CLI
Seamless Auth CLI
Section titled “Seamless Auth CLI”The Seamless Auth CLI is published as seamless-cli and exposes the seamless binary. It scaffolds
a self-hosted local project, checks the generated stack, verifies auth conformance, and also acts as
an authenticated client against a running Seamless Auth instance (log in, inspect sessions, and run
admin operations).
Current commands cover:
- scaffold a React + Express Seamless Auth project
- configure the auth server in Docker or local-source mode
- optionally include the admin dashboard
- validate generated config, Docker Compose, containers, and local health endpoints
- bootstrap the first admin user
- verify the full auth surface with the
seamless verifyconformance harness - log in to an instance and manage the active profile, session, and account
- run admin
config,users, andorgoperations against an instance
The current ../seamless-cli source does not ship deploy, destroy, or contribute commands.
Mental Model
Section titled “Mental Model”seamless-cli package -> seamless binary -> init local project -> check local runtime -> bootstrap first adminInstallation
Section titled “Installation”No global install is required. Use the package through npx:
npx seamless-cli --helpIf installed globally or linked locally, run the binary directly:
seamless --helpThe package is named seamless-cli; the executable command is seamless.
Core Commands
Section titled “Core Commands”npx seamless-cli init my-appOr use the shortcut:
npx seamless-cli my-appCreates a new Seamless Auth project. The generated project includes a React frontend, an Express
API, Docker Compose wiring, seamless.config.json, and either a Docker-based auth server or local
auth server source depending on your prompt choices.
npx seamless-cli checkValidates the generated project shape and local runtime:
seamless.config.json- configured web and API paths
- Docker availability
docker-compose.yml- expected running containers
- API, auth, and admin health endpoints on local ports
This command checks the local generated stack. It does not currently check Terraform, AWS CLI, or deployment state.
bootstrap-admin
Section titled “bootstrap-admin”npx seamless-cli bootstrap-admin admin@example.comCreates a bootstrap admin invite for the first admin user.
The CLI resolves the bootstrap secret from local project files before prompting manually. It sends
the request through the backend adapter at /auth/internal/bootstrap/admin-invite.
verify
Section titled “verify”seamless verifyseamless verify --localRuns the cross-package auth conformance harness: it stands up the ecosystem with Docker Compose and
runs a Playwright matrix across the api, adapter, and React (browser) layers, then prints a flow x
layer pass/fail grid. Use --local to build the @seamless-auth/* packages from local source
(pre-publish contract testing); the default tests the published packages. See the
CLI command reference for all flags and environment overrides.
Account And Instance Commands
Section titled “Account And Instance Commands”Beyond scaffolding, the CLI can authenticate against a running Seamless Auth instance and act as a client. It targets whichever instance is set in the active profile.
profile
Section titled “profile”seamless profile add work --instance-url https://<your-app-id>.seamlessauth.comseamless profile listseamless profile use workseamless profile remove workProfiles are named pointers to Seamless Auth instances, stored in ~/.config/seamless/config.json
(respects XDG_CONFIG_HOME). The config file holds only non-secret instance and identity metadata,
not tokens. Set the active profile per command with --profile <name> or the SEAMLESS_PROFILE
environment variable.
login, whoami, logout
Section titled “login, whoami, logout”seamless login # email OTP against the active profile's instanceseamless whoami # show the current identity, profile, and instance URLseamless logout # end the session and clear local tokensseamless logout --all # revoke every session first, then clear local tokenslogin authenticates with email OTP and stores the session in the OS keychain (macOS Keychain,
Windows Credential Manager, or Linux Secret Service), not in a plaintext file.
sessions
Section titled “sessions”seamless sessions listseamless sessions revoke <id>seamless sessions revoke --allLists and revokes sessions for the logged-in user.
Admin commands
Section titled “Admin commands”With an admin role on the target instance, the CLI can also run config, users, and org
operations. See the CLI command reference for the full flag surface.
CLI Behavior
Section titled “CLI Behavior”If no command is provided, the CLI prints help.
This is valid:
npx seamless-cli my-appIt is treated as:
npx seamless-cli init my-appThe same behavior applies to the binary:
seamless my-appWhat Happens During init
Section titled “What Happens During init”The CLI will:
- Ask configuration questions
- Generate the React web starter
- Generate the Express API starter
- Configure the auth server in Docker or local-source mode
- Optionally include the admin dashboard
- Generate Docker Compose and local config
Generated Files
Section titled “Generated Files”web/api/auth/ # only in local auth modeadmin/ # only in admin source modedocker-compose.ymlseamless.config.jsonREADME.mdDesign Philosophy
Section titled “Design Philosophy”The CLI is built to be:
- opinionated: secure defaults and a known project shape
- guided: interactive prompts for local stack generation
- explicit: generated config and service wiring are visible in the project
- local-first: the current source focuses on a repeatable development stack
Current Boundaries
Section titled “Current Boundaries”The CLI still does not provide a polished “attach Seamless Auth to an existing application” flow.
Deployment automation is not part of the current seamless-cli command surface. Keep deployment
docs status-based until deployment commands ship again in source.
Next Step
Section titled “Next Step”Continue to CLI Init Deep Dive.