Skip to content

CLI#

astra anemoi manages flows and checks receipts from a terminal; astra evidence verify checks evidence packs. The flows commands work in the organisation, workspace and cluster you chose with astra use (Install the CLI), as you; the verify commands need only files.

$ astra login
$ astra use acme/research@main
$ astra anemoi flows apply -f nightly-digest.yaml
$ astra anemoi flows run nightly-digest --input day=2026-09-30 --wait
$ astra anemoi receipts verify run.receipt.json --jwks jwks.json
$ astra evidence verify q3-2026.zip --jwks jwks.json

Agents from the CLI

astra has no commands to create, change or run agents, decide approvals, or manage budgets, guardrails, evaluations or the marketplace yet: use the console or the API. Agent runs are runs, so astra astraeus status, logs and delete work on them.

astra anemoi flows#

Command Description
apply -f <file> Create the flow from a YAML or JSON file, or write its next version. --no-current writes it without making it current. Runs the cluster's checks on the file first. Prints flow <name>: version <n> written, now current.
validate -f <file> Check the file here, without sending it: shape, step ids, the graph, each kind's fields, the names expressions use. --remote also asks the cluster, which checks that the agents, flows and drives named exist. Works signed out without --remote. Exit status 1 with problems.
list FLOW CURRENT LATEST AGE.
run <flow> Start an execution. -i, --input key=value (repeatable); --version <n>; --wait follows it until it ends, prints its steps, and exits 1 unless it Succeeded.
executions EXECUTION FLOW VERSION STATE STEPS WHY AGE, newest first. --flow <name> for one flow's.
get <execution> Its state, then STEP STATE ATTEMPTS LAST MACHINE WHY OUTPUTS, its agent runs' receipts and its outputs. --json prints the whole execution.
cancel <execution> Stop its running steps.
retry <execution> <step> Run a failed step again.
events send <execution> <name> [key=value…] Send the event a wait_event step waits for; the data at most 4 KiB.

astra anemoi receipts verify#

$ astra anemoi receipts verify <receipt.json> [--jwks jwks.json | --cluster <url>] \
    [--prev previous.json] [--node-ca node-ca.pem] [--trace steps.jsonl] [--json]

Checks an agent run's receipt offline: format, machine signature, machine certificate, countersignature, chain, trace. What is not given is skipped. Prints each check and verified or NOT verified; exit status 1 when a check failed. astra anemoi receipt verify is the same. See Verify a receipt.

Flag Description
--jwks <file> The cluster's JWKS (GET $WS/identity/jwks), saved.
--cluster <url> Fetch the JWKS from <url>/v1/identity/jwks instead. Not with --jwks.
--prev <file> The agent's previous receipt.
--node-ca <file> The node CA, PEM.
--trace <file> The exported steps (trace?canonical=1&format=jsonl, or the json export).
--json {ok, receipt_digest, checks}.

astra evidence verify#

$ astra evidence verify <pack.zip> [--jwks jwks.json | --cluster <url>] [--json]

Checks an evidence pack offline: its manifest, its signature, and every file's SHA-256 (files). Without --jwks or --cluster, the pack's own jwks.json is used: that shows the pack is whole, not that it is the cluster's. Exit status 1 when a check failed; --json prints {ok, checks, manifest}. See Export an evidence pack.