{"_id":"@caipe-io/caipe","_rev":"2-e509deae73bb0558e0481b631d2013b0","name":"@caipe-io/caipe","dist-tags":{"latest":"0.2.29"},"versions":{"0.2.26":{"name":"@caipe-io/caipe","version":"0.2.26","keywords":["caipe","ai","cli","acp","agent-client-protocol","platform-engineering"],"license":"Apache-2.0","_id":"@caipe-io/caipe@0.2.26","maintainers":[{"name":"caipe","email":"outshiftcaipe@gmail.com"}],"homepage":"https://github.com/caipe-io/caipe-cli#readme","bugs":{"url":"https://github.com/caipe-io/caipe-cli/issues"},"bin":{"caipe":"bin/caipe.cjs"},"dist":{"shasum":"9ab85804f6b46db40930661eafc1bc49f20a0695","tarball":"https://registry.npmjs.org/@caipe-io/caipe/-/caipe-0.2.26.tgz","fileCount":89,"integrity":"sha512-zc2u4tZAxDC/ND5kiSOBRqfv8cE8copb0Gh3g9H8uIGOsvPgTi3ShxMWc5gzmfMPsJ0iaLuVkgFL1YEw07uVFw==","signatures":[{"sig":"MEUCIBX3gInaVZWir3PUu4nWNusYRI0exiAqLyd1ZkvrNuTaAiEA/ELXLOVqrBf7T4nR5B6MRplf5gEIJ+aY/mNLpskfqW8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":435694},"type":"module","engines":{"node":">=20.17"},"gitHead":"6f1570164539899ebf40b634b850cdf38fe42316","scripts":{"dev":"tsx src/index.ts","lint":"biome check src/ tests/","test":"vitest run","build":"esbuild src/index.ts --bundle --platform=node --target=node20 --format=cjs --outfile=dist/bundle.cjs --external:keytar --external:fsevents","format":"biome format --write src/ tests/","compile":"bun build src/index.ts --compile --target=bun-darwin-arm64 --outfile=dist/caipe --external keytar && codesign --remove-signature dist/caipe && codesign --sign - --force --entitlements entitlements.plist dist/caipe","lint:fix":"biome check --write src/ tests/","test:e2e":"vitest run tests/cli.e2e.test.ts","link:path":"sh scripts/link-path.sh","test:unit":"vitest run --exclude tests/cli.e2e.test.ts","test:watch":"vitest","compile:all":"npm run compile:darwin-arm64 && npm run compile:darwin-x64 && npm run compile:linux-arm64 && npm run compile:linux-x64","compile:linux-x64":"bun build src/index.ts --compile --target=bun-linux-x64 --outfile=dist/caipe-linux-x64 --external keytar","compile:darwin-x64":"bun build src/index.ts --compile --target=bun-darwin-x64 --outfile=dist/caipe-darwin-x64 --external keytar && codesign --remove-signature dist/caipe-darwin-x64 && codesign --sign - --force --entitlements entitlements.plist dist/caipe-darwin-x64","compile:linux-arm64":"bun build src/index.ts --compile --target=bun-linux-arm64 --outfile=dist/caipe-linux-arm64 --external keytar","compile:darwin-arm64":"bun build src/index.ts --compile --target=bun-darwin-arm64 --outfile=dist/caipe-darwin-arm64 --external keytar && codesign --remove-signature dist/caipe-darwin-arm64 && codesign --sign - --force --entitlements entitlements.plist dist/caipe-darwin-arm64"},"_npmUser":{"name":"caipe","email":"outshiftcaipe@gmail.com"},"overrides":{"vite":"6.4.3","react-devtools-core":"file:./src/stubs/react-devtools-core"},"repository":{"url":"git+https://github.com/caipe-io/caipe-cli.git","type":"git"},"_npmVersion":"11.11.1","description":"AI-assisted coding, workflows, and platform engineering from the terminal","directories":{},"_nodeVersion":"25.8.2","dependencies":{"ink":"5.2.1","tsx":"4.21.0","zod":"3.25.76","diff":"8.0.3","execa":"9.6.1","react":"18.3.1","marked":"15","semver":"7.7.4","commander":"12.1.0","@ag-ui/client":"0.0.52","marked-terminal":"7","react-devtools-core":"file:./src/stubs/react-devtools-core","@agentclientprotocol/sdk":"1.4.