OAuth account commands
Interactiverelai setup uses OAuth device authorization. It prints the dashboard device
URL and short code, then opens the complete verification link
in the system browser when possible. If opening fails, use the printed URL and
code manually. It also makes a best-effort local clipboard copy of the short
code without storing it. It is suitable for SSH, containers, and browserless
environments; approve the printed link from another machine when needed.
auth status confirms the active account and workspace;
auth login runs the same browser-opening device flow directly. Run it again
to reauthenticate or select a different server-bound workspace.
~/.relai/credentials.json, never in ~/.relai/config.toml or CLI logs.
RELAI restricts the file to the current user (mode 0600 on Unix and a
user-only access control list on Windows) and writes replacements atomically.
Anyone who can read files as your user can read these tokens, so protect your
user account and home directory and never share or commit this file.
Versions that previously used Keychain, Credential Manager, or Secret Service
do not copy credentials from those stores. After upgrading, run
relai auth login once to sign in and create ~/.relai/credentials.json.
relai --version
Print the installed CLI version and embedded build identity.
relai setup
Configure machine-level preferences and sign in with OAuth device authorization.
relai setup --check audits Harbor prerequisites. Missing tools do not prevent setup from saving CLI preferences.
~/.relai/config.toml, plaintext OAuth tokens to
the user-only ~/.relai/credentials.json, and selected local plugin packages.
Keep both configuration and credential files private and do not commit them.
Interactive setup always offers Codex and Claude Code, and offers Cursor or
GitHub Copilot when its executable or conventional host directory is detected.
A noninteractive caller can select any host directly with --agent; omitting
it leaves host plugin settings unchanged.
See User configuration for editable settings and global
permissions.
Setup also materializes [permissions] profile = "auto" when no global permissions profile exists. An explicit existing profile and any global read/write rules are preserved. See Permissions for profiles and path rules.
Common failures: the verification link cannot open (use the printed link and
code manually), permission issues writing ~/.relai/credentials.json, missing
required tools, or permission issues writing home-directory config. Run relai setup --check
to identify missing Harbor tools; start Docker before initializing or running a
simulation.
relai update
Update the installed CLI to the latest release.
--force to reinstall even when the current version already matches the latest release.
Common failures: unsupported platform, missing release artifact, network failure, checksum failure, or permission issues replacing the binary.
relai uninstall
Uninstall previews its complete removal scope and asks for confirmation; use
--dry-run for the same preview without changing anything. For Cursor and
GitHub Copilot, it removes only the marked RELAI-owned
~/.cursor/plugins/local/relai directory and marked
~/.copilot/skills/<skill> directories. Unmarked or unrelated directories and
the parent .cursor and .copilot host directories are preserved.
relai plugins install
Install or refresh local RELAI guidance and configure coding-agent hosts without requiring their executables or authentication.
See Supported interfaces for host-specific
package layouts and interaction limitations.
Codex and Claude Code packages are replaced completely under
~/.relai/plugins/ and their host configuration is updated directly. Cursor receives a portable Agent Plugin at ~/.cursor/plugins/local/relai; GitHub Copilot receives one directory per skill under ~/.copilot/skills/. The default --agent all installs all four packages; neither executable nor an authenticated host session is required. Existing Codex installations get an optional host CLI refresh; older RELAI cache versions are removed only after the replacement is verified. Failed or unavailable refreshes retain the old cache and report activation as unverified. See Plugin updates. Restart or reload the selected host, then verify the RELAI skills.