WalkPic documentation
Command-line tools
Inspect the catalog and execute approved read operations.
Build the packages using the installation guide and provide an approved token through your trusted launcher.
node packages/cli/dist/bin.js operations list
node packages/cli/dist/bin.js auth status
printf '{"query":{"limit":"5"}}\n' | node packages/cli/dist/bin.js call integrationListOwnedPublications --input -Detailed usage
WalkPic CLI 0.1.0
Node 24.21.0. Thin adapter over @walkpic/sdk: the generated contract and reviewed integration policy describe all 203 operations. Only eight explicit v2 starter JSON reads can run. Local candidate flags never establish server authorization: current grants, account state and resource access remain required.
walkpic --help
walkpic operations list
walkpic operations describe integrationListOwnedPublications --schema request
walkpic auth status
walkpic call integrationListOwnedPublications --input -
HTTPS is required outside loopback. Set WALKPIC_BASE_URL and WALKPIC_ACCESS_TOKEN explicitly in the launching process environment. The token must be a wp_int. integration bearer. Use a trusted launcher to inject it; never put secrets in command arguments, shell history, request JSON or committed files. MeshAgent server/project/room credentials are rejected. Environment variables are ephemeral configuration, not a secure persisted credential store. Keychain integration, device authorization, login await separate support.
Input is a JSON SDK request envelope (path, query, headers, optional body and contentType), read from a regular file or stdin (--input -, at most 64 KiB). Credential headers and capability query parameters cannot override the integration provider. Query primitives use SDK serialization and source contract checks. The default deadline is 30 seconds (--timeout-ms 1..60000). Ctrl-C cancels; there are no retries or automatic token refreshes.
Stdout contains one JSON response envelope with operation ID, HTTP status, permitted transport headers and SDK-validated body. Progress and sanitized failures go to stderr. --output NEW_FILE exclusively creates a mode-0600 JSON file; existing files are preserved. JSON output is bounded to 1 MiB. Binary, streams, authentication/token-producing operations, writes and all nonstarter operations are denied before network access. The catalog describes them for future reviewed adoption.
Exit codes: 0 successful declared HTTP response; 2 invalid CLI/input; 3 credentials/local denial or HTTP 401/403; 4 other declared HTTP errors; 5 transport/deadline/output failure; 130 user cancellation. Timeout/cancellation does not claim remote work completed or was undone.
Build SDK first, then npm ci && npm run build && npm test using Node 24.21.0. npm run pack:local stages a distributable tarball with versioned SDK dependency; it does not publish. Local HTTP/SQLite tests issue real local integration grants through the production-shaped adapter with room connectivity replaced. They prove local behavior, not deployed grant enforcement.
Explicit one-time refresh: walkpic auth refresh --credential-fd N [--input -]. Provide a trusted launcher-created, private, writable local pipe/socket descriptor N>=3, separate from standard streams. Regular files, terminals, network sockets and stdio aliases are rejected before dispatch. This private descriptor mode currently supports Unix-like systems. The launcher controls the receiving process; the descriptor does not authenticate that process. Do not redirect credentials to a file or use a terminal.
Supply WALKPIC_REFRESH_TOKEN, WALKPIC_CLIENT_ID and WALKPIC_GRANT_ID in the explicit environment, or bounded stdin JSON containing refreshToken, clientId, grantId and optionally a stable requestId. WALKPIC_BASE_URL remains explicit. Stdin credentials must come from a private pipe, never a terminal or file. Secret values are never command arguments. The command uses the generated integrationRefreshPersonalGrant operation with a separate SDK integrationRefresh credential kind; it is denied through ordinary call and absent from MCP tools.
Only the validated credential pair goes to the private descriptor. Stdout contains nonsecret acknowledgement/status/error code; stderr contains stages and safe guidance. Update both launcher credentials only after a complete validated JSON line is received. A failed write, abort or lost acknowledgement can leave rotation completed with credentials unavailable. Do not retry the old refresh token: revoke the grant in first-party Integrations and approve a new grant. There is no plaintext recovery or automatic rotation. Restart an MCP child with the explicitly delivered access token; MCP never handles or returns the refresh secret.
The live personal-approval page is https://app.walkpic.com/integrations; set WALKPIC_BASE_URL=https://walkpic.com in your trusted launcher. An owned production QA account verified all eight read operations, insufficient-scope denial, revocation and actor access loss across SDK/CLI/MCP. The CLI also verified explicit credential rotation through its private descriptor. Tokens remain launcher secrets; MCP receives only the approved access token. Evidence: docs/evidence/resumed-delivery-20261005/integration-acceptance/public-verification-r4.json.