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"3.2.6","esbuild":"0.25.0","typescript":"5.9.3","@types/node":"22.19.17","@types/react":"18.3.28","@types/semver":"7.7.1","@biomejs/biome":"1.9.4"},"trustedDependencies":["@biomejs/biome"],"optionalDependencies":{"keytar":"7.9.0","caipe-linux-x64":"0.2.26","caipe-darwin-x64":"0.2.26","caipe-linux-arm64":"0.2.26","caipe-darwin-arm64":"0.2.26"},"_npmOperationalInternal":{"tmp":"tmp/caipe_0.2.26_1787675205846_0.6396868548526504","host":"s3://npm-registry-packages-npm-production"}},"0.2.29":{"name":"@caipe-io/caipe","version":"0.2.29","description":"AI-assisted coding, workflows, and platform engineering from the terminal","type":"module","bin":{"caipe":"bin/caipe.cjs"},"scripts":{"build":"esbuild src/index.ts --bundle --platform=node --target=node20 --format=cjs --outfile=dist/bundle.cjs --external:keytar --external:fsevents","compile:darwin-arm64":"bun build src/index.ts --compile --target=bun-darwin-arm64 --outfile=dist/caipe-darwin-arm64 --external keytar && codesign --remove-signature dist/caipe-darwin-arm64 && codesign --sign - --force --entitlements entitlements.plist dist/caipe-darwin-arm64","compile:darwin-x64":"bun build src/index.ts --compile --target=bun-darwin-x64 --outfile=dist/caipe-darwin-x64 --external keytar && codesign --remove-signature dist/caipe-darwin-x64 && codesign --sign - --force --entitlements entitlements.plist dist/caipe-darwin-x64","compile:linux-arm64":"bun build src/index.ts --compile --target=bun-linux-arm64 --outfile=dist/caipe-linux-arm64 --external keytar","compile:linux-x64":"bun build src/index.ts --compile --target=bun-linux-x64 --outfile=dist/caipe-linux-x64 --external keytar","compile:all":"npm run compile:darwin-arm64 && npm run compile:darwin-x64 && npm run compile:linux-arm64 && npm run compile:linux-x64","compile":"bun build src/index.ts --compile --target=bun-darwin-arm64 --outfile=dist/caipe --external keytar && codesign --remove-signature dist/caipe && codesign --sign - --force --entitlements entitlements.plist dist/caipe","dev":"tsx src/index.ts","test":"vitest run","test:unit":"vitest run --exclude tests/cli.e2e.test.ts","test:e2e":"vitest run tests/cli.e2e.test.ts","test:watch":"vitest","lint":"biome check src/ tests/","lint:fix":"biome check --write src/ tests/","format":"biome format --write src/ tests/","link:path":"sh scripts/link-path.sh"},"dependencies":{"@ag-ui/client":"0.0.52","@agentclientprotocol/sdk":"1.4.0","commander":"12.1.0","diff":"8.0.3","execa":"9.6.1","ink":"5.2.1","marked":"15","marked-terminal":"7","react":"18.3.1","react-devtools-core":"file:./src/stubs/react-devtools-core","semver":"7.7.4","tsx":"4.21.0","zod":"3.25.76"},"devDependencies":{"@biomejs/biome":"1.9.4","@types/node":"22.19.17","@types/react":"18.3.28","@types/semver":"7.7.1","esbuild":"0.25.0","typescript":"5.9.3","vitest":"3.2.6"},"optionalDependencies":{"caipe-darwin-arm64":"0.2.29","caipe-darwin-x64":"0.2.29","caipe-linux-arm64":"0.2.29","caipe-linux-x64":"0.2.29","keytar":"7.9.0"},"engines":{"node":">=20.17"},"keywords":["caipe","ai","cli","acp","agent-client-protocol","platform-engineering"],"license":"Apache-2.0","repository":{"type":"git","url":"git+https://github.com/caipe-io/caipe-cli.git"},"trustedDependencies":["@biomejs/biome"],"overrides":{"react-devtools-core":"file:./src/stubs/react-devtools-core","vite":"6.4.3"},"gitHead":"002c46460a52d40945007174f9217e01b1616ded","_id":"@caipe-io/caipe@0.2.29","bugs":{"url":"https://github.com/caipe-io/caipe-cli/issues"},"homepage":"https://github.com/caipe-io/caipe-cli#readme","_nodeVersion":"24.19.0","_npmVersion":"11.15.0","dist":{"integrity":"sha512-IVTDNvEtdnUKW1u4w49iMw+dOblRzn8PQoLGFyNcH+NZ+471SeGK10fjxvsXZUW15zxIqKeH04lNxWcAEi0cug==","shasum":"42fce89ef367c0742029218e9db4e19d1fef3733","tarball":"https://registry.npmjs.org/@caipe-io/caipe/-/caipe-0.2.29.tgz","fileCount":89,"unpackedSize":435672,