oap CLI reference

The oap CLI installs, manages, and runs agents. Every command below is generated directly from the CLI, so it matches the binary you have. Pick a family for its subcommands and flags.

Families

FamilyWhat it does
oap agentManage and run AgentClass resources
oap artifactInspect versioned artifacts and their revisions
oap auditVerify the tamper-evident audit log of a session
oap buildBuild (and load) Docker images
oap channelManage Channel CRs (Slack, browser, GitHub webhooks, schedules, ...).
oap checkverify namespace, CRDs, services, and every registered component's health
oap classInspect SpiceboxClass resources (sandbox image + capability descriptors)
oap cleanRemove everything oap installed (CRs → operator → CRDs → namespace)
oap desktopRun the oap macOS menubar app (local VM + built-in chat; macOS/Apple Silicon only)
oap directoryConfigure directory-sync sources (RelationshipSource): Slack, GitHub, 1Password, ...
oap identityManage AgentIdentity resources
oap idpManage the cluster identity provider
oap imageWork with local Docker images and the current cluster
oap initBring up agent-primitives end-to-end (build + install + check)
oap installInstall the operator + CRDs into the configured cluster
oap kgQuery the knowledge graph
oap loginLog in to this cluster's identity provider and cache the assertion
oap logoutRemove the cached identity assertion
oap memoryInspect and manage session memory entries
oap pinInspect and update dependency pin baselines
oap plangateInspect what the plan gate recorded for a session
oap platformManage platform-level admin access (the admin UI gate)
oap preferencesInspect a session's resolved per-user preferences
oap sandboxInspect SpiceboxSession resources (per-bundle running sandbox pods)
oap sessionInspect AgentSession resources
oap settingsManage cluster-wide agent settings (security defaults wizard + apply).
oap skillList, view, create, and delete agent Skills and SkillSources
oap spicedbApply schema and check permissions against the system SpiceDB.
oap toolsManage tools used by agents (kind-agnostic)
oap user-identityManage UserIdentity resources (per-user credential catalogs)

Global flags

These persistent flags apply to every command:

--context string        Kubeconfig context to use (default: current-context)
--kubeconfig string     Path to kubeconfig file (default: $KUBECONFIG or ~/.kube/config)
--no-color              Disable terminal colors (also auto-disabled when stdout isn't a TTY or NO_COLOR is set)
-n, --namespace string  Kubernetes namespace (default: kubeconfig context's namespace, falling back to 'default')