@acfstandards/cli
v1.0.2
Published
ACF Agent Certification CLI — run behavioral certification for your AI agent from the terminal
Readme
@acfstandards/cli
Run ACF behavioral certification for your AI agent from the terminal.
ACF (Agent Certification Framework) tests AI agents against defined behavioral standards and issues tiered certifications. This CLI triggers the certification process using a code obtained after registration and payment on the ACF portal.
All tests run server-side — prompts and rubrics never leave the ACF platform.
Certifying an agent that is not already an HTTPS endpoint — a Claude Managed Agent, an OpenAI agent, or anything on a private network — needs
@acfstandards/agent-bridgein front of it. Connect your agents to ACF is the end-to-end path covering both packages.
Install
npm install -g @acfstandards/cliOr run directly with npx:
npx @acfstandards/cli --code acf_abc123 --endpoint https://my-agent.com/chatPrerequisites
- Register your agent at acfstandards.org
- Select a tier and complete payment
- Copy your certification code (
acf_...) from the portal
Your agent must expose an HTTP endpoint that accepts POST requests with an OpenAI-compatible messages format:
{
"messages": [
{ "role": "user", "content": "..." }
]
}CLI Usage
Basic
acf-certify --code acf_abc123 --endpoint https://my-agent.com/chatWith Bearer Token Auth
acf-certify \
--code acf_abc123 \
--endpoint https://my-agent.com/chat \
--auth-method bearer \
--auth-secret sk-my-tokenWith API Key Auth
acf-certify \
--code acf_abc123 \
--endpoint https://my-agent.com/chat \
--auth-method api_key \
--auth-header X-API-Key \
--auth-secret my-keyWith Anthropic Request Format
acf-certify \
--code acf_abc123 \
--endpoint https://my-agent.com/chat \
--format anthropicAll Options
| Option | Required | Default | Description |
|--------|----------|---------|-------------|
| --code | Yes | — | Certification code from ACF portal |
| --endpoint | Yes | — | Agent HTTP endpoint URL |
| --auth-method | No | none | bearer, api_key, or none |
| --auth-secret | No* | — | Auth token or API key (*required if method ≠ none) |
| --auth-header | No | X-API-Key (api_key) / Authorization (bearer) | Custom header name for the secret |
| --format | No | openai | Request format: openai, anthropic, custom |
| --base-url | No | https://acfstandards.org | API base URL |
| --skip-preflight | No | false | Skip agent connectivity check |
Fleet certification (acf-certify fleet)
Added in 1.0.2. Certify every agent behind an ACF bridge in one command, instead of registering each one through the browser wizard.
export ACF_API_KEY=acf_live_... # Portal -> Settings -> API Keys (read-write)
acf-certify fleet \
--config ./agents.json \
--bridge-url https://bridge.acme.com \
--tier tier2The command reads the bridge's own agents.json, so there is no second inventory to maintain: each route's slug becomes https://<bridge-url>/agent/<slug> and its token becomes the bearer secret. Run bridge gen first if any token is still a placeholder.
Add --dry-run to validate the config and print the fleet without registering anything.
Fleet options
| Option | Required | Default | Description |
|--------|----------|---------|-------------|
| --config | Yes | — | Path to the bridge's agents.json |
| --bridge-url | Yes | — | Public HTTPS base URL of your deployed bridge |
| --tier | Yes | — | tier1, tier2, tier3 or tier4 |
| --payment-intent | No | billing_bypassed | Stripe PaymentIntent covering the fleet |
| --discount-code | No | — | Discount code, when billing is bypassed by code |
| --api-key | No | $ACF_API_KEY | Operator API key — needs read-write scope |
| --base-url | No | https://acfstandards.org | API base URL |
| --poll-interval | No | 15000 | Milliseconds between status polls |
| --dry-run | No | false | Validate and print, register nothing |
Paying for a fleet
One PaymentIntent can fund many certifications when its metadata carries certCount; the server verifies that the amount received covers certCount x tier price. Operators on the exempt list or holding a 100% discount code pass --payment-intent billing_bypassed.
Output
Fleet Summary
─────────────────────────────────────────────
✓ billing-agent PASS
✗ support-agent FAIL
• research-agent INCOMPLETE (testing)
─────────────────────────────────────────────
1 passed · 1 failed · 1 incomplete · 0 rejectedExit code is 0 only when every agent passed. Scores are never printed — ACF reports suite-level PASS/FAIL only.
Interrupted? Re-run the same command: certifications continue server-side and the summary reattaches to them.
Programmatic API
import { certify } from '@acfstandards/cli';
const result = await certify({
code: 'acf_abc123',
endpoint: 'https://my-agent.com/chat',
authMethod: 'bearer',
authSecret: 'sk-my-token',
onProgress: (progress) => {
console.log(`${progress.percent}% — ${progress.message}`);
},
});
if (result.passed) {
console.log('Certificate:', result.certificateUrl);
console.log('Registry:', result.registryUrl);
} else {
console.log('Failed suites:', result.suiteResults);
if (result.reportPath) {
console.log('Report saved:', result.reportPath);
}
}certify(options) Options
| Property | Type | Required | Default | Description |
|----------|------|----------|---------|-------------|
| code | string | Yes | — | Certification code |
| endpoint | string | Yes | — | Agent endpoint URL |
| authMethod | "bearer" \| "api_key" \| "none" | No | "none" | Auth method |
| authSecret | string | No | — | Auth token/key |
| authHeader | string | No | "X-API-Key" (api_key) / "Authorization" (bearer) | Custom auth header |
| requestFormat | "openai" \| "anthropic" \| "custom" | No | "openai" | Request format |
| baseUrl | string | No | "https://acfstandards.org" | API base URL |
| maxWaitMs | number | No | 4× the server estimate (30 min–4 h) | Overall polling budget before giving up |
| pollInterval | number | No | 5000 | Polling interval (ms) |
| onProgress | function | No | — | Progress callback |
CertifyResult
| Property | Type | Description |
|----------|------|-------------|
| passed | boolean | Whether the agent passed |
| status | string | Final status |
| suiteResults | Record<string, string> | Per-suite PASS/FAIL |
| certificateUrl | string \| null | PDF certificate URL (pass only) |
| registryUrl | string \| null | Registry listing URL (pass only) |
| failureReport | object \| null | Structured failure details (fail only) |
| failureReportUrl | string \| null | PDF failure report URL (fail only) |
| reportPath | string | Local markdown report path (fail only) |
Certification Tiers
| Tier | Label | Suites Tested | |------|-------|---------------| | T1 | Identity | CB + CS | | T2 | Behavioral | CB + CS + HD | | T3 | Compliance | CB + CS + HD + AR | | T4 | Enterprise Audit | All suites + full audit |
How It Works
- You register and pay on acfstandards.org
- You receive a one-time certification code (
acf_...) - The CLI sends your agent endpoint + auth to the ACF server
- ACF runs all behavioral tests server-side (prompts/rubrics stay private)
- The CLI polls for progress and displays results
- On pass: certificate PDF + public registry listing
- On fail: detailed failure report with remediation guidance
Requirements
- Node.js >= 18
- Agent must accept HTTP POST with JSON body
- Agent must respond within 30 seconds per request
License
MIT — Blue Horn Ventures LLC