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@caipe-io%2fcaipe@0.2.29","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDppmFCZ1XcWjJCsTxy2Ki08p3t/WvFtsK4n7XvyrZNvgIhAMgqmWLA2jqXzaoIYC4DOq0r3atGNbm1vaOyHgRXV7XM"}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a417efcc-86a1-4bd4-b92d-c235dfe927b4"}},"directories":{},"maintainers":[{"name":"caipe","email":"outshiftcaipe@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/caipe_0.2.29_1787676073073_0.3417062004253377"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-25T16:26:45.596Z","modified":"2026-08-25T16:41:13.682Z","0.2.26":"2026-08-25T16:26:46.070Z","0.2.29":"2026-08-25T16:41:13.242Z"},"bugs":{"url":"https://github.com/caipe-io/caipe-cli/issues"},"license":"Apache-2.0","homepage":"https://github.com/caipe-io/caipe-cli#readme","keywords":["caipe","ai","cli","acp","agent-client-protocol","platform-engineering"],"repository":{"type":"git","url":"git+https://github.com/caipe-io/caipe-cli.git"},"description":"AI-assisted coding, workflows, and platform engineering from the terminal","maintainers":[{"name":"caipe","email":"outshiftcaipe@gmail.com"}],"readme":"# CAIPE CLI\n\nTerminal client for [CAIPE](https://github.com/cnoe-io/ai-platform-engineering): chat with dynamic agents, manage skills, and run headless prompts against a remote CAIPE UI / BFF.\n\n## TL;DR\n\n**Install CAIPE CLI:**\n\n```bash\ncurl -fsSL https://raw.githubusercontent.com/cnoe-io/caipe-cli/main/install.sh | sh\n```\n\nThe installer downloads the latest verified release and asks where to place the\n`caipe` launcher. Press Enter for `~/.local/bin` (recommended, no password),\nchoose `~/.bin`, or stage a launcher for an explicit system-wide install. The\nweb-fetched script never invokes `sudo` or reads a password.\n\n**Point at your CAIPE deployment, sign in, chat:**\n\n```bash\ncaipe config set server.url https://caipe.example.com\ncaipe config set auth.url https://idp.caipe.example.com/realms/caipe\ncaipe auth login\ncaipe agents list\ncaipe chat --agent '<id-from-agents-list>'\n```\n\nType messages at the `❯` prompt. **`/`** for commands, **`Ctrl+O`** to pick an agent, **`Ctrl+D`** to exit.\n\nPrompt line editing is implemented in-tree (`src/chat/line-edit.ts`, Apache-2.0): common bash/emacs keys (Ctrl+A/E/K/U/W/Y, Alt+b/f/d, Ctrl+R history search, etc.). It does **not** use GNU Readline or other GPL line-editing libraries.\n\nOther host (UI serves OAuth on the same URL): set only `server.url`, then `caipe auth login` and `caipe chat`.\n\n---\n\n- macOS or Linux on arm64 or x64\n- `curl` and Node.js 20 or newer\n- A reachable CAIPE deployment (API + OAuth)\n\nOptional: **keytar** only if you set `auth.credential-storage` to `keychain`.\n\n---\n\n## Install\n\n```bash\ncurl -fsSL https://raw.githubusercontent.com/cnoe-io/caipe-cli/main/install.sh | sh\n```\n\nThe installer asks you to choose:\n\n1. `~/.local/bin` — recommended, no password\n2. `~/.bin` — user-owned alternative, no password\n3. `/usr/local/bin` — stages the launcher and prints separate review/install commands\n\nPress Enter to accept option 1. In a non-interactive environment, option 1 is\nselected automatically. Then verify with `caipe --version`. If the selected\ndirectory is not already on `PATH`, the installer prints the exact command to\nadd it.\n\nAutomation can bypass the prompt with `CAIPE_INSTALL_DIR`. For example, choose\nthe user-owned `~/.bin` directory without a password:\n\n```bash\ncurl -fsSL https://raw.githubusercontent.com/cnoe-io/caipe-cli/main/install.sh \\\n  | CAIPE_INSTALL_DIR=\"$HOME/.bin\" sh\n```\n\nChoose a system-wide directory explicitly:\n\n```bash\ncurl -fsSL https://raw.githubusercontent.com/cnoe-io/caipe-cli/main/install.sh \\\n  | CAIPE_INSTALL_DIR=/usr/local/bin sh\n```\n\nThe web installer downloads and verifies the binary, stages the launcher under\n`~/.local/share/caipe`, and stops. It never invokes `sudo`. Review the staged\nlauncher, then separately run the exact `sudo mkdir` and `sudo install` commands\nit prints.