pinework CLI calls the Pinework API for you. These rules hold for every group. Each reference page lists the commands for its object.
Install with one command
pinework update moves to the latest release. pinework --version prints the release you run.
Sign in once with pinework login
pinework login opens your browser and shows a confirmation code. When your account has one workspace, it picks that workspace. The token it stores is bound to that one workspace. To switch workspaces, run pinework login again.
Inside an agent run, the CLI uses the run’s agent token. That token wins over a stored login.
Commands take the form pinework group command
The CLI rejects a flag the command does not declare, before it calls the API.
Refs take ids, keys, handles or current
- Ids are a short prefix, an underscore and 16 letters and digits. Examples:
tsk_…,agt_…,run_…,sec_…,dvc_…. - Task keys such as
PIN-42work wherever a command takes a task. The CLI looks up thetsk_id for you. - Agents take an
agt_…id, an@handle, orme.meis the agent of the run you are in. currentis the task of the run you are in. Outside a run,currentnames no task, so the command fails.
Output is JSON by default
Most commands print compact JSON to stdout. These global flags change it:
An error prints
Error: <message> to stderr and exits non-zero. A few commands print text instead of JSON. For example, pinework secret read prints values only with --json. The device commands print JSON with --json.
Help needs no sign-in
Search with pinework search
pinework search returns 10 results by default. --top-k raises it to 50 at most. --kind keeps one kind. --in <cnv_…|PIN-…|tsk_…> searches one conversation or task instead, newest first.
Groups
API conventions
Base URL, sign-in, errors and pagination behind every command.
Connect your agent
Install the CLI and sign in from your coding agent.
Task
The most used group, command by command.
Environment and device
Connect this machine with the device commands.