Management Commands
The CLI manages Flow resources directly through the versioned management API. Commands return the response body as JSON on stdout; request failures go to stderr and set exit code 1. They work outside a local task project.
export THYME_API_URL="$API_URL"
thyme login --management
thyme projects list --workspace WORKSPACE_IDSet API_URL to the HTTP API base for your deployment before this example. Management commands and thyme api read exported environment variables and saved config; they do not themselves load a project's .env.
Credentials and shared options
Management login requests workspace-bound access through browser consent. Multiple credentials can coexist. A sole unexpired workspace credential is selected automatically; with several workspaces, pass -w, --workspace <id>. There is no global active-workspace setting.
If no matching stored management credential exists, the CLI falls back to the standard configured token or THYME_AUTH_TOKEN. The API still requires the appropriate workspace and scopes. A personal upload token is not automatically full management access.
All resource commands below accept --workspace. Every mutation also accepts --idempotency-key <key>. A mutation gets a generated key when you omit it. The client retries a network exception once using the same request and key; it does not automatically retry an HTTP error response. Supply your own stable key when separate CLI invocations represent the same operation.
List pagination options are shown where supported. Follow the response's cursor explicitly; the CLI does not collect every page automatically.
Projects and chains
| Command | Required / optional arguments |
|---|---|
projects list | No resource arguments. |
projects get <id> | Project ID. |
projects create | Required --name, --slug; optional --description, --environment production|development. |
projects update <id> | Optional --name, --description. |
chains list | Lists chains enabled for the workspace. |
thyme projects create --name Automation --slug automation \
--environment development --workspace WORKSPACE_ID
thyme chains list --workspace WORKSPACE_IDFunctions
| Command | Required / optional arguments |
|---|---|
functions list | Required --project; optional --name, --limit, --cursor. |
functions get <id> | Inspect a release. |
functions source <id> | Fetch source metadata/content. |
functions copy <id> | Required target --project; optional --name, -t/--tag. |
functions delete <id> | Delete a release, subject to API constraints. |
Create a release with thyme upload. Copying a function does not copy an executable's profile, secrets, or trigger. Tags remain reserved after deletion.
thyme functions list --project PROJECT_ID --name monitor --workspace WORKSPACE_ID
thyme functions copy FUNCTION_ID --project TARGET_PROJECT_ID --tag v2 \
--workspace WORKSPACE_IDExecutables
| Command | Required / optional arguments |
|---|---|
executables list | Required --project; optional --limit, --cursor. |
executables get <id> | Inspect status and configuration. |
executables create | Required --data <json> with the complete API configuration. |
executables pause <id> / resume <id> | Change scheduling state. |
executables run <id> | Request a cloud execution. This may submit transactions. |
executables simulate <id> | Request cloud simulation. |
executables reprovision <id> | Request reprovisioning through the API. |
executables regenerate <id> | Regenerate derived executable resources through the API. |
executables set-function <id> | Required --function; optional --args <json>. Requires a paused executable. |
executables update <id> <field> | Required --data <json> for one configuration facet. |
executables delete <id> | Delete an executable, subject to API constraints. |
executables storage-get <id> | Read storage and its current version. |
executables storage-set <id> | Required --expected-version <n>, --value <json>. |
executables webhooks <id> | List webhook credentials for the executable. |
executables webhook-create <id> | Required --name; creates a webhook credential. |
The supported update fields are args, secrets, gas-mode, profile, sponsorship-provider, pinned, and trigger. The body must match the corresponding endpoint's schema; it is not a generic key/value wrapper. See API resources.
thyme executables update EXECUTABLE_ID gas-mode \
--data '{"gasMode":"self-funded","gasFallback":true}' \
--workspace WORKSPACE_IDFor larger executable configurations, use the raw proxy's file input:
thyme api POST /api/v1/executables --data-file executable.json \
--workspace WORKSPACE_ID --idempotency-key create-monitor-v1Switching a release
thyme executables pause EXECUTABLE_ID --workspace WORKSPACE_ID
thyme executables set-function EXECUTABLE_ID --function FUNCTION_V2_ID \
--workspace WORKSPACE_ID
thyme executables get EXECUTABLE_ID --workspace WORKSPACE_IDInspect the returned state and wait until the version switch finishes successfully before resuming. A release switch may involve asynchronous provisioning and permissions changes; a successful request is not proof that the switch is already complete.
