WalkPic DevelopersManage integrations ↗

WalkPic documentation

Command-line tools

Inspect the catalog and execute approved read operations.

Before you start

Build the packages using the installation guide and provide an approved token through your trusted launcher.

node packages/cli/dist/bin.js operations list
node packages/cli/dist/bin.js auth status
printf '{"query":{"limit":"5"}}\n' | node packages/cli/dist/bin.js call integrationListOwnedPublications --input -

Detailed usage

WalkPic CLI 0.1.0

Node 24.21.0. Thin adapter over @walkpic/sdk: the generated contract and reviewed integration policy describe all 203 operations. Only eight explicit v2 starter JSON reads can run. Local candidate flags never establish server authorization: current grants, account state and resource access remain required.

walkpic --help
walkpic operations list
walkpic operations describe integrationListOwnedPublications --schema request
walkpic auth status
walkpic call integrationListOwnedPublications --input -

HTTPS is required outside loopback. Set WALKPIC_BASE_URL and WALKPIC_ACCESS_TOKEN explicitly in the launching process environment. The token must be a wp_int. integration bearer. Use a trusted launcher to inject it; never put secrets in command arguments, shell history, request JSON or committed files. MeshAgent server/project/room credentials are rejected. Environment variables are ephemeral configuration, not a secure persisted credential store. Keychain integration, device authorization, login await separate support.

Input is a JSON SDK request envelope (path, query, headers, optional body and contentType), read from a regular file or stdin (--input -, at most 64 KiB). Credential headers and capability query parameters cannot override the integration provider. Query primitives use SDK serialization and source contract checks. The default deadline is 30 seconds (--timeout-ms 1..60000). Ctrl-C cancels; there are no retries or automatic token refreshes.

Stdout contains one JSON response envelope with operation ID, HTTP status, permitted transport headers and SDK-validated body. Progress and sanitized failures go to stderr. --output NEW_FILE exclusively creates a mode-0600 JSON file; existing files are preserved. JSON output is bounded to 1 MiB. Binary, streams, authentication/token-producing operations, writes and all nonstarter operations are denied before network access. The catalog describes them for future reviewed adoption.

Exit codes: 0 successful declared HTTP response; 2 invalid CLI/input; 3 credentials/local denial or HTTP 401/403; 4 other declared HTTP errors; 5 transport/deadline/output failure; 130 user cancellation. Timeout/cancellation does not claim remote work completed or was undone.

Build SDK first, then npm ci && npm run build && npm test using Node 24.21.0. npm run pack:local stages a distributable tarball with versioned SDK dependency; it does not publish. Local HTTP/SQLite tests issue real local integration grants through the production-shaped adapter with room connectivity replaced. They prove local behavior, not deployed grant enforcement.

Explicit one-time refresh: walkpic auth refresh --credential-fd N [--input -]. Provide a trusted launcher-created, private, writable local pipe/socket descriptor N>=3, separate from standard streams. Regular files, terminals, network sockets and stdio aliases are rejected before dispatch. This private descriptor mode currently supports Unix-like systems. The launcher controls the receiving process; the descriptor does not authenticate that process. Do not redirect credentials to a file or use a terminal.

Supply WALKPIC_REFRESH_TOKEN, WALKPIC_CLIENT_ID and WALKPIC_GRANT_ID in the explicit environment, or bounded stdin JSON containing refreshToken, clientId, grantId and optionally a stable requestId. WALKPIC_BASE_URL remains explicit. Stdin credentials must come from a private pipe, never a terminal or file. Secret values are never command arguments. The command uses the generated integrationRefreshPersonalGrant operation with a separate SDK integrationRefresh credential kind; it is denied through ordinary call and absent from MCP tools.

Only the validated credential pair goes to the private descriptor. Stdout contains nonsecret acknowledgement/status/error code; stderr contains stages and safe guidance. Update both launcher credentials only after a complete validated JSON line is received. A failed write, abort or lost acknowledgement can leave rotation completed with credentials unavailable. Do not retry the old refresh token: revoke the grant in first-party Integrations and approve a new grant. There is no plaintext recovery or automatic rotation. Restart an MCP child with the explicitly delivered access token; MCP never handles or returns the refresh secret.

The live personal-approval page is https://app.walkpic.com/integrations; set WALKPIC_BASE_URL=https://walkpic.com in your trusted launcher. An owned production QA account verified all eight read operations, insufficient-scope denial, revocation and actor access loss across SDK/CLI/MCP. The CLI also verified explicit credential rotation through its private descriptor. Tokens remain launcher secrets; MCP receives only the approved access token. Evidence: docs/evidence/resumed-delivery-20261005/integration-acceptance/public-verification-r4.json.