amaretto-software-labs-cobalt-cli-0.1.3.tgz","_nodeVersion":"24.20.0","_npmVersion":"11.19.0","dist":{"integrity":"sha512-fYe6g0rvU5hBPICovT7QnikTvLVT947KBmEw2xUGmHXQaTCyLj9yK9F6Telrdw+AiqH19nDZhra740ntJEJJlg==","shasum":"33685bd15bd94d97e89e627caf18d3fd954cad10","tarball":"https://registry.npmjs.org/@amaretto-software-labs/cobalt-cli/-/cobalt-cli-0.1.3.tgz","fileCount":61,"unpackedSize":771661,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@amaretto-software-labs%2fcobalt-cli@0.1.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDbaZWJxkncd97ggde6nML+OMiiX4oZpIxf21RMNIXk3AIgdpbxnSOxgvzIEsfsVm+1tC6D+UCKGid1+dQy2wQLZjM="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:c05c4021-51e4-4e9a-8b3f-024e3bd0c754"}},"directories":{},"maintainers":[{"name":"vlad_vasoftware","email":"vlad@vasoftware.co.uk"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/cobalt-cli_0.1.3_1788793359495_0.37867417902677447"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-28T21:00:46.992Z","modified":"2026-09-07T15:02:40.008Z","0.1.0":"2026-08-28T21:00:47.368Z","0.1.1":"2026-08-28T21:49:18.395Z","0.1.2":"2026-08-30T10:43:12.986Z","0.1.3":"2026-09-07T15:02:39.642Z"},"bugs":{"url":"https://github.com/Amaretto-Software-Labs/cobalt-cli/issues"},"license":"Apache-2.0","homepage":"https://github.com/Amaretto-Software-Labs/cobalt-cli#readme","keywords":["cobalt","cli","coding-agent","developer-tools"],"repository":{"type":"git","url":"git+https://github.com/Amaretto-Software-Labs/cobalt-cli.git"},"description":"Official command-line interface for Cobalt.","maintainers":[{"name":"vlad_vasoftware","email":"vlad@vasoftware.co.uk"}],"readme":"# Cobalt CLI\n\nThe official open-source command-line client for Cobalt. It talks only to the versioned Cobalt External API and is distributed as a normal npm package—there are no platform executables.\n\nWebsite: [cobaltcode.ai](https://cobaltcode.ai) · Built by [Amaretto Software Labs](https://amarettosoftware.com)\n\n## Install\n\nNode.js 22 or newer is required.\n\n```bash\nnpx @amaretto-software-labs/cobalt-cli --help\nnpm install --global @amaretto-software-labs/cobalt-cli\ncobalt auth login\n```\n\nOAuth sessions are stored in macOS Keychain, Windows Credential Manager, or Linux Secret Service. Credential storage fails closed; the CLI never falls back to a plaintext token file. For automation, provide one scoped token through `COBALT_TOKEN`.\n\nIf browser sign-in fails or you cancel consent, keep the CLI running. The branded\nrecovery page offers **Try again** and **Use another account** (which signs out of\nthe web app before returning to sign-in). You can also press **Enter** in an\ninteractive terminal to start a fresh attempt, or open the recovery URL printed\nby the CLI if you closed the browser. Each attempt uses new OAuth state and PKCE\nvalues. Attempts time out after five minutes; the retry page remains available\nfor another ten minutes. **Ctrl+C** stops login and closes the local listener.\nThe success page is shown only after credentials are validated and securely saved.\n\n## Quick start\n\n```bash\ncobalt auth login\ncobalt workspace list\ncobalt workspace use \"My Workspace\"\ncobalt repo list --eligible-only\ncobalt agent list --available\n\ncobalt task create \\\n  --repo my-repository \\\n  --message \"Fix the failing tests and open a PR\"\n\ncobalt task list --created-by-me\ncobalt task follow <task-id> --jsonl\n```\n\nEnvironments are selected with `--environment prod|dev|demo|local` or `COBALT_ENVIRONMENT`. Select a workspace with `--workspace`, `COBALT_WORKSPACE`, or the saved per-environment workspace context.\n\nThe `local` environment targets the standard Cobalt Aspire endpoints (`https://localhost:7295/v1`, `https://localhost:7270`, and `https://localhost:7250`) and reuses the development OAuth client registration. It adds the operating-system trust store to Node's default roots when the runtime supports that API. On older Node 22 builds, use `NODE_OPTIONS=--use-system-ca` after trusting the ASP.NET Core development certificate. Certificate verification remains enabled.\n\n## Commands\n\n```text\nauth login|logout|status\nworkspace list|use|current\nrepo list\nagent list\ntask list|get|search|create|messages|message-search|events\ntask send|steer|cancel|suspend|resume|auto-wake|delete|wait|follow|open\ntask queue list|hold|release|cancel|retry|move\nloop list|get|create|update|enable|disable|delete|run|rerun\nloop runs|decisions|lanes|descriptors|preview\nrole list|get|create|update|delete\ninteractive\ncompletion bash|zsh|fish|powershell\nversion\n```\n\nAll mutations accept `--idempotency-key <uuid>`. Message input uses exactly one of `--message`, `--message-file`, or `--stdin`. Output defaults to human-readable text; use `--json` for one envelope or `--jsonl` for streams and pagination.