CLI#
astra anemoi manages flows and checks receipts from a terminal;
astra evidence verify checks evidence packs. The flows commands work in
the organisation, workspace and cluster you chose with astra use
(Install the CLI), as you; the verify
commands need only files.
$ astra login
$ astra use acme/research@main
$ astra anemoi flows apply -f nightly-digest.yaml
$ astra anemoi flows run nightly-digest --input day=2026-09-30 --wait
$ astra anemoi receipts verify run.receipt.json --jwks jwks.json
$ astra evidence verify q3-2026.zip --jwks jwks.json
Agents from the CLI
astra has no commands to create, change or run agents, decide
approvals, or manage budgets, guardrails, evaluations or the
marketplace yet: use the console or the API. Agent runs are
runs, so astra astraeus status, logs and delete work on them.
astra anemoi flows#
| Command | Description |
|---|---|
apply -f <file> |
Create the flow from a YAML or JSON file, or write its next version. --no-current writes it without making it current. Runs the cluster's checks on the file first. Prints flow <name>: version <n> written, now current. |
validate -f <file> |
Check the file here, without sending it: shape, step ids, the graph, each kind's fields, the names expressions use. --remote also asks the cluster, which checks that the agents, flows and drives named exist. Works signed out without --remote. Exit status 1 with problems. |
list |
FLOW CURRENT LATEST AGE. |
run <flow> |
Start an execution. -i, --input key=value (repeatable); --version <n>; --wait follows it until it ends, prints its steps, and exits 1 unless it Succeeded. |
executions |
EXECUTION FLOW VERSION STATE STEPS WHY AGE, newest first. --flow <name> for one flow's. |
get <execution> |
Its state, then STEP STATE ATTEMPTS LAST MACHINE WHY OUTPUTS, its agent runs' receipts and its outputs. --json prints the whole execution. |
cancel <execution> |
Stop its running steps. |
retry <execution> <step> |
Run a failed step again. |
events send <execution> <name> [key=value…] |
Send the event a wait_event step waits for; the data at most 4 KiB. |
astra anemoi receipts verify#
$ astra anemoi receipts verify <receipt.json> [--jwks jwks.json | --cluster <url>] \
[--prev previous.json] [--node-ca node-ca.pem] [--trace steps.jsonl] [--json]
Checks an agent run's receipt offline: format, machine signature,
machine certificate, countersignature, chain, trace. What is not
given is skipped. Prints each check and verified or NOT verified; exit
status 1 when a check failed. astra anemoi receipt verify is the same.
See Verify a receipt.
| Flag | Description |
|---|---|
--jwks <file> |
The cluster's JWKS (GET $WS/identity/jwks), saved. |
--cluster <url> |
Fetch the JWKS from <url>/v1/identity/jwks instead. Not with --jwks. |
--prev <file> |
The agent's previous receipt. |
--node-ca <file> |
The node CA, PEM. |
--trace <file> |
The exported steps (trace?canonical=1&format=jsonl, or the json export). |
--json |
{ok, receipt_digest, checks}. |
astra evidence verify#
Checks an evidence pack offline: its manifest, its signature, and every
file's SHA-256 (files). Without --jwks or --cluster, the pack's own
jwks.json is used: that shows the pack is whole, not that it is the
cluster's. Exit status 1 when a check failed; --json prints {ok,
checks, manifest}. See Export an evidence pack.