doax is the executor for the doax registry: it resolves resources, verifies package
integrity, runs the authentication tier a resource demands, invokes it, and records every access
in the audit log.
Linux or macOS with Node.js ≥ 20 and curl. Nothing else — the CLI is a single self-contained file.
$ curl -fsSL https://doax.io/install.sh | bash
The script downloads https://doax.io/cli/doax.mjs into ~/.doax/lib/ and puts a doax launcher in ~/.local/bin (override with DOAX_BIN). It tells you if ~/.local/bin is missing from your PATH.
Prefer to read before you run? View install.sh. Manual equivalent:
$ curl -fsSL https://doax.io/cli/doax.mjs -o ~/.doax/lib/doax.mjs $ node ~/.doax/lib/doax.mjs --version
$ doax status # { "registry": "https://registry.doax.io", "reachable": true, ... }
# find something to use $ doax search slack # read a Slack channel — the CLI asks for your Slack token in context, # with the link to obtain one, then caches it for every Slack resource $ doax read @doax/slack-channel-history --param channel=C0123456789 # preview an action without side effects, then run it $ doax execute @doax/slack-post --param channel=C0123456789 --param text="hello from doax" --dry-run $ doax execute @doax/slack-post --param channel=C0123456789 --param text="hello from doax" # see or drop cached credentials $ doax auth list $ doax auth purge --all
Every command runs without a TTY. Agents get structured output and machine-actionable errors instead of prompts:
$ doax read @doax/slack-channel-history --param channel=C01 --json --no-input # on missing auth: {"ok":false,"faultClass":"credential-missing", # "willRequireInteraction":true,"fix":"re-run with --secret <value>, ..."} $ doax read @doax/slack-channel-history --param channel=C01 --secret xoxb-... --json
| flag | effect |
|---|---|
--json | single JSON object on stdout/stderr; errors carry faultClass and a fix |
--no-input | never prompt (also DOAX_NO_INPUT=1; non-TTY stdin never prompts) |
--secret | supply the authenticator secret inline |
--yes | grant tier-2 per-call authorization |
$ doax login --email you@example.com # a 6-digit code arrives by mail; enter it (or re-run with --code 123456) $ doax whoami
Proof of your inbox is your identity — no password, no account form. Signing in lets you claim a namespace (POST /namespaces), publish into it, publish to the shared @global namespace, and query the audit trail of your own namespaces with doax audit.
$ doax publish my-resource.manifest.json my-resource.mjs # @global accepts anyone signed in; your own @namespace needs the owner/publisher role
The CLI holds a list of registries and resolves each resource from the one that owns its namespace — the npm scoped-registry model:
$ doax registry add @mate https://kachit.ai/registry $ doax read @mate/orders --param since=2026-01-01 # @mate/* resolves at kachit.ai; everything else at registry.doax.io $ doax registry list
Unrouted namespaces use the default registry (doax registry add default <url>, or DOAX_REGISTRY). Audit events for a resource are delivered to the registry it came from, so a company's own usage lands in its own audit log.
$ rm -rf ~/.doax ~/.local/bin/doax
~/.doax also holds your cached credentials and the package cache; removing it removes them.