{"_id":"@axiom-studio/vibeflow-setup","_rev":"4-4ec631a0e2678709f237074bf1baebfb","name":"@axiom-studio/vibeflow-setup","dist-tags":{"latest":"0.2.0"},"versions":{"0.1.0":{"name":"@axiom-studio/vibeflow-setup","version":"0.1.0","keywords":["vibeflow","mcp","setup","bootstrap","ai-agents"],"license":"Apache-2.0","_id":"@axiom-studio/vibeflow-setup@0.1.0","maintainers":[{"name":"rwxvishnu","email":"vish@axiomstudio.ai"},{"name":"krypton_2303","email":"piyush@axiomstudio.ai"}],"homepage":"https://github.com/axiom-studio/vibeflow-cli#readme","bugs":{"url":"https://github.com/axiom-studio/vibeflow-cli/issues"},"bin":{"vibeflow-setup":"index.js"},"dist":{"shasum":"d9ca70b3962e73488bada0e40c9ef666d3c5613e","tarball":"https://registry.npmjs.org/@axiom-studio/vibeflow-setup/-/vibeflow-setup-0.1.0.tgz","fileCount":3,"integrity":"sha512-tQKEC1lyWPyUohVKTAZsgeF0hqr6ZFm8y23u20te6q8vWt9vL4EvhANRAssi2Y+tefNMX9mATRdkwhocL3Qvvw==","signatures":[{"sig":"MEQCIDz6f5m3Nt/ZCReEiiPImLxL/ty8oeTDYAtrnKE8WRVAAiAvG/oLsL/qkCypDOinipSTuv3HtblDoFC71EKwVs9tuw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":10226},"engines":{"node":">=18"},"gitHead":"ab864dc494addf68d34c70a18caf3b283d9edbaa","_npmUser":{"name":"krypton_2303","email":"piyush@axiomstudio.ai"},"repository":{"url":"git+https://github.com/axiom-studio/vibeflow-cli.git","type":"git","directory":"npx"},"_npmVersion":"11.4.2","description":"One-command VibeFlow setup: downloads vibeflow-cli, installs tmux, and configures the VibeFlow MCP server for your coding agents.","directories":{},"_nodeVersion":"22.17.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/vibeflow-setup_0.1.0_1785661312689_0.9201254549970701","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@axiom-studio/vibeflow-setup","version":"0.2.0","keywords":["vibeflow","mcp","setup","bootstrap","ai-agents"],"license":"Apache-2.0","_id":"@axiom-studio/vibeflow-setup@0.2.0","maintainers":[{"name":"rwxvishnu","email":"vish@axiomstudio.ai"},{"name":"krypton_2303","email":"piyush@axiomstudio.ai"},{"name":"rparth","email":"ranjan@axiomstudio.ai"}],"homepage":"https://github.com/axiom-studio/vibeflow-cli#readme","bugs":{"url":"https://github.com/axiom-studio/vibeflow-cli/issues"},"bin":{"vibeflow-setup":"index.js"},"dist":{"shasum":"8d0a1a77bc802929d5d53e581754682801d3826f","tarball":"https://registry.npmjs.org/@axiom-studio/vibeflow-setup/-/vibeflow-setup-0.2.0.tgz","fileCount":3,"integrity":"sha512-ZctvkW3LY2WqBh4ywdHEIFGyA2mOw+Tddjd8jrpj26/9cQg376kDs528uImHRv7d12mcRvGdjiGLRYg055AorQ==","signatures":[{"sig":"MEYCIQDAJtXgs0ALOKGiSNwCOcmFh848gsgJaj2eut7Sb1pLAwIhAPxbzzHiSmwXu8TmWQmH2Szbnjl/uc9F/puHWjp6zBcM","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":34926},"engines":{"node":">=18"},"gitHead":"76a87e6dc0291235cb05727b5f84eec421d0c316","scripts":{"test":"node --test index.test.js signed-release.test.js"},"_npmUser":{"name":"krypton_2303","email":"piyush@axiomstudio.ai"},"repository":{"url":"git+https://github.com/axiom-studio/vibeflow-cli.git","type":"git","directory":"npx"},"_npmVersion":"11.4.2","description":"One-command VibeFlow setup: downloads vibeflow-cli, installs tmux, and configures the VibeFlow MCP server for your coding agents.","directories":{},"_nodeVersion":"22.17.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/vibeflow-setup_0.2.0_1786460332083_0.21844419843853302","host":"s3://npm-registry-packages-npm-production"}}},"time":{"created":"2026-08-02T09:01:52.485Z","modified":"2026-08-13T23:15:29.091Z","0.1.0":"2026-08-02T09:01:52.857Z","0.2.0":"2026-08-11T14:58:52.231Z"},"bugs":{"url":"https://github.com/axiom-studio/vibeflow-cli/issues"},"license":"Apache-2.0","homepage":"https://github.com/axiom-studio/vibeflow-cli#readme","keywords":["vibeflow","mcp","setup","bootstrap","ai-agents"],"repository":{"url":"git+https://github.com/axiom-studio/vibeflow-cli.git","type":"git","directory":"npx"},"description":"One-command VibeFlow setup: downloads vibeflow-cli, installs tmux, and configures the VibeFlow MCP server for your coding agents.","maintainers":[{"email":"piyush@axiomstudio.ai","name":"krypton_2303"},{"email":"ranjan@axiomstudio.ai","name":"rparth"}],"readme":"# @axiom-studio/vibeflow-setup\n\nOne-command setup for VibeFlow. Replaces the manual Setup-page steps with:\n\n```bash\nnpx @axiom-studio/vibeflow-setup --api-key <API_KEY>\n```\n\nIt will:\n\n1. Download the matching `vibeflow-cli` release binary for your OS/arch into\n   `~/.vibeflow/bin`, after verifying its SHA-256 against the release's published\n   `checksums.txt`. A mismatch deletes the download and aborts before the binary\n   is executed in step 3.