Skip to content
Thyme Docs

Management Commands

The CLI manages Flow resources directly through the versioned management API. Commands return the response body as JSON on stdout; request failures go to stderr and set exit code 1. They work outside a local task project.

export THYME_API_URL="$API_URL"
thyme login --management
thyme projects list --workspace WORKSPACE_ID

Set API_URL to the HTTP API base for your deployment before this example. Management commands and thyme api read exported environment variables and saved config; they do not themselves load a project's .env.

Credentials and shared options

Management login requests workspace-bound access through browser consent. Multiple credentials can coexist. A sole unexpired workspace credential is selected automatically; with several workspaces, pass -w, --workspace <id>. There is no global active-workspace setting.

If no matching stored management credential exists, the CLI falls back to the standard configured token or THYME_AUTH_TOKEN. The API still requires the appropriate workspace and scopes. A personal upload token is not automatically full management access.

All resource commands below accept --workspace. Every mutation also accepts --idempotency-key <key>. A mutation gets a generated key when you omit it. The client retries a network exception once using the same request and key; it does not automatically retry an HTTP error response. Supply your own stable key when separate CLI invocations represent the same operation.

List pagination options are shown where supported. Follow the response's cursor explicitly; the CLI does not collect every page automatically.

Projects and chains

CommandRequired / optional arguments
projects listNo resource arguments.
projects get <id>Project ID.
projects createRequired --name, --slug; optional --description, --environment production|development.
projects update <id>Optional --name, --description.
chains listLists chains enabled for the workspace.
thyme projects create --name Automation --slug automation \
  --environment development --workspace WORKSPACE_ID
thyme chains list --workspace WORKSPACE_ID

Functions

CommandRequired / optional arguments
functions listRequired --project; optional --name, --limit, --cursor.
functions get <id>Inspect a release.
functions source <id>Fetch source metadata/content.
functions copy <id>Required target --project; optional --name, -t/--tag.
functions delete <id>Delete a release, subject to API constraints.

Create a release with thyme upload. Copying a function does not copy an executable's profile, secrets, or trigger. Tags remain reserved after deletion.

thyme functions list --project PROJECT_ID --name monitor --workspace WORKSPACE_ID
thyme functions copy FUNCTION_ID --project TARGET_PROJECT_ID --tag v2 \
  --workspace WORKSPACE_ID

Executables

CommandRequired / optional arguments
executables listRequired --project; optional --limit, --cursor.
executables get <id>Inspect status and configuration.
executables createRequired --data <json> with the complete API configuration.
executables pause <id> / resume <id>Change scheduling state.
executables run <id>Request a cloud execution. This may submit transactions.
executables simulate <id>Request cloud simulation.
executables reprovision <id>Request reprovisioning through the API.
executables regenerate <id>Regenerate derived executable resources through the API.
executables set-function <id>Required --function; optional --args <json>. Requires a paused executable.
executables update <id> <field>Required --data <json> for one configuration facet.
executables delete <id>Delete an executable, subject to API constraints.
executables storage-get <id>Read storage and its current version.
executables storage-set <id>Required --expected-version <n>, --value <json>.
executables webhooks <id>List webhook credentials for the executable.
executables webhook-create <id>Required --name; creates a webhook credential.

The supported update fields are args, secrets, gas-mode, profile, sponsorship-provider, pinned, and trigger. The body must match the corresponding endpoint's schema; it is not a generic key/value wrapper. See API resources.

thyme executables update EXECUTABLE_ID gas-mode \
  --data '{"gasMode":"self-funded","gasFallback":true}' \
  --workspace WORKSPACE_ID

For larger executable configurations, use the raw proxy's file input:

thyme api POST /api/v1/executables --data-file executable.json \
  --workspace WORKSPACE_ID --idempotency-key create-monitor-v1

Switching a release

thyme executables pause EXECUTABLE_ID --workspace WORKSPACE_ID
thyme executables set-function EXECUTABLE_ID --function FUNCTION_V2_ID \
  --workspace WORKSPACE_ID
thyme executables get EXECUTABLE_ID --workspace WORKSPACE_ID