\n\nInteractive mode retains an ambiguous mutation's idempotency key and directs you to `/retry`, which safely replays the same operation with that key. Read-only inspection remains available, while another mutation or context change waits for the replay.\n\nExit codes are stable: `0` success, `2` usage, `3` authentication, `4` authorization, `5` not found, `6` conflict, `7` rate limited, `8` unavailable, `9` admission, `10` configuration, and `130` interrupted.\n\n## Loops and worker roles\n\nRead the current definition before replacing it. Updates require its observed\nversion/revision and one complete file; creates start no work. Enabling a Loop\nauthorizes its future unattended runs as your current identity.\n\n```bash\ncobalt loop list --all\ncobalt loop get <loop-id> --json\ncobalt loop update <loop-id> --document-file review.md --expected-version 7\ncobalt loop enable <loop-id> --expected-version 8\ncobalt loop runs <loop-id> --all\ncobalt loop descriptors --json\n\ncobalt role list --all\ncobalt role get pr-reviewer --json\ncobalt role update pr-reviewer --name \"PR Reviewer\" --description \"Review PRs\" \\\n  --instructions-file reviewer.md --expected-revision 2\n\ncobalt task create --repo <repository-id> --pull-request 184 \\\n  --title \"[PR Review 184] Review current revision\" --retention persistent \\\n  --default-role pr-reviewer --role pr-reviewer --no-auto-wake \\\n  --computer-idle-policy suspend_after_turn --message \"Review the exact head/base.\"\ncobalt task send <task-id> --role pr-reviewer --message \"Review the next revision.\"\ncobalt task auto-wake <task-id> off\n```\n\nTask creation supports `--on-hold`; inspect and release admission through\n`cobalt task queue`. Role selection belongs to task creation or message send.\n`task resume` restores compute and does not accept a role. Auto-wake controls\ngeneric environment restoration on resume; it is separate from automatic\nsuspension after a turn. Server-side permissions, capacity, and immutable role\nsnapshots apply to every command.\n\n## Reuse the branded OAuth callback in an MCP client\n\nDesktop MCP clients can use the same renderer and response headers as the CLI:\n\n```js\nimport {\n  oauthCallbackResponseHeaders,\n  renderOAuthCallbackPage,\n} from \"@amaretto-software-labs/cobalt-cli/oauth-callback\";\n\n// Only after the client's OAuth state/PKCE and token validation succeed:\nresponse.writeHead(200, oauthCallbackResponseHeaders);\nresponse.end(renderOAuthCallbackPage(\"success\", undefined, \"mcp\"));\n```\n\nThe shared renderer supports `success`, `cancelled`, `waiting`, `invalid`,\n`timeout`, and `failed` states. The MCP variant directs the user back to their\ndesktop app. It performs no OAuth operations and never receives tokens or raw\nprovider error details. The client owns validation, token storage, and listener\ncleanup. Pass a local retry path only when the client implements that route.\n\n## Development\n\n```bash\ncorepack enable\npnpm install --frozen-lockfile\npnpm verify\n```\n\n[`openapi/v1.json`](openapi/v1.json) is the canonical Cobalt External API schema copied from the product repository. `pnpm openapi:check` fails if its 39 CLI operations drift from the client mapping. The five OAuth browser-session operations are accounted for separately because they belong to the browser extension.\n\n## Releasing\n\nThe release workflow uses Node 24, pnpm 10.14.0, npm provenance, and npm trusted publishing through GitHub OIDC. Main-branch releases publish a generated `0.1.0-dev.<run>.<attempt>` version under the `dev` tag. Manual runs support `dev`, `demo`, and stable `prod` channels.\n\nCreate GitHub environments named `dev`, `demo`, and `prod` before enabling releases, and configure `prod` with required reviewers. Both package creation and publishing are bound to the selected environment so a production release cannot bypass its approval policy.\n\nThe package must exist before npm allows a trusted publisher to be configured. Bootstrap publishing once from an npm account protected by 2FA:\n\n1. Run `pnpm verify`, then generate the chosen initial version with `COBALT_CLI_PACKAGE_VERSION=<version> pnpm pack:check`.\n2. Authenticate with npm and run `npm publish release/npm/*.tgz --access public`, completing the 2FA prompt.\n3. In the npm package settings, add the GitHub Actions trusted publisher for `Amaretto-Software-Labs/cobalt-cli` and workflow `release.yml`.\n4. Set the repository variable `NPM_TRUSTED_PUBLISHING_ENABLED` to `true`.\n\nUntil that variable is enabled, main pushes still run CI and build the release artifact, while the publish job is intentionally skipped.\n\n## Security\n\nPlease report vulnerabilities privately through GitHub Security Advisories. Do not include access tokens, refresh tokens, task messages, or repository content in public issues.\n\n## License\n\nApache-2.0.\n","readmeFilename":"README.md"}