reachpad-cli
Health Uyari
- No license — Repository has no license file
- Description — Repository has a description
- Active repo — Last push 0 days ago
- Low visibility — Only 5 GitHub stars
Code Basarisiz
- rm -rf — Recursive force deletion command in install.sh
- child_process — Shell command execution capability in npm/cli/bin/reachpad.js
- spawnSync — Synchronous process spawning in npm/cli/bin/reachpad.js
Permissions Gecti
- Permissions — No dangerous permissions requested
Bu listing icin henuz AI raporu yok.
The reachpad CLI: workspaces where Claude, Codex and other coding agents build full-stack apps and share them by link, from your terminal.
reachpad CLI
Run coding agents in durable cloud workspaces: the disk survives the machine
underneath, so a paused workspace costs nothing and picks up from its last
save. Files survive a pause; running processes do not.
Install
With Homebrew on Apple silicon macOS or x86_64/arm64 Linux:
brew install reachpad/tap/reachpad
With npm, anywhere Node 18+ runs:
npm install -g @reachpad/cli
Or with the checksum-verifying installer:
curl -fsSL https://reachpad.dev/install | sh
Linux x86_64/arm64 (musl, static) and macOS arm64/x86_64. The script fetches
the latest release from this repository, verifies its checksum against
SHA256SUMS, and installs to ~/.local/bin/reachpad (override withREACHPAD_INSTALL_DIR).
All three deliver the same binary. @reachpad/cli is a launcher around it, not
a second implementation — see npm/README.md, which also
explains the macOS quarantine problem npm sidesteps.
Get started
Run Reachpad:
reachpad
On first use, the CLI shows a short code, opens WorkOS hosted sign-in, and then
lists your workspaces. WorkOS handles the account login and any required MFA or
SSO. After approval, Reachpad exchanges the short-lived WorkOS token once and
saves a user-scoped Reachpad credential and the production endpoint with mode
0600. No password or authentication factor is entered into Reachpad.
On a remote machine without a usable browser, run reachpad auth login --no-browser and open the displayed URL on another device. The manual
credential flow remains available from
reachpad.dev/connect as a recovery path.
Then create a workspace, work in it, and put it away:
reachpad create scratch
reachpad list
reachpad attach <workspace-id>
reachpad run <workspace-id> -- cargo test
reachpad pause <workspace-id>
create prints the workspace id the other verbs take. The name is only a
label; there is no lookup by name.
Useful maintenance commands:
reachpad doctor
reachpad update
reachpad completions bash
reachpad completions zsh
reachpad completions fish
reachpad update respects how Reachpad was installed: Homebrew installs are
directed to brew upgrade reachpad and npm installs to npm install -g @reachpad/cli@latest, while installer-managed binaries are updated in place
after the release checksum is verified. Whoever installed the binary owns it —
a second writer is how a working install becomes a broken one.
Docs: reachpad.dev/docs/cli
Source and provenance
This repository carries the full CLI source: the reach package (shipped
binary name reachpad) and its two library crates (proto, the frozen wire
protocol, and authz, Biscuit verify and offline attenuation). Release
binaries are built from this source by
the release workflow on GitHub's runners, and
every release carries a SHA256SUMS the install script verifies. To build it
yourself (needs Rust and protoc):
cargo build --release -p reach
./target/release/reachpad --version
Every release tarball also carries a signed build-provenance attestation, so
the chain is checkable without trusting us:
gh attestation verify reachpad-<target>.tar.gz --repo Reachpad/reachpad-cli
That proves the bytes came out of this repository's release workflow at the
commit the tag names. It rests on no key of ours — the signing identity is a
short-lived credential minted for that one workflow run, and the record is in
a public transparency log.
The snapshot is synced from a private monorepo on every release, so file an
issue rather than a PR for changes; a PR here would be overwritten by the
next sync (the sync script and its header in Cargo.toml say the same).
The CLI is an ordinary client of a public API: it holds no platform secrets
and nothing it does is privileged (the server refuses anything a stranger
could not do).
Source-available; copyright Tako Research, all rights reserved.
Yorumlar (0)
Yorum birakmak icin giris yap.
Yorum birakSonuc bulunamadi