Commands for managing third-party integrations: credentials, connections,
sources, syncs, listeners and connected accounts.
For a walkthrough, see Connecting and syncing.
Syntax
Deployment selection
Every subcommand acts on your dev deployment by default and accepts:
Subcommands
Credentials
Credential values are read from piped stdin or from --from-file, never from
an argument or an interactive terminal. Input is limited to 8 KiB of valid
UTF-8 and must arrive within 30 seconds. All bytes are preserved, including a
terminal newline: use printf instead of echo when no newline is intended.
Values are never printed.
credential-create
Create a private integration credential.
credential-rotate
Rotate an existing private integration credential. Takes the same arguments as
credential-create.
credential-status
Inspect private credential metadata.
Connections
Configure an admitted integration connection.
Which setup values a provider needs is declared on its integration definition.
Secrets are never supplied this way: create one with credential-create and
name it as --credential-ref.
identify
Admit identity verification work. Run it afterwards with run.
install
Install a verified collection source. Prints the source ID.
role-bind
Bind one credential role of a configured connection, for a definition whose
HTTP contracts dispatch under named credential roles. The credential envelope
is read from piped stdin or --from-file, with the same limits as
credential-create. A role belongs to the connection’s authorizing account.
Activate the connection afterwards with activate.
activate
Activate a configured connection once it holds every credential role its
definition names.
Work
Identity checks and syncs are durable work identified by a request ID.
capture
Admit a source acquisition under a request ID of your choice.
run
Run or resume admitted acquisition work.
cancel
Cancel pending acquisition work.
status
Inspect historical work and publication status.
Sources
sources
List installed sources, their connection and acquisition health.
source-status
Inspect a source’s schedule, state, sync history, last connection check and
retained work.
refresh
Request a current-state refresh: the CLI’s Sync now. A request made while
one is outstanding joins it.
resume
Wake an exact blocked or retrying acquisition.
cancel-source
Cancel the current source occurrence. Future syncs stay scheduled.
refresh-repair
Repair a blocked refresh with currently deployed code.
Native sources
postgres-control
PostgreSQL change data capture is in beta.
Stop PostgreSQL acquisition or request a qualified new baseline. See
PostgreSQL.
mail-repair
Mail integrations are in beta.
Retry mail gaps without creating new arrival occurrences. See
Mail.
Listeners
Configure automatic refresh from provider notifications. See
Listeners and webhooks.
listener-status
Inspect notification health and refresh responsibility.
Webhook events
Webhook events are in beta.
Bind an occurrence listener to one operation.
webhook-status
Inspect occurrence custody and retained identity capacity.
webhook-event
Inspect one retained occurrence.
webhook-control
Hold, retry, discard, expand capacity, retire or reinstate a feed.
Commands
Inspect and recover integration commands your operations submitted as
external calls. See Operations.
command-status
Inspect a command’s outcome, the destination’s own name for a refusal,
recovery bounds and required evidence.
command-recover
Recover an existing command from retained evidence or a bounded read.
Recovery preserves the accepted identity and budgets. It does not submit a new
write or treat matching current state as proof of delivery.
Connected accounts
Connected accounts are in beta.
These commands act for an application user, named with --as. Except for
account-callback, they also name the integration with --module and
--export, and accept --component <path>, which defaults to root.
account-authorize
Connect a provider account for an application user. The provider grants what
it chooses, which may be less than was asked. A single-use authorization code
is never printed or stored.
account-callback
Complete an authorization started by account-authorize.
account-resources
List what an account offers to read.
account-select
Install the resources an account may read. The selection is the complete set
for this account: a resource left out of a later selection is no longer
acquired.
account-status
Inspect account state, capabilities and sources.
account-pause
Stop acquisition without surrendering authority.
account-resume
Recreate acquisition for a paused account.
account-disconnect
Revoke an account’s authority and stop its acquisition. Disconnection is
terminal for this account: reconnecting completes a new authorization and does
not revive this one. Acquired records are kept.
account-erase
Erase an account’s sources and everything acquired through them. Erasure is
permanent and removes acquired records. It does not undo effects already
delivered to the provider.