4 min read
CLI reference
The commands you need for everyday protection, recovery and account management.
On this page
Everyday commands
| Command | What it does |
|---|---|
| leash init | Create private local configuration |
| leash start | Start proxy, sync and enrolled-device command polling |
| leash run --cap 5 -- claude | Run an attributed, capped agent session |
| leash status --json | Read local sessions, spend and pending alerts |
| leash kill SESSION_ID / --all | Kill a session or activate panic |
| leash resume SESSION_ID --add 2 | Resume and explicitly add $2 to the session cap |
| leash resume --all | Clear panic; individual kills remain |
| leash doctor | Check local configuration and reachability |
Accounts and transport
| Command | What it does |
|---|---|
| leash login --api URL | Browser-approved device-code login |
| leash whoami / logout | Inspect or revoke human CLI identity |
| leash device register --name laptop | Enroll a fresh ledger using owner/admin access |
| leash device connect --api URL --token-file FILE | Import a one-time device token |
| leash device list / revoke ID | Inspect or revoke registered devices |
| leash sync --device | Sync over device HTTPS, never DATABASE_URL |
| leash agent --once | One poll/execute/ack cycle |
| leash gateway connect --url URL --key-file FILE | Connect proxy to the hosted gateway |
| leash gateway disconnect | Remove gateway enrollment; restart required |
Analysis and recovery
| Command | What it does |
|---|---|
| leash report --json | Parse Claude/Codex logs and emit an estimated report |
| leash report --output DIR | Write private HTML/PNG report artifacts |
| leash handoff [SESSION_ID] | Assess conversation and create a private HANDOFF.md |
| leash handoff --json | Inspect recommendation without writing a file |
| leash reconcile ID --cost USD | Reconcile a crash reservation; proxy must be stopped |
| leash install claude-code / codex | Back up and configure agent |
| leash uninstall claude-code / codex | Restore saved configuration |
Configuration and files
LEASH_HOME defaults to ~/.leash. Use a separate directory for independent machines or transport modes. LEASH_PORT defaults to 8787. The CLI does not automatically load an arbitrary .env file: explicitly select a trusted file with LEASH_ENV_FILE if needed.
config.toml contains local policy and optional model pricing overrides. Credential files are private; do not commit them. Proxy changes require a restart. Use each command's --help for the installed version's complete flag list.
leash --help
leash run --help
leash device --help
leash handoff --helpSomething unclear?Help us improve this guide