thyme executables resume EXECUTABLE_ID --workspace WORKSPACE_IDEditing storage
thyme executables storage-get EXECUTABLE_ID --workspace WORKSPACE_ID
thyme executables storage-set EXECUTABLE_ID \
--expected-version 4 --value '{"cursor":"1200"}' \
--workspace WORKSPACE_IDUse the version returned by the preceding read, replacing 4 in the example. The update replaces the full object; a stale version conflicts. Management storage requests support at most 16 MiB per request, separate from the stored-value limit. See storage.
Executions
| Command | Required / optional arguments |
|---|---|
executions list | Required --project; optional --status, --limit, --cursor. |
executions get <id> | Inspect one execution. |
executions logs <id> | Retrieve captured execution logs. |
thyme executions list --project PROJECT_ID --status failed --limit 20 \
--workspace WORKSPACE_ID
thyme executions logs EXECUTION_ID --workspace WORKSPACE_IDA run request can be asynchronous. Inspect execution state rather than treating request acceptance as transaction confirmation.
Profiles
| Command | Required / optional arguments |
|---|---|
profiles list | Required --project; optional --limit, --cursor. |
profiles get <id> | Inspect one profile. |
profiles create | Required --project, --alias, --chain <chainId>. |
profiles rename <id> | Required --name. |
profiles archive <id> / unarchive <id> | Change availability. |
profiles retry <id> | Retry profile provisioning. |
profiles share <id> | Required target --project; optional --alias. |
Use chains list for valid chain choices. The typed profiles create command exposes only these fields; use the documented Console/profile flow for account types and signature approvals requiring additional inputs. The independent verify roles-profile command supports a narrower, explicitly pinned network.
Secrets
| Command | Required / optional arguments |
|---|---|
secrets list | Required --project; returns metadata, not values. |
secrets create | Required --project, --key, --value. |
secrets rotate <id> | Required replacement --value. |
secrets delete <id> | Delete a secret. |
Secrets are write-only. Creating a project secret does not automatically bind it to every executable. Configure bindings through executables update <id> secrets using the API schema. Prefer the raw proxy's --data-file for secret request bodies when command-line argument exposure is a concern; do not commit that file.
Webhooks and usage
| Command | Required / optional arguments |
|---|---|
webhooks get <id> | Inspect webhook metadata. |
webhooks rename <id> | Required --name. |
webhooks rotate <id> | Issue a replacement webhook credential. |
webhooks revoke <id> | Revoke the credential. |
usage current | Inspect workspace Flow usage. |
Create and list webhooks through the executable commands above. Creation/rotation responses can contain sensitive credential material; store it securely and avoid printing it to shared CI logs. See webhooks.
Raw API proxy
thyme api GET '/api/v1/functions?projectId=PROJECT_ID&name=monitor' \
--workspace WORKSPACE_ID
thyme api PATCH /api/v1/executables/EXECUTABLE_ID/pinned \
--data '{"pinned":true}' --idempotency-key pin-monitor \
--workspace WORKSPACE_ID| Option | Behavior |
|---|---|
<method> | GET, POST, PATCH, PUT, or DELETE; case-insensitive. |
<path> | Relative versioned route under /api/v1/; query strings accepted. |
--data <json> | Inline JSON body. |
--data-file <path> | Read JSON from a file; mutually exclusive with --data. |
--header <header...> | Additional Name: Value headers. |
--workspace <id> | Select workspace and matching credential. |
--idempotency-key <key> | Preserve mutation identity across separate retries. |
Absolute URLs and routes outside /api/v1/ are rejected. Authorization, apikey, and X-Workspace-Id headers are controlled by the CLI; use its credential configuration and workspace option. The raw proxy shares the resource commands' JSON output, network retry, and error behavior.
Remove a stored workspace credential with thyme logout --management --workspace WORKSPACE_ID. That only removes local access; revoke the server-side key in the Console when it must stop working everywhere.