\n\nIn every case, `CAIPE_INSTALL_DIR` controls only the small launcher on `PATH`;\nthe platform binary is stored under `~/.local/share/caipe` by default.\n\nThe installer downloads the latest multi-architecture GitHub release and\nverifies its SHA-256 checksum. Pin a release when reproducibility matters:\n\n```bash\ncurl -fsSL https://raw.githubusercontent.com/cnoe-io/caipe-cli/main/install.sh \\\n  | CAIPE_VERSION=0.2.22 sh\n```\n\nAlternatively, install the npm package. The executable is still named `caipe`:\n\n```bash\nnpm install -g @caipe-io/caipe\ncaipe --version\n```\n\n### Updates\n\nInteractive chat checks GitHub Releases at most once every 24 hours. Known\nbinary installs update automatically; other install types receive one\nnotification per release. Update manually:\n\n```bash\ncaipe update --check    # inspect only\ncaipe update            # download, verify, smoke-test, and install\n```\n\nDownloaded binaries must match `caipe-checksums.txt` and pass `--version`\nbefore atomically replacing the installed binary. npm-managed installations\ndelegate an explicit update to npm. Verified binary updates install\nautomatically by default:\n\n```bash\ncaipe config set updates.mode notify  # auto (default), notify, or off\n```\n\nSource or unknown launchers fall back to a notification and an actionable\nmanual update command. Set `CAIPE_NO_UPDATE_CHECK=1` for a one-off invocation.\n\nEvery commit to `main` is released after the full CI workflow succeeds. The\nrelease workflow creates the next patch tag, publishes checksummed binaries,\nsigns them with cosign, and publishes the matching npm packages.\n\n---\n\n## Developer guide\n\n### Build from source\n\n```bash\ngit clone https://github.com/cnoe-io/caipe-cli.git\ncd caipe-cli\nbun install\nnpm run compile          # native binary → dist/caipe\n./dist/caipe --version\n```\n\nFor a development checkout, run `npm link` or use `node bin/caipe.cjs` rather\nthan copying the compiled binary into `PATH`.\n\n### Other build targets\n\n| Command | Output |\n|--------|--------|\n| `npm run dev -- chat` | Run via **tsx** (fast iteration, no compile) |\n| `npm run build` | Node bundle `dist/bundle.cjs` (keytar external) |\n| `node bin/caipe.cjs chat` | Entry script: platform binary → `dist/caipe` → bundle → tsx |\n| `npm run compile:all` | Cross-compile all platform binaries in `dist/` |\n\n**Compile note:** `npm run compile` uses Bun with **`keytar` external** so the default **encrypted-file** credential store works without building native modules. If you use the keychain backend:\n\n```bash\nnpm install keytar\nnpm rebuild keytar\ncaipe config set auth.credential-storage keychain\n```\n\n### Verify the build\n\n```bash\nnpm run lint\nnpm test\n```\n\n### Publish a release\n\nThe `Publish caipe CLI` GitHub Actions workflow runs for semantic-version tags.\nIt verifies the source, builds and smoke-tests all four supported binaries,\npublishes a GitHub release with checksums and keyless cosign signatures, then\npublishes the four platform packages and the top-level `@caipe-io/caipe` npm\npackage.