Inspect the returned state and wait until the version switch finishes successfully before resuming. A release switch may involve asynchronous provisioning and permissions changes; a successful request is not proof that the switch is already complete.

thyme executables resume EXECUTABLE_ID --workspace WORKSPACE_ID

Editing storage

thyme executables storage-get EXECUTABLE_ID --workspace WORKSPACE_ID
thyme executables storage-set EXECUTABLE_ID \
  --expected-version 4 --value '{"cursor":"1200"}' \
  --workspace WORKSPACE_ID

Use the version returned by the preceding read, replacing 4 in the example. The update replaces the full object; a stale version conflicts. Management storage requests support at most 16 MiB per request, separate from the stored-value limit. See storage.

Executions

CommandRequired / optional arguments
executions listRequired --project; optional --status, --limit, --cursor.
executions get <id>Inspect one execution.
executions logs <id>Retrieve captured execution logs.
thyme executions list --project PROJECT_ID --status failed --limit 20 \
  --workspace WORKSPACE_ID
thyme executions logs EXECUTION_ID --workspace WORKSPACE_ID

A run request can be asynchronous. Inspect execution state rather than treating request acceptance as transaction confirmation.

Profiles

CommandRequired / optional arguments
profiles listRequired --project; optional --limit, --cursor.
profiles get <id>Inspect one profile.
profiles createRequired --project, --alias, --chain <chainId>.
profiles rename <id>Required --name.
profiles archive <id> / unarchive <id>Change availability.
profiles retry <id>Retry profile provisioning.
profiles share <id>Required target --project; optional --alias.

Use chains list for valid chain choices. The typed profiles create command exposes only these fields; use the documented Console/profile flow for account types and signature approvals requiring additional inputs. The independent verify roles-profile command supports a narrower, explicitly pinned network.

Secrets

CommandRequired / optional arguments
secrets listRequired --project; returns metadata, not values.
secrets createRequired --project, --key, --value.
secrets rotate <id>Required replacement --value.
secrets delete <id>Delete a secret.

Secrets are write-only. Creating a project secret does not automatically bind it to every executable. Configure bindings through executables update <id> secrets using the API schema. Prefer the raw proxy's --data-file for secret request bodies when command-line argument exposure is a concern; do not commit that file.

Webhooks and usage

CommandRequired / optional arguments
webhooks get <id>Inspect webhook metadata.
webhooks rename <id>Required --name.
webhooks rotate <id>Issue a replacement webhook credential.
webhooks revoke <id>Revoke the credential.
usage currentInspect workspace Flow usage.

Create and list webhooks through the executable commands above. Creation/rotation responses can contain sensitive credential material; store it securely and avoid printing it to shared CI logs. See webhooks.

Raw API proxy

thyme api GET '/api/v1/functions?projectId=PROJECT_ID&name=monitor' \
  --workspace WORKSPACE_ID
thyme api PATCH /api/v1/executables/EXECUTABLE_ID/pinned \
  --data '{"pinned":true}' --idempotency-key pin-monitor \
  --workspace WORKSPACE_ID
OptionBehavior
<method>GET, POST, PATCH, PUT, or DELETE; case-insensitive.
<path>Relative versioned route under /api/v1/; query strings accepted.
--data <json>Inline JSON body.
--data-file <path>Read JSON from a file; mutually exclusive with --data.
--header <header...>Additional Name: Value headers.
--workspace <id>Select workspace and matching credential.
--idempotency-key <key>Preserve mutation identity across separate retries.

Absolute URLs and routes outside /api/v1/ are rejected. Authorization, apikey, and X-Workspace-Id headers are controlled by the CLI; use its credential configuration and workspace option. The raw proxy shares the resource commands' JSON output, network retry, and error behavior.

Remove a stored workspace credential with thyme logout --management --workspace WORKSPACE_ID. That only removes local access; revoke the server-side key in the Console when it must stop working everywhere.