doax

Install the doax CLI

doax is the executor for the doax registry: it resolves resources, verifies package integrity, runs the authentication tier a resource demands, invokes it, and records every access in the audit log.

Requirements

Linux or macOS with Node.js ≥ 20 and curl. Nothing else — the CLI is a single self-contained file.

Install

$ curl -fsSL https://doax.io/install.sh | bash

The script downloads https://doax.io/cli/doax.mjs into ~/.doax/lib/ and puts a doax launcher in ~/.local/bin (override with DOAX_BIN). It tells you if ~/.local/bin is missing from your PATH.

Prefer to read before you run? View install.sh. Manual equivalent:

$ curl -fsSL https://doax.io/cli/doax.mjs -o ~/.doax/lib/doax.mjs
$ node ~/.doax/lib/doax.mjs --version

Verify

$ doax status
# { "registry": "https://registry.doax.io", "reachable": true, ... }

First five minutes

# find something to use
$ doax search slack

# read a Slack channel — the CLI asks for your Slack token in context,
# with the link to obtain one, then caches it for every Slack resource
$ doax read @doax/slack-channel-history --param channel=C0123456789

# preview an action without side effects, then run it
$ doax execute @doax/slack-post --param channel=C0123456789 --param text="hello from doax" --dry-run
$ doax execute @doax/slack-post --param channel=C0123456789 --param text="hello from doax"

# see or drop cached credentials
$ doax auth list
$ doax auth purge --all

For agents (non-interactive)

Every command runs without a TTY. Agents get structured output and machine-actionable errors instead of prompts:

$ doax read @doax/slack-channel-history --param channel=C01 --json --no-input
# on missing auth: {"ok":false,"faultClass":"credential-missing",
#   "willRequireInteraction":true,"fix":"re-run with --secret <value>, ..."}
$ doax read @doax/slack-channel-history --param channel=C01 --secret xoxb-... --json
flageffect
--jsonsingle JSON object on stdout/stderr; errors carry faultClass and a fix
--no-inputnever prompt (also DOAX_NO_INPUT=1; non-TTY stdin never prompts)
--secretsupply the authenticator secret inline
--yesgrant tier-2 per-call authorization

Sign in

$ doax login --email you@example.com
# a 6-digit code arrives by mail; enter it (or re-run with --code 123456)
$ doax whoami

Proof of your inbox is your identity — no password, no account form. Signing in lets you claim a namespace (POST /namespaces), publish into it, publish to the shared @global namespace, and query the audit trail of your own namespaces with doax audit.

Publish a resource

$ doax publish my-resource.manifest.json my-resource.mjs
# @global accepts anyone signed in; your own @namespace needs the owner/publisher role

Private registries

The CLI holds a list of registries and resolves each resource from the one that owns its namespace — the npm scoped-registry model:

$ doax registry add @mate https://kachit.ai/registry
$ doax read @mate/orders --param since=2026-01-01
# @mate/* resolves at kachit.ai; everything else at registry.doax.io
$ doax registry list

Unrouted namespaces use the default registry (doax registry add default <url>, or DOAX_REGISTRY). Audit events for a resource are delivered to the registry it came from, so a company's own usage lands in its own audit log.

Uninstall

$ rm -rf ~/.doax ~/.local/bin/doax

~/.doax also holds your cached credentials and the package cache; removing it removes them.