\n\n| Operating system | Architecture | npm platform package | Release asset |\n|------------------|--------------|----------------------|---------------|\n| macOS | Apple Silicon (arm64) | `caipe-darwin-arm64` | `caipe-darwin-arm64` |\n| macOS | Intel (x64) | `caipe-darwin-x64` | `caipe-darwin-x64` |\n| Linux | arm64 | `caipe-linux-arm64` | `caipe-linux-arm64` |\n| Linux | x64 | `caipe-linux-x64` | `caipe-linux-x64` |\n\n```bash\ngit tag 0.2.22\ngit push origin 0.2.22\n```\n\nPublishing uses npm Trusted Publishing with GitHub Actions OIDC; no long-lived\nnpm write token is stored in GitHub. Configure `@caipe-io/caipe` and the four\n`caipe-<os>-<arch>` packages on npmjs.com with this trusted publisher:\n\n- GitHub organization: `caipe-io`\n- Repository: `caipe-cli`\n- Workflow: `release.yml`\n- Environment: `npm-publish`\n- Allowed action: `npm publish`\n\nThe packages must exist in the registry before npm allows trusted-publisher\nconfiguration. Bootstrap each package once from a maintainer workstation using\ninteractive npm authentication and 2FA, then configure the trust relationship\nand disallow token-based publishing. Protect the GitHub `npm-publish`\nenvironment with required reviewers and deployment branch/tag rules.\n\nPrerelease tags such as `0.2.22-rc.1` publish to npm's `next` dist-tag; stable\nversions publish to `latest`.\n\n---\n\n## Configure and sign in\n\nSettings live in **`~/.config/caipe/settings.json`**.\n\n### Typical setup (single host)\n\nWhen the UI exposes OAuth and `/.well-known/agent.json` on the same host:\n\n```bash\ncaipe config set server.url https://your-caipe.example.com\ncaipe auth login\ncaipe agents list\ncaipe config set agent.default agent-sre   # id from agents list; optional\ncaipe chat\n```\n\n`config set server.url` also sets **`auth.url`** to the same value.\n\n### Split API vs IdP\n\nOn some deployments the BFF may not expose `/oauth/authorize` yet. Point the\n**API** at CAIPE and **OAuth** at Keycloak:\n\n```bash\ncaipe config set server.url https://caipe.example.com\ncaipe config set auth.url https://idp.caipe.example.com/realms/caipe\nrm -f ~/.config/caipe/agent-config.json\ncaipe auth logout    # if you have stale tokens\ncaipe auth login\n```\n\nOptional IdP shortcut (e.g. Duo SSO):\n\n```bash\ncaipe config set auth.idp-hint duo-sso\n# or: export CAIPE_IDP_HINT=duo-sso\n```\n\n### Environment overrides\n\n| Variable | Purpose |\n|----------|---------|\n| `CAIPE_SERVER_URL` | BFF base URL (agents, chat stream) |\n| `CAIPE_AUTH_URL` | OAuth / discovery base (login) |\n| `CAIPE_DEFAULT_AGENT` | Default dynamic agent id (overrides `agent.default` in settings) |\n| `CAIPE_UPDATE_MODE` | CLI update behavior: `auto` (default), `notify`, or `off` |\n| `CAIPE_NO_UPDATE_CHECK` | Set to `1` to skip the startup update check |\n| `CAIPE_AUTH_REALM` | Keycloak realm name for IdP heuristics (default `caipe`) |\n| `CAIPE_PLAIN_TERMINAL` | Set to `1` to disable rich markdown, alt screen, and inline images |\n| `CAIPE_NO_ALT_SCREEN` | Set to `1` to keep chat in the normal scrollback buffer |\n| `CAIPE_NO_INLINE_IMAGES` | Set to `1` to disable iTerm2 inline image rendering |\n| `CAIPE_STREAM_BUFFER_MS` | Token flush interval while streaming (default `50`) |\n| `CAIPE_STREAM_PLAIN` | Set to `1` for legacy plain-text chunk streaming (no live markdown colors) |\n| `CAIPE_IDP_HINT` | Keycloak `kc_idp_hint` |\n| `CAIPE_CALLBACK_PORT` | OAuth loopback port (default `8085`; the IdP must register any override) |\n| `CAIPE_TOKEN` | Bearer token (headless / CI) |\n| `CAIPE_KB_URL` | Knowledge Base RAG API base URL |\n| `CAIPE_TENANT_ID` | `X-Tenant-Id` for KB API calls (when not using default tenant) |\n| `CAIPE_API_KEY` | API key where supported |\n\n### Auth troubleshooting\n\n| Symptom | What to do |\n|---------|------------|\n| `Already authenticated as (unknown)` | `caipe auth logout` then `caipe auth login`, or upgrade to a build