make build, or download a release archive for Apple Silicon macOS,
x86-64 Linux or x86-64 Windows. Verify it against checksums.txt, extract it and
put threadify-cli (threadify-cli.exe on Windows) on your PATH. Archives include
this guide and example contract/profile-type YAML. To use the shorter command on
a client machine, you can set alias threadify=threadify-cli in your shell.
Connect and sign in
Use the same setup pattern as Fused CLI:login prompts for it. Use --no-input or CI=true
to require an explicit/configured URL. The browser opens the Engine’s configured
Threadify UI. Sign in through Fused Registry or with an existing API key, then
click Approve CLI login. Approval is explicit even if already signed in.
The CLI generates its credential locally; neither the browser nor the Engine
receives that credential in plaintext. Enrollment expires after five minutes;
the resulting credential expires after 30 days. User status and source-key
revocation are checked on requests, and user role/status changes revoke existing
CLI logins. Service-account approval retains the service identity and permissions.
The Engine needs registry.browser_origin / THREADIFY_BROWSER_ORIGIN set to
the deployed UI origin, and that UI must connect to this Engine. Both need the
CLI-login update. The Engine doesn’t bundle the UI. Email/SSO continues to use
Registry’s existing identity flow.
THREADIFY_API_KEY credentials remain available after logout.
Automation and configuration
For scripts and service accounts, configure the URL and supply an API key:threadify-cli config set api-key KEY is also supported, but shell history can
record arguments. CLI config lives at $XDG_CONFIG_HOME/threadify/cli.yaml,
defaulting to $HOME/.config/threadify/cli.yaml. Override it with
THREADIFY_CLI_CONFIG. It is separate from the server’s config.yaml and is
written atomically with file mode 0600 on Unix. Changing its API URL clears
the saved credential to avoid sending it to a different Engine.
URL precedence: --api-url (alias --engine-url), THREADIFY_API_URL,
THREADIFY_ENGINE_URL, saved config. Credential precedence: --key, saved
credential for that exact Engine URL, then THREADIFY_API_KEY. Global
connection flags can precede the command or follow it. Proxy path prefixes
are retained. HTTP redirects are rejected so credentials cannot be forwarded
to a different endpoint.
Resource commands print JSON to stdout and errors to stderr, exit nonzero on
failure, and accept --timeout 30s. Writes are not automatically retried.
An acknowledgement timeout can mean the operation succeeded; query its state
before retrying. Use --file - to read a document from stdin.
Contracts
--yes.
Contract validation and permissions are enforced by the Engine.
Entity profile types and profiles
Definecustomers.yaml:
entity_profile_type.update; creating types
requires entity_profile_type.create. Engine quotas apply. Profiles also appear
automatically when thread references match a configured type; persistence is
asynchronous, so allow a short delay before querying newly derived profiles.
Threads and references
--contract and --role are optional for contract-free threads. Finding by ref
returns every matching thread; refs are not unique thread identifiers. close
requires an explicit completed or cancelled status. verify prints integrity
results and exits nonzero when verification fails. Use SDKs or OTEL for event
instrumentation; the CLI manages and inspects resources.
For other Engine queries: