# CLI reference (/sdk-and-cli/cli)



## Install [#install]

```bash
npm install --global @openmetal/cli
openmetal --help
```

## Global options [#global-options]

Place global options before the subcommand.

```bash
openmetal --json --no-input --profile ci sandbox list
```

* `--json` emits stable JSON.
* `--no-input` fails instead of prompting.
* `--yes` confirms destructive operations.
* `--profile`, `--api-url`, `--organization`, and `--project` override stored context.

Prefer environment variables to secret command arguments in automation.

```bash
export OPENMETAL_API_URL="https://api.openmetal.sh"
export OPENMETAL_PROJECT_ID="prj_your_project"
export OPENMETAL_API_KEY="metal_sk_your_key"
```

## Command groups [#command-groups]

Account and project management:

```bash
openmetal org list
openmetal project list
openmetal api-key list
openmetal provider-credential list
openmetal member list
openmetal invitation create --email user@example.com
openmetal billing show
```

Compute and runtime:

```bash
openmetal sandbox list
openmetal operation get <operation-id>
openmetal process get <sandbox-id> <process-id>
openmetal file list <sandbox-id> /workspace
openmetal endpoint list <sandbox-id>
openmetal events list
```

Webhook management and organization usage analytics are currently available through the
[OpenMetal dashboard](https://www.openmetal.sh/dashboard), REST API, and TypeScript SDK rather than
dedicated CLI commands.

## Profiles [#profiles]

Use profiles to separate environments and projects. Production uses the hosted OpenMetal API:

```bash
openmetal config use-profile production
openmetal --profile production config set \
  --api-url https://api.openmetal.sh
openmetal doctor
```

Configuration precedence starts with command flags, then `OPENMETAL_*` variables, legacy `METAL_*` aliases, profile values, and compiled defaults.

## Automation pattern [#automation-pattern]

```bash
mutation="$(
  openmetal --json --no-input sandbox create \
    --environment metal/node \
    --environment-version latest \
    --vcpu 2 \
    --memory-mb 4096 \
    --runtime-timeout 1800 \
    --async
)"

# Extract and persist both IDs before waiting.
openmetal operation wait <operation-id> --timeout 180
```

<Callout type="warn" title="Do not expose one time keys">
  API key creation prints the plaintext key once, including JSON mode. Run it in a trusted terminal,
  not an agent transcript or CI log.
</Callout>

See [the CLI quickstart](/get-started/cli) for a complete first run.