with session fixes |\n| Browser **404** on `/oauth/authorize` | Set `auth.url` to the realm issuer (see the split API/IdP section above) |\n| OAuth callback port `8085` is busy | CAIPE automatically retries on IPv6 loopback. Otherwise use `--device`, `--manual`, or `--callback-port <port>` when that port is registered with the IdP. |\n| `Invalid client_type: cli` | CLI retries with `slack` on older BFFs; upgrade UI to add `cli` to `VALID_CLIENT_TYPES` |\n| **403** `agent#use` / `pdp_denied` | Run `caipe agents list`, then `caipe chat --agent <id>` for an agent you can use; ask admin for OpenFGA **agent#use** if the list is empty |\n\n---\n\n## Use the CLI\n\n### Interactive chat (default)\n\n```bash\ncaipe                  # same as caipe chat\ncaipe chat --agent my-agent\n```\n\nIn the REPL:\n\n- **`/`** — slash commands (`/agents`, `/skills`, `/login`, `/help`, `/exit`, …)\n- **`!cmd`** — run a shell command and inject output\n- **`Esc`** — abort streaming\n\n### Agents and skills\n\n```bash\ncaipe agents list\ncaipe agents info <name>\ncaipe skills list\ncaipe skills install <name>\n```\n\n### Headless / CI\n\n```bash\ncaipe chat --headless --prompt \"Summarize open incidents\"\ncaipe chat --headless --prompt-file question.txt --output json\ncaipe chat --headless --token \"$JWT\" --prompt \"health check\"\n```\n\n### ACP editor integration\n\n`caipe acp` exposes accessible CAIPE agents to editors that support the\n[Agent Client Protocol](https://agentclientprotocol.com/). The editor launches\nthe CLI as a local subprocess; the CLI translates ACP JSON-RPC on stdio to the\nremote CAIPE AG-UI service.\n\nVerify the installed CLI, authenticate, and select an agent:\n\n```bash\ncaipe --version            # 0.2.26 or newer\ncaipe acp --help\ncaipe auth login\ncaipe agents list\ncaipe config set agent.default <agent-id>  # optional\n```\n\nFor [Zed custom agents](https://zed.dev/docs/ai/external-agents#custom-agents),\nuse the absolute path returned by `command -v caipe` in `settings.json`:\n\n```json\n{\n  \"agent_servers\": {\n    \"CAIPE\": {\n      \"type\": \"custom\",\n      \"command\": \"/absolute/path/to/caipe\",\n      \"args\": [\"acp\", \"--agent\", \"<agent-id>\"],\n      \"env\": {}\n    }\n  }\n}\n```\n\nEditors do not discover CAIPE merely because it is installed or exposes the\n`acp` subcommand. Configure it as a custom agent until CAIPE is published in\nthe [ACP Agent Registry](https://agentclientprotocol.com/get-started/registry).\n\nSee the **[complete ACP guide](docs/acp.md)** for discovery, authentication,\ncommand options, a published-binary smoke test, end-to-end acceptance testing,\ncapabilities, limitations, and troubleshooting.\n\n### Auth commands\n\n```bash\ncaipe auth status\ncaipe auth login --force\ncaipe auth login              # PKCE in isolated Chrome/Chromium (default)\ncaipe auth login --system-browser   # use default browser profile (can affect Web UI)\ncaipe auth login --device      # device code flow\ncaipe auth login --manual      # paste authorization code\ncaipe auth logout\n```\n\n**OAuth browser:** By default the CLI opens Chrome/Chromium with a **temporary profile** so logging in does not overwrite cookies for an open caipe-ui tab. Set `CAIPE_CHROMIUM_PATH` if Chrome is non-standard. `CAIPE_AUTH_BROWSER=system` restores the old behavior. `CAIPE_AUTH_HEADLESS=1` uses headless mode (often breaks MFA).\n\n### Knowledge Base (scripts / CI)\n\nNon-interactive commands talk to the [CAIPE RAG REST API](https://github.com/cnoe-io/ai-platform-engineering/tree/main/ai_platform_engineering/knowledge_bases/rag) and **always print JSON** to stdout (errors as JSON on stderr).