Install
- macOS and Linux
- Windows
forge on the command
path. macOS and Linux use /usr/local/bin when writable and otherwise use
~/.local/bin. Run the stable-channel installer again to update to its current
release. forge version verifies the installed version after installation or
an update.
Authenticate
Interactive login uses OAuth device authorization and discovers the organization bound to the resulting token:invalid_scope or invalid_client, first update the CLI and
retry without OAuth override environment variables. Forge API permissions are
assigned by your organization; they are not values for --scopes. Custom
enterprise OAuth clients must have device authorization enabled by their
administrator.
Use a service-account token for CI or another non-interactive environment:
forge auth login --token "$FORGE_TOKEN". Avoid doing so on ephemeral CI
runners; environment injection keeps the credential out of a persisted profile.
Configuration
Values resolve in this order, from highest to lowest precedence:- Global command flags.
- Environment variables.
- The selected saved profile.
- Built-in defaults.
JSON is the default command output. The deliberate exception is
forge resources token, which prints only the short-lived token so it can be used in
a client command without parsing. Add --json to that command when structured
output and the expiry time are needed.
Profiles isolate organizations or environments:
Global flags
Global flags must appear before the command group:
Command-local safety flags override neither authorization nor policy. Forge
still validates the actor’s role, token scopes, organization settings, and the
operation contract.
Exit behavior
Successful commands write JSON to stdout except for the resource-token command
described above. Errors and usage text are written to stderr. The CLI does not
retry API requests automatically; automation should apply the retry rules
described in the API guide.
Connect to a Resource
Mint a five-minute direct-access token for one Resource by ID, exact name, or access name:resources:connect scope and the
headless direct-access API.
Guarded execution
Preview a supported write, review the JSON response, then execute with the same reason and idempotency key:CI
Uninstall
--purge only when the local Forge credential store should also be removed.
Commands
Review command syntax, filters, and mutation safeguards.
API
Implement retries and inspect the underlying REST contracts.
MCP
Install governed MCP servers and manage MCP sessions.
Roles
Configure permissions for operators and service accounts.