CLI reference
Run any command with --help for complete options:
oci workflow run --helpLocal commands take --dir DIR, the directory that holds the workflow
(default: the current directory), and --config FILE, the workflow file
relative to it (default: outcome.yml). Cloud commands take
--workspace-id ID, the identifier of your OutcomeCI Cloud workspace.
Write and check a workflow
| Command | Purpose |
|---|---|
oci init |
Write a starter workflow, its step instructions, and a sample request |
oci validate |
Compile the workflow and print its revision |
oci workflow compile |
Print the compiled workflow: steps, grants, instructions, and schemas |
oci init writes an outcomeci.workflow/v1 workflow and never replaces a
file that exists. oci workflow compile --step NAME prints only one step's
instructions.
Run a workflow
oci workflow run runs the workflow in --dir inside the runner container.
By default its secrets come from the local Vault and its agent login from
this machine. See Run in the container.
| Option | Effect |
|---|---|
--trigger NAME |
The trigger to run; defaults to the only trigger, or the manual one |
--payload FILE |
Use a JSON file as the trigger payload |
--auto-continue |
Run every step, including real side effects later steps make |
--agent, --model |
Run every step with codex, claude, or opencode, and this model |
--retry RUN_ID |
Resume a run in --dir that stopped on an error |
--cloud |
Use the cloud workflow's Vault grants and the workspace's connected agent |
--workspace-id ID |
The workspace of the --cloud workflow |
--workflow-id ID |
The cloud workflow whose Vault grants --cloud uses |
--image IMAGE |
Runner image (default: ghcr.io/outcomeci/outcome-runner at the CLI version) |
--network NETWORK |
Docker network for the container, such as host |
--cloud needs --workspace-id and --workflow-id, and those two need --cloud. --agent opencode needs an OpenRouter model, such as
--model openrouter/<provider>/<model>.
OutcomeCI Cloud
| Command | Purpose |
|---|---|
oci auth login |
Sign in with device login |
oci auth login --key-stdin |
Store a workspace API key read from stdin |
oci auth status |
Show the signed-in account |
oci auth logout |
Remove stored credentials |
oci workflow sync FILE --workspace-id ID --create |
Upload the workflow and its .outcomeci/ files as a new workflow |
oci workflow sync FILE --workspace-id ID --version |
Add a version to the existing workflow with this name |
oci workflow get WORKFLOW_ID --workspace-id ID |
Print the latest cloud revision, or write it with --output |
oci workflow prepare-publication FILE --output DIR |
Create and verify a sanitized package for public reuse |
Credentials are stored in ~/.config/outcomeci/credentials.json, or under
OUTCOMECI_CONFIG_HOME when it is set. oci auth login --api-url URL targets
another OutcomeCI API, and --no-open prints the sign-in link instead of
opening a browser.
oci workflow sync compiles the workflow locally before uploading it, and
--name sets the display name. oci workflow prepare-publication takes
--agent, --model, and a repeatable --sensitive-term; see
Share a workflow.
Vault
| Command | Purpose |
|---|---|
oci vault list --workspace-id ID |
List Vault entries, without values |
oci vault put PATH --workspace-id ID --value-stdin |
Store a credential at a path |
oci vault rotate ENTRY_ID --workspace-id ID --value-stdin |
Replace an entry's value |
oci vault grant ENTRY_ID --workspace-id ID --workflow-id WORKFLOW_ID |
Set which workflows may use an entry |
oci vault revoke ENTRY_ID --workspace-id ID |
Revoke an entry |
oci vault local init |
Create this checkout's encrypted local Vault |
oci vault local put PATH --value-stdin |
Store a credential in the local Vault |
oci vault local list |
List local Vault entries, without values |
A workflow references an entry as vault:PATH. Entries under agents/claude
and agents/opencode in the local Vault hold agent logins for
oci workflow run. oci vault put takes --workflow-id (repeatable) to grant
the entry while storing it.
Both put commands store typed credentials with the same options:
| Option | Used for |
|---|---|
--credential-type TYPE |
api_key, auth_header, basic, oauth2, oidc, jwt_bearer, or app_installation |
--provider NAME |
The service, such as slack; oci vault put requires it with --credential-type |
--value-stdin |
A type's single secret field |
--secrets-json-stdin |
Several secret fields as one JSON object |
--secret-name FIELD |
The field --value-stdin fills, when it is not inferred |
--header-name, --prefix, --scheme |
api_key and auth_header |
--client-id, --grant-type, --scope, --audience, --token-url, --account-id |
oauth2 |
--client-id, --issuer-url, --scope, --audience |
oidc |
--issuer, --subject, --token-url, --audience, --scope |
jwt_bearer |
--app-id, --installation-id |
app_installation |
See Vault for what each type stores and how a connector uses it.
Slack app
| Command | Purpose |
|---|---|
oci integration slack setup |
Create and install a Slack app with the Slack CLI |
oci integration slack status |
Check the Slack app and Slack CLI |
oci integration slack manifest |
Print the generated Slack app manifest |
oci integration slack sync-credentials --local |
Copy the installed app's bot token into the local Vault |
oci integration slack sync-credentials --cloud --workspace-id ID |
Copy the installed app's bot token into a workspace's Vault |
The Slack app backs a workflow's Slack trigger and the Slack connector. Setup takes two passes, because Slack verifies the request URL when the manifest is applied and the webhook answers only once the app's signing secret is in the Vault:
oci integration slack setup --name "Acme Outcomes"
# store the app's signing secret in the Vault, then:
oci integration slack setup --name "Acme Outcomes" \
--request-url https://<your workflow webhook URL> --event mention --event dm--event accepts mention and dm and defaults to both. --team selects one
Slack workspace when the app is installed in several. sync-credentials stores
the token at slack/bot-token unless you pass --path; with --cloud,
--workflow-id WORKFLOW_ID also grants it to a workflow.
Compilation failures
oci validate, oci workflow compile, oci workflow run, and
oci workflow sync compile the workflow first and fail before any agent
starts when a step reads an unknown step or output, a grant names an
operation its connector does not have, an auth names an undeclared secret,
or a reason file is missing from .outcomeci/instructions/.