\n\n```bash\ncaipe config set kb.url https://your-kb-api.example.com   # or export CAIPE_KB_URL\ncaipe auth login   # or export CAIPE_TOKEN / client credentials for CI\n\ncaipe kb user info\ncaipe kb datasources list\ncaipe kb documents list <datasource-id> --limit 50\ncaipe kb query --query \"how do I deploy SSE?\"\ncaipe kb chunk get '<chunk-id>'\n\ncaipe kb ingest url --url https://docs.example.com/\ncaipe kb ingest file ./README.md ./guide.pdf --owner-team-slug my-team\ncaipe kb job get <job-id>\n```\n\nShared flags on `caipe kb`: `--kb-url`, `--token`, `--tenant-id` (or `CAIPE_TENANT_ID`).\n\n---\n\n## Configuration reference\n\n| Key | Description |\n|-----|-------------|\n| `server.url` | CAIPE UI / BFF HTTPS base URL |\n| `auth.url` | OAuth and discovery base (Keycloak realm URL or UI URL) |\n| `agent.default` | Default dynamic agent id for `caipe chat` when `--agent` is omitted |\n| `auth.idp-hint` | Skip Keycloak login chooser (`kc_idp_hint`) |\n| `kb.url` | Knowledge Base RAG REST API base URL |\n| `updates.mode` | Daily CLI update behavior: `auto` (default), `notify`, or `off` |\n| `auth.apiKey` | Static API key (headless alternative) |\n| `auth.credential-storage` | `encrypted-file` (default) or `keychain` |\n\n**Rich terminal output (interactive chat):** Markdown is rendered with **react-markdown** + **remark-gfm** as native Ink components (no ANSI markdown strings). Diffs use Ink colors. Block streaming caches completed sections in `<Static>`; the active tail updates in place. Tool runs show in the footer. Chat uses the **alternate screen** unless `CAIPE_NO_ALT_SCREEN=1` or `CAIPE_PLAIN_TERMINAL=1`. Legacy plain streaming: `CAIPE_STREAM_PLAIN=1`.\n\n**Default credentials:** encrypted file at `~/.config/caipe/credentials.enc` (AES-256-GCM, machine-derived key). No Keychain prompts unless you opt into `keychain`.\n\n---\n\n## Command reference\n\n| Command | Description |\n|---------|-------------|\n| `caipe` / `caipe chat` | Interactive REPL |\n| `caipe acp [--agent <id>]` | ACP v1 agent bridge over stdio for compatible editors |\n| `caipe auth login\\|logout\\|status` | OAuth session |\n| `caipe config set\\|get\\|unset\\|discover` | Settings (`discover` sets `auth.url` via well-known URLs or deployment hostname heuristics) |\n| `caipe agents list\\|info` | Server agents |\n| `caipe kb …` | KB query, read chunks, ingest, jobs, RBAC (`user info`) — JSON only |\n| `caipe skills list\\|install\\|preview\\|update` | Skill catalog |\n| `caipe update [--check]` | Check for or install a verified CLI release |\n| `caipe memory` | Project memory files |\n| `caipe commit` | DCO-aware commit helper |\n\nGlobal flags: `--agent`, `--url`, `--json`, `--no-color`, `-v` / `--version`.\n\n---\n\n## Project layout\n\n```\ncaipe-cli/\n  src/           TypeScript source\n  bin/caipe.cjs  npm/npx launcher\n  dist/          compile output (gitignored)\n  tests/         Vitest\n  setup-caipe-cli.sh\n  install.sh\n```\n\n---\n\n## Troubleshooting\n\n### `Invalid client_type: \"cli\"`\n\nOlder BFFs only allow `webui`, `slack`, and `webex`. The CLI tries **`slack` first**, then `cli`, when creating conversations. Rebuild from latest `main` if you still see a `cli`-only error.\n\n### OAuth 404 on `/oauth/authorize`\n\nSet **`server.url`** to the UI/BFF, then run **`caipe config discover`**.\nDiscovery tries, in order: `/.well-known/agent.json`, OIDC metadata on the BFF\nhost, then deployment-specific hostname heuristics. Override the realm with\n**`CAIPE_AUTH_REALM`**. You can still set **`auth.url`** manually (for example,\n`https://idp.caipe.example.com/realms/caipe`).\n\n---\n\n## License\n\nApache-2.0\n","readmeFilename":"README.md"}