<command> --help for its exact options. User-facing commands support --json for automation. Command success (ok) is not runtime health; inspect explicit evidence fields. Gate commands such as verify, doctor, events --wait and connect --wait-evidence also fail when their verification condition is not met.
Sign in and connect
--kind accepts agent or mcp; --language accepts typescript or python for agents. The CLI does not infer the kind for a first non-interactive connection. It does not launch your coding agent, invent sync scripts or run rippletide:start.
Login and project binding are distinct from runtime health. A failed logout keeps the local credential for retry. Changing workspace requires its own authorization.
Inspect and diagnose
Use
--agent outside a connected repository. --wait cannot be combined with a trace ID or cursor. SDK-agent proof includes before-response evidence; MCP requires a tool call but no turn. verify does not prove a live turn or compare the stored catalogue with every tool in your source code.
Running rippletide without a command opens the interactive home in a terminal. Non-interactive use returns next-step information rather than waiting for terminal input.
Rules
Use
--agent <id> or advanced --target <id> when there is no project binding. Enforce requires Admin permission.
Authoring selectors are --actions <key> (repeat for selected actions), --all-actions, --before-response, and --after-action <key> for one declared collection. Legacy --action <key> remains supported. Before-action Rules accept --effect ALLOW or BLOCK; BLOCK is the default. If the compiler asks a question, keep the original input/effect and add --context "answer".
Discover from recorded traces
--include-raw-values permits analysis of captured values for that request. Review the output’s evidence, replay and required settings. Add --config '{"setting":100}' using the proposal’s declared fields when needed. Saving through this CLI flow starts Disabled; set Observe explicitly after review.
For catalogue/document discovery, --source accepts text, an HTTPS URL or @file containing UTF-8 text. --json is read-only for discovery. Interactive ready-only batches omit proposals needing additional configuration; trace export preserves proposals for explicit review/save.
Business context
Run from the connected repository, or add--agent <id> / --target <id>:
--source <id> to select them. update checks the expected version to avoid overwriting someone else’s newer version.
analyze proposes changes; apply changes only selected IDs and accepts --config keyed by those IDs. New Rules start Disabled, replacements Observe. Review per-change failures before retrying. Archiving disables dependent Rules. See Business context for the web preview, Notion and retained evidence.
Workspaces
Roles are
viewer, editor or admin; invitations default to viewer. Invitation commands return a link, not an automatically sent email. CLI workspace changes do not change the browser’s selected workspace.
Codex
--session <token> or --agent <id>; without either it can create the Codex agent. --traces/--no-traces controls stored activity, and --backfill/--no-backfill controls history import. Backfill accepts --capture metadata|redacted|full; redacted is the default. codex hook <event> is called by Codex, not a manual verification command.
Read Connect Codex before setup for coverage, trust and privacy choices.
Local configuration
The account credential is in~/.rippletide/config.json, project binding in .rippletide/project.json, and runtime connection in the repository’s git-ignored .env. CLI setup writes only RIPPLETIDE; Codex has its own ~/.rippletide/codex.env. See API keys for rotation, precedence and removal.