@odyshell/cli
v0.19.0
Published
Install and operate an Odyshell Client on Linux, macOS, or Windows.
Maintainers
Readme
ods is the Machine-side administration tool. Agents do not run it: they connect to the
Odyshell Server through remote OAuth MCP or the canonical HTTP Session/Command protocol.
Install
Requires Linux and Node.js 24 or newer:
npm install --global @odyshell/cliConnect a Machine
Open Machines, select Add Machine, and run the generated command on the target Windows, Linux, or macOS host:
ods --server https://api.example.com up \
--token <single-use-token> \
--name production-apiods up creates an Ed25519 Machine identity, saves a conservative Local Policy, verifies the
Server, and installs a restartable systemd user service. The token expires after ten minutes,
works once, and is never persisted.
The Local Policy permits one Session and Command at a time, a one-hour Session, a ten-minute Command, and 1 MiB of output. It permits remote human approval but does not configure sudo or a sandbox.
Local lifecycle
ods status
ods profiles ls
ods profiles status default
ods client status --profile default
ods client doctor --profile default
ods client update --check --profile default
ods down --profile default
ods up --profile defaultUse another Profile name when one host connects to another Server or customer Organization.
Profiles keep independent Machine keys, policies, state directories, and systemd services.
--profile and --config cannot be combined.
Remove one local identity or all of them:
ods profiles remove default
ods reset --yesMachine records remain in the dashboard for audit. --json provides stable output for local
automation.
Security boundary
Commands execute as the Linux user running the Client. Use a dedicated user with no root, sudo, or Docker membership and grant only the files, credentials, network, and services the Agent needs. The Client enforces Organization, Session identity, duration, concurrency, timeout, and output limits locally. Agents receive temporary Machine authority only through authorized Sessions.
ods deliberately has no login, Agent, Session, Command, shell, filesystem, Docker, Session, or MCP
runtime commands. Keeping remote authorization in the Server prevents a second policy path from
appearing on every Machine.
For monorepo development:
pnpm install:ods