OpenClaw EnterpriseDOCSGitHub

OCC CLI command reference

occ manages OpenClaw Control Plane (OCC) resources. To install it and make your first request, see CLI setup. To see help for the installed version, run occ --help or add --help to a command.

Global options

Command-line flags override the corresponding environment variables.

Flag Environment variable What it controls
--url OCC_URL Required for resource commands. An HTTP or HTTPS origin, without embedded credentials, a base path, query, or fragment.
--service-key-file OCC_SERVICE_KEY_FILE Required for resource commands. Path to the complete bootstrap or issued service-key JSON response.
--namespace OCC_NAMESPACE Required for configuration, secret, credential-source, iam, and agent commands. Supply the Namespace ID, not its name.
--ca-bundle OCC_CA_BUNDLE Adds a PEM certificate-authority bundle to the system trust roots for HTTPS. TLS verification cannot be disabled.
--timeout-seconds OCC_TIMEOUT_SECONDS Positive whole seconds for an HTTP request. Default: 30.
--output, -o — Output format: table (default), json, or yaml.
--help, -h — Prints help for the command.
--version, -v — Prints the CLI version. Source builds report dev; published binaries report their OCE release version.

The service-key JSON must contain a nonempty data.key with no line breaks. The client sends it as x-api-key and does not follow redirects. Use a trusted HTTPS endpoint unless connecting to a local loopback development Installation. See Service API Keys for issuing or rotating keys.

Pressing Ctrl-C, or sending SIGTERM, cancels an in-flight request and exits with an error instead of waiting for --timeout-seconds to expire.

Resource commands

Replace ID with the corresponding resource ID, NAME with a Namespace name, and FILE with a JSON file path. --file reads a local file, not stdin; YAML input is not supported. The server validates document fields against the HTTP API contract.

Command What it does
occ installation get Reads the singleton Installation.
occ installation deployment-inventory Reads the complete Agent deployment inventory for a coordinated fleet operation.
occ namespace list Lists authorized Namespaces.
occ namespace get ID Reads one Namespace and its status.
occ namespace create NAME Creates a Namespace. --existing-namespace K8S_NAME requests adoption of an operator-prepared Kubernetes namespace and also requires Installation administer.
occ namespace delete ID Begins deleting an empty Namespace. Use namespace get to inspect the resulting state.
occ configuration create --file FILE Creates a Configuration. The body contains kind and values.
occ configuration get ID Reads a Configuration.
occ configuration update ID --file FILE Updates a Configuration; the body must replace values. Omit the create-only kind.
occ configuration delete ID Deletes an unreferenced Configuration.
occ secret create --file FILE Stores a Namespace Secret from a protected JSON document.
occ secret get ID Reads Secret metadata, never its value.
occ secret update ID --file FILE Replaces the Secret value; consumers require explicit redeployment.
occ secret delete ID Deletes an unreferenced Namespace Secret.
occ credential-source create --file FILE Registers a Secret with the selected Credential Gateway. See credential sources.
occ credential-source list Lists credential sources without live gateway status.
occ credential-source get ID Reads a credential source and its live gateway status, never its value.
occ credential-source delete ID Deletes an unreferenced credential source and the gateway's copy.
occ iam role list Lists Namespace Roles.
occ iam role get ID Reads a Namespace Role.
occ iam role create --file FILE Creates a Namespace Role with explicit permissions.
occ iam role delete ID Deletes an unreferenced Namespace Role.
occ iam access-binding list Lists Namespace AccessBindings.
occ iam access-binding get ID Reads a Namespace AccessBinding.
occ iam access-binding create --file FILE Grants a Role to a principal for an exact resource.
occ iam access-binding delete ID Deletes a Namespace AccessBinding.
occ agent delete ID Begins asynchronous Agent deletion, including its owned runtime state.
occ agent list Lists authorized Agents in the selected Namespace.
occ agent get ID Reads an Agent's desired state and active revision.
occ agent create --file FILE Creates an Agent draft.
occ agent update ID --file FILE Updates editable Agent fields; the body must include configurationId.
occ agent deploy ID Requests deployment and creates an immutable revision.
occ agent deployment-status ID DEPLOYMENT_ID Reads the durable status of one exact Agent deployment.
occ agent runtime-credentials get ID Reads whether generated runtime credentials are configured for the Agent.
occ agent runtime-credentials provision ID Creates the initial generated runtime credential bundle (empty request body).
occ agent stop ID Requests a stop while retaining revisions and persistent state.

Use the HTTP API to inspect revision history or to work with ServiceAccounts and configured Backends; the CLI has no commands for these. Neither the CLI nor the HTTP API offers Configuration listing. An accepted deploy returns a revision; agent get shows desired state and the selected revision, not runtime health. Use the deployment status command and verify the model separately.

The installation get, installation deployment-inventory, and namespace list commands require an Installation-scoped service key. With a Namespace-scoped key, use namespace get ID to read that exact Namespace instead.

installation deployment-inventory requires Installation administer, exact read access to every Namespace and Agent, exact read access to each selected Agent's active revision, and exact deploy access to every running Agent that is eligible for coordinated deployment. It fails instead of silently omitting an unauthorized resource. JSON and YAML output include each Agent's desired runtime state, execution mode, active revision, and whether deployment work is queued or claimed.

Output and errors

Table output is meant for people; it prints - for unset fields and No resources found. for an empty list. JSON and YAML print the resource or array without the HTTP envelope. Deleting a Configuration prints Deleted configuration ID. in table mode; structured output contains deleted, kind, and id.

Failures go to stderr and the CLI exits nonzero. For HTTP errors, the CLI prints the status and, when present, the API error code and message. It does not print the server's request ID. To capture that ID for a failed request, use the HTTP API directly.

Local development

Run these from a repository checkout. They use local development configuration, not the remote connection or output options above. Kubernetes is the supported local setup for deploying an Agent; follow Local Setup.

Command What it does
occ dev up Starts the profile selected by OCC_DEVELOPMENT_COMPUTE_DRIVER: docker (default) or kubernetes. Docker is a control-plane preview and cannot deploy Agents.
occ dev up --key-output PATH Writes the bootstrap service-key file to an absent absolute path in a private directory.
occ dev down Stops the selected profile. Docker keeps Compose volumes by default. Kubernetes removes its owned k3d cluster; the Compose control-plane profile also removes Compose volumes.
occ dev down --volumes Also removes Docker Compose volumes; Kubernetes cleanup already removes its volumes.

Compose global options, when needed, must follow --. Keep the cleanup command printed by startup so it selects the same profile and state directory. The explicitly selected Kubernetes-only profile rejects Compose options. Use scripts/dev-up and scripts/dev-down as the common entry points for every profile; the Compute and Sandbox Driver settings select the implementation.

Search documentation