CLI reference

Run any command with --help for complete options:

oci workflow run --help

Local commands take --dir DIR, the directory that holds the workflow (default: the current directory), and --config FILE, the workflow file relative to it (default: outcome.yml). Cloud commands take --workspace-id ID, the identifier of your OutcomeCI Cloud workspace.

Write and check a workflow

Command Purpose
oci init Write a starter workflow, its step instructions, and a sample request
oci validate Compile the workflow and print its revision
oci workflow compile Print the compiled workflow: steps, grants, instructions, and schemas

oci init writes an outcomeci.workflow/v1 workflow and never replaces a file that exists. oci workflow compile --step NAME prints only one step's instructions.

Run a workflow

oci workflow run runs the workflow in --dir inside the runner container. By default its secrets come from the local Vault and its agent login from this machine. See Run in the container.

Option Effect
--trigger NAME The trigger to run; defaults to the only trigger, or the manual one
--payload FILE Use a JSON file as the trigger payload
--auto-continue Run every step, including real side effects later steps make
--agent, --model Run every step with codex, claude, or opencode, and this model
--retry RUN_ID Resume a run in --dir that stopped on an error
--cloud Use the cloud workflow's Vault grants and the workspace's connected agent
--workspace-id ID The workspace of the --cloud workflow
--workflow-id ID The cloud workflow whose Vault grants --cloud uses
--image IMAGE Runner image (default: ghcr.io/outcomeci/outcome-runner at the CLI version)
--network NETWORK Docker network for the container, such as host

--cloud needs --workspace-id and --workflow-id, and those two need --cloud. --agent opencode needs an OpenRouter model, such as --model openrouter/<provider>/<model>.

OutcomeCI Cloud

Command Purpose
oci auth login Sign in with device login
oci auth login --key-stdin Store a workspace API key read from stdin
oci auth status Show the signed-in account
oci auth logout Remove stored credentials
oci workflow sync FILE --workspace-id ID --create Upload the workflow and its .outcomeci/ files as a new workflow
oci workflow sync FILE --workspace-id ID --version Add a version to the existing workflow with this name
oci workflow get WORKFLOW_ID --workspace-id ID Print the latest cloud revision, or write it with --output
oci workflow prepare-publication FILE --output DIR Create and verify a sanitized package for public reuse

Credentials are stored in ~/.config/outcomeci/credentials.json, or under OUTCOMECI_CONFIG_HOME when it is set. oci auth login --api-url URL targets another OutcomeCI API, and --no-open prints the sign-in link instead of opening a browser.

oci workflow sync compiles the workflow locally before uploading it, and --name sets the display name. oci workflow prepare-publication takes --agent, --model, and a repeatable --sensitive-term; see Share a workflow.

Vault

Command Purpose
oci vault list --workspace-id ID List Vault entries, without values
oci vault put PATH --workspace-id ID --value-stdin Store a credential at a path
oci vault rotate ENTRY_ID --workspace-id ID --value-stdin Replace an entry's value
oci vault grant ENTRY_ID --workspace-id ID --workflow-id WORKFLOW_ID Set which workflows may use an entry
oci vault revoke ENTRY_ID --workspace-id ID Revoke an entry
oci vault local init Create this checkout's encrypted local Vault
oci vault local put PATH --value-stdin Store a credential in the local Vault
oci vault local list List local Vault entries, without values

A workflow references an entry as vault:PATH. Entries under agents/claude and agents/opencode in the local Vault hold agent logins for oci workflow run. oci vault put takes --workflow-id (repeatable) to grant the entry while storing it.

Both put commands store typed credentials with the same options:

Option Used for
--credential-type TYPE api_key, auth_header, basic, oauth2, oidc, jwt_bearer, or app_installation
--provider NAME The service, such as slack; oci vault put requires it with --credential-type
--value-stdin A type's single secret field
--secrets-json-stdin Several secret fields as one JSON object
--secret-name FIELD The field --value-stdin fills, when it is not inferred
--header-name, --prefix, --scheme api_key and auth_header
--client-id, --grant-type, --scope, --audience, --token-url, --account-id oauth2
--client-id, --issuer-url, --scope, --audience oidc
--issuer, --subject, --token-url, --audience, --scope jwt_bearer
--app-id, --installation-id app_installation

See Vault for what each type stores and how a connector uses it.

Slack app

Command Purpose
oci integration slack setup Create and install a Slack app with the Slack CLI
oci integration slack status Check the Slack app and Slack CLI
oci integration slack manifest Print the generated Slack app manifest
oci integration slack sync-credentials --local Copy the installed app's bot token into the local Vault
oci integration slack sync-credentials --cloud --workspace-id ID Copy the installed app's bot token into a workspace's Vault

The Slack app backs a workflow's Slack trigger and the Slack connector. Setup takes two passes, because Slack verifies the request URL when the manifest is applied and the webhook answers only once the app's signing secret is in the Vault:

oci integration slack setup --name "Acme Outcomes"
# store the app's signing secret in the Vault, then:
oci integration slack setup --name "Acme Outcomes" \
  --request-url https://<your workflow webhook URL> --event mention --event dm

--event accepts mention and dm and defaults to both. --team selects one Slack workspace when the app is installed in several. sync-credentials stores the token at slack/bot-token unless you pass --path; with --cloud, --workflow-id WORKFLOW_ID also grants it to a workflow.

Compilation failures

oci validate, oci workflow compile, oci workflow run, and oci workflow sync compile the workflow first and fail before any agent starts when a step reads an unknown step or output, a grant names an operation its connector does not have, an auth names an undeclared secret, or a reason file is missing from .outcomeci/instructions/.