Skip to main content
Commands for managing third-party integrations: credentials, connections, sources, syncs, listeners and connected accounts. For a walkthrough, see Connecting and syncing.

Syntax

Deployment selection

Every subcommand acts on your dev deployment by default and accepts:

Subcommands

Credentials

Credential values are read from piped stdin or from --from-file, never from an argument or an interactive terminal. Input is limited to 8 KiB of valid UTF-8 and must arrive within 30 seconds. All bytes are preserved, including a terminal newline: use printf instead of echo when no newline is intended. Values are never printed.

credential-create

Create a private integration credential.

credential-rotate

Rotate an existing private integration credential. Takes the same arguments as credential-create.

credential-status

Inspect private credential metadata.

Connections

configure

Configure an admitted integration connection.
Which setup values a provider needs is declared on its integration definition. Secrets are never supplied this way: create one with credential-create and name it as --credential-ref.

identify

Admit identity verification work. Run it afterwards with run.

install

Install a verified collection source. Prints the source ID.

role-bind

Bind one credential role of a configured connection, for a definition whose HTTP contracts dispatch under named credential roles. The credential envelope is read from piped stdin or --from-file, with the same limits as credential-create. A role belongs to the connection’s authorizing account. Activate the connection afterwards with activate.

activate

Activate a configured connection once it holds every credential role its definition names.

Work

Identity checks and syncs are durable work identified by a request ID.

capture

Admit a source acquisition under a request ID of your choice.

run

Run or resume admitted acquisition work.

cancel

Cancel pending acquisition work.

status

Inspect historical work and publication status.

Sources

sources

List installed sources, their connection and acquisition health.

source-status

Inspect a source’s schedule, state, sync history, last connection check and retained work.

refresh

Request a current-state refresh: the CLI’s Sync now. A request made while one is outstanding joins it.

resume

Wake an exact blocked or retrying acquisition.

cancel-source

Cancel the current source occurrence. Future syncs stay scheduled.

refresh-repair

Repair a blocked refresh with currently deployed code.

Native sources

postgres-control

PostgreSQL change data capture is in beta.
Stop PostgreSQL acquisition or request a qualified new baseline. See PostgreSQL.

mail-repair

Mail integrations are in beta.
Retry mail gaps without creating new arrival occurrences. See Mail.

Listeners

Listeners are in beta.

listener-configure

Configure automatic refresh from provider notifications. See Listeners and webhooks.

listener-status

Inspect notification health and refresh responsibility.

Webhook events

Webhook events are in beta.

webhook-configure

Bind an occurrence listener to one operation.

webhook-status

Inspect occurrence custody and retained identity capacity.

webhook-event

Inspect one retained occurrence.

webhook-control

Hold, retry, discard, expand capacity, retire or reinstate a feed.

Commands

Inspect and recover integration commands your operations submitted as external calls. See Operations.

command-status

Inspect a command’s outcome, the destination’s own name for a refusal, recovery bounds and required evidence.

command-recover

Recover an existing command from retained evidence or a bounded read.
Recovery preserves the accepted identity and budgets. It does not submit a new write or treat matching current state as proof of delivery.

Connected accounts

Connected accounts are in beta.
These commands act for an application user, named with --as. Except for account-callback, they also name the integration with --module and --export, and accept --component <path>, which defaults to root.

account-authorize

Connect a provider account for an application user. The provider grants what it chooses, which may be less than was asked. A single-use authorization code is never printed or stored.

account-callback

Complete an authorization started by account-authorize.

account-resources

List what an account offers to read.

account-select

Install the resources an account may read. The selection is the complete set for this account: a resource left out of a later selection is no longer acquired.

account-status

Inspect account state, capabilities and sources.

account-pause

Stop acquisition without surrendering authority.

account-resume

Recreate acquisition for a paused account.

account-disconnect

Revoke an account’s authority and stop its acquisition. Disconnection is terminal for this account: reconnecting completes a new authorization and does not revive this one. Acquired records are kept.

account-erase

Erase an account’s sources and everything acquired through them. Erasure is permanent and removes acquired records. It does not undo effects already delivered to the provider.