npx @outerlayer/cli <command>. It needs Node.js 22 or later.
These pages write outerlayer <command> for short. Unless you installed the CLI with npm install -g @outerlayer/cli, type npx @outerlayer/cli in its place.
How upgrades reach the hooks:
- Run through
npx,initcopies the CLI to~/.outerlayer/cli. The hooks and the status line run that copy, so clearing npm’s cache does not break them. - To upgrade that copy, run
npx @outerlayer/cli@latest init --local. It points every hook at the new copy and makes no network call. - A plain
initupgrades the copy too, and also runs the connect step. - With
npm install -g, the hooks run the global install. Upgrading it upgrades them.
outerlayer daemon or outerlayer runner start after an upgrade so it runs the new version.
Commands
outerlayer <command> --help (or -h) prints every flag of a command.
Conventions every command follows
--jsonmakes stdout one JSON document and nothing else. Most commands that report a result take it. These do not:logout,runner init,runner install,runner uninstall,runner check,runner stop,runner logs,hooks install-git,hooks wrapandhooks unwrap. Neither do the long-runningdaemon,runner startandmcp serve. Onconnect,--jsonmoves the text to stderr instead of dropping it.--no-colorstrips escape codes. Color is off on its own when stdout is not a terminal, whenNO_COLORis set, or whenTERMisdumb.FORCE_COLOR=1turns it on for a pipe.--urland--app-idoverride the saved config onsync, everyworkandemitcommand, andmcp installandmcp serve.connect,logoutanddoctortake neither. There is no default gateway. A command with no URL from a flag, the environment or the config file refuses and says so. The API key is never a flag. It comes fromlogin, or fromOUTERLAYER_API_KEY.loginis the exception to--urland--app-id. They apply only when a key is piped on stdin. Without a piped key,loginsigns in by browser, refuses both flags and exits 2. Browser login takes its gateway address from the dashboard, and--dashboard <address>picks the dashboard. See Cloud.--no-inputmakesloginandhooks wrapfail instead of waiting on a person. They are the only commands that take it.connectasks only on a terminal.--version(or-V) prints the package version and, when the build carries one, its build id.
Credential resolution
A cloud command sends one credential and names one factory. It picks a factory key over a login whenever a key exists, so CI and runners always act as their key. With a factory key. The first hit wins for each value:- The key:
OUTERLAYER_API_KEY, thenapiKeyin~/.outerlayer/config.json. It is never a flag. - The gateway:
--url, thenOUTERLAYER_URL, thenurlin the config file. - The factory:
--app-id, thenOUTERLAYER_APP_ID, thenappIdin the config file.
- The token:
accountTokenin the config file, written byouterlayer login. - The gateway:
--url, thenOUTERLAYER_URL, thenurlin the config file. - The factory:
--app-id, thenOUTERLAYER_APP_ID, then the repository’s saved connection fromouterlayer connect. A login never usesappIdfrom the config file, which belongs to a factory key.
--app-id or set OUTERLAYER_APP_ID.