castarcade
v0.3.1
Published
Create, check, preview and submit Cast Arcade browser games from your terminal.
Readme
castarcade 0.3.1
The Cast Arcade command line for self-contained browser games. Node 22 or newer. Nothing to download: npx fetches the current release the first time you run it.
npx castarcade init my-game --template shared-screen
npx castarcade dev my-game
npx castarcade check my-game --json
npx castarcade pack my-game --out my-game.bundle.json
npx castarcade submit my-game --jsonPin it in a project with npm install --save-dev castarcade, or install it once with npm install -g castarcade. The libraries it uses are @castarcade/sdk, @castarcade/game-runtime and @castarcade/game-contract. All four are source-available under the Cast Arcade Developer Tools License in LICENSE.md.
solo and shared-screen starters are playable Pulse Sprint timing games. For agents and CI, set starter metadata explicitly with --name, --mode, --min-players, and --max-players. Without those flags, a terminal asks one short question at a time; a non-interactive command uses the directory name and safe template defaults. The shared-screen starter declares schema v2 room support for two to four players using Cast Arcade phones or local keyboard, touch, and browser gamepads. Both starters include the vendored SDK, metadata, instructions, and a complete AGENTS.md adaptation brief. Review the title, descriptions, artwork, category, tags, and access choice in the Store listing after the first submission.
Bring an already-built export with castarcade import ./export. This preserves the real entrypoint and writes only castarcade.json plus CASTARCADE-INTEGRATION.md. It refuses to overwrite existing integration files. Import does not complete SDK integration: adapt real gameplay lifecycle/input/result handling before submission. The CLI never shell-executes build scripts. Work from your exported assets directory, with castarcade.json at its root and a relative HTML entry.
check and pack use the installed shared contract's exact policy. Files are read with no-follow protection; symlinks, source/config files, unsupported paths/MIME extensions, size/count violations and invalid metadata are rejected. Git, node_modules, hidden files, root metadata, generated guidance and *.bundle.json outputs are excluded. Pack refuses to overwrite an existing output. Keep bundles outside the export or name them *.bundle.json. Limits are 256 files, 8 MiB/file, 16 MiB decoded total, 24 MiB serialized. policy --json prints versioned limits, types and manual checks.
dev [dir] [--port 4174] binds only 127.0.0.1, serves a validated snapshot and a trusted shell, and uses the same artifact CSP/CORS/cache builder as hosted releases. Restart after changing files. Its shell has a separate frame-src restricted to that snapshot's artifact namespace. No credentials are exposed or browser silently opened.
Create a publisher profile and a scoped developer token in your platform's /developers page. login --token-stdin --api https://your-platform.example reads a token from standard input, verifies /me, and saves owner-only credentials keyed by API origin. --token VALUE also works but may enter shell history/process listings. Environment variables CASTARCADE_TOKEN and CASTARCADE_API_URL override saved configuration. CASTARCADE_CONFIG_DIR overrides the default ~/.config/castarcade directory for local tooling/tests. HTTPS is required except explicit localhost, 127.0.0.1 or [::1] development origins. Redirects are never followed with authorization. logout --api ORIGIN removes only that origin's saved token; also unset environment tokens yourself.
castarcade submit my-game --json
castarcade status BUILD_ID --json
# After manual review approval; this explicitly changes the public release:
castarcade release GAME_ID APPROVED_BUILD_ID --jsonsubmit validates, packages, stores, and sends the version for review. It requests a time-limited exact preview URL and returns the version ID (buildId in API v1) plus the exact project and status links. The older publish command remains an alias for existing scripts. Neither command activates a public release; release is a separate, explicit command after approval. If storage succeeds but submission or preview fails, the command exits nonzero while preserving the version ID and a recovery action. A locked version is the exact code and game assets reviewers test; changes require a new semantic version. Retry later steps with that existing version in the partner portal. Use read/upload/submit token scopes; public release additionally requires publish.
Every command supports --json: exactly one JSON result on stdout and nonzero exit on failure, with tokens redacted even from API error bodies. Human mode prints diagnostics/links. Validation never authorizes release and does not claim runtime/content checks were performed. Released schema v2 shared-display games can use Cast Arcade rooms and phone controllers. Private text/action phone views and checkpoint recovery are wired through the room player and simulated by local preview. Schema v2 server rules need deployment activation; local dev refuses them and directs builders to preview on an activated host. Remote network services, native binaries, and arbitrary phone HTML are unsupported. No deployments or infrastructure provisioning run here.