\n\n   When the release also publishes `checksums.txt.sig`, its **Ed25519 signature**\n   is verified against a public key pinned in `index.js` — that is what proves the\n   checksum list came from us, not merely from the same server as the archive.\n   Verified with Node's built-in `crypto`, so there is nothing extra to install.\n\n   Once signing is live, a **missing** signature is refused by default for any\n   release in the signed era — withholding a `.sig` would otherwise be a free way\n   to downgrade the check back to same-origin trust. `--allow-unsigned` overrides\n   that; a **bad** signature always aborts and cannot be overridden.\n\n   **Current state:** signing is wired up but **inert until a release key is\n   generated and the signed-era floor is set** (see [SIGNING.md](SIGNING.md)).\n   Until then, and for genuinely older releases, the installer verifies checksums\n   and says plainly that authenticity is unverified rather than implying a check\n   it is not performing. Pass `--require-signature` to refuse anything unsigned\n   even now.\n2. Install **tmux** if it is missing (apt / dnf / yum / apk / brew). Skipped on\n   Windows. If tmux is still missing afterwards the installer says so explicitly,\n   because `vibeflow launch` cannot work without it.\n3. Run `vibeflow bootstrap --all --api-key <key>`, which writes **7 targets**: the\n   MCP server config for all six supported agents — Claude CLI, Claude Desktop,\n   Gemini CLI, Cursor, Codex CLI, **Kiro CLI** — plus the `vibeflow-cli` `config.yaml`\n   that stores your API key.\n\n   Each agent config carries the endpoint and a `${MCP_TOKEN}` reference rather\n   than the key itself. Four of the five JSON agents also get the 300000 ms\n   client timeout; **Claude CLI deliberately gets none**, because it honors the\n   `MCP_TIMEOUT` environment variable instead (bootstrap prints a note about\n   this). Codex uses TOML with `bearer_token_env_var`. Claude Desktop is the one\n   exception that stores the real key, in its own `env` block at mode 0600 —\n   it is a GUI app, so it cannot receive a variable injected at launch.\n\n## Options\n\n| Flag | Default | Meaning |\n|---|---|---|\n| `--api-key <key>` | (required) | VibeFlow API key, from Account > API Keys |\n| `--base-url <url>` | `https://cloud.axiomstudio.ai` | VibeFlow base URL |\n| `--agents <csv>` | all | Configure only these agents |\n| `--all` | on | Configure all supported agents |\n| `--version <tag>` | latest | Pin a specific `vibeflow-cli` release |\n| `--skip-checksum` | off | Skip SHA-256 verification of the download (not recommended) |\n| `--require-signature` | off | Refuse to install unless the release checksums carry a valid signature |\n\n## Verify\n\nThe configs reference the token as `${MCP_TOKEN}`, so the variable must be set in\nwhatever shell you verify from:\n\n```bash\nMCP_TOKEN=<your-api-key> claude mcp list   # should show: vibeflow ... ✓ Connected\n```\n\nWithout it you get `[Warning] mcpServers.vibeflow: Missing environment variables:\nMCP_TOKEN` and no connection. That is expected, not a failed setup — `vibeflow\nlaunch` and the TUI inject `MCP_TOKEN` into every agent they start, so **only\nhand-started agents need the export**. To verify through the supported path\ninstead, run `vibeflow launch` and let the agent call `list_projects`.\n\n## Notes\n\n- Requires Node >= 18. No npm dependencies (built-in modules only).\n- Linux, macOS, and Windows (amd64/arm64) are supported.\n- On Windows the MCP config is written normally, so Claude Desktop and the other\n  agents connect — but `vibeflow launch` needs **tmux**, which has no Windows\n  port, so run session launching under WSL. Step 2 (tmux install) is skipped.\n- Model selection from the Setup UI is handled at agent-launch time, not by\n  `bootstrap`, so it is not a flag here.\n","readmeFilename":"README.md"}