Docs/CLI Reference
@torknetwork/cli 0.3.0

Tork CLI Reference

Authenticate, wire the Tork SDK into a project, send governed test requests, and read receipts and usage from the terminal. Every command supports --json for scripts, CI and AI agents.

What is published, and what is not

The Tork CLI is the npm package @torknetwork/cli (Node.js 20+), with the eight commands listed below. An earlier version of this page documented a Python CLI installed by pip install tork-governance with tork scan, tork policy, MCP configuration scanning, SARIF output, custom security rules and batch scanning. None of that is published: the PyPI package ships no command-line entry point, and the npm CLI has no scan or policy command. Those sections were removed on 24 September 2026.

Installation

Run with npx, install globally with npm, or use Homebrew.

bash
# Run without installing (Node.js 20 or newer)
npx @torknetwork/cli --help

# Or install globally
npm install -g @torknetwork/cli

# Or via Homebrew (wraps the same npm package)
brew install torkjacobs/tap/tork

# Check the installed version
tork --version

Requires Node.js 20 or newer. The Homebrew formula installs the same npm package.

Four commands to a governed request

The full walkthrough is on the CLI quickstart page.

bash
tork login    # 1. authenticate with your tork_ API key
tork init     # 2. install the SDK + write tork.config.json in your project
tork test     # 3. send a synthetic governed request end to end
tork doctor   # 4. verify the whole setup

Step-by-step, with expected output: CLI Quickstart.

Available Commands

CommandDescription
tork loginAuthenticate the CLI with your Tork API key
tork initSet up Tork Governance in the current project (SDK install + tork.config.json)
tork testSend a synthetic governed request through /api/v1/govern and report the decision
tork doctorDiagnose your Tork setup: config, key, connectivity, API health, project wiring
tork logsShow recent governance decisions for your org (backed by the receipts feed)
tork receiptsList governance receipts, or fetch and verify one by id
tork usageShow plan usage for the authenticated org (calls used / limit / remaining)
tork whoamiShow the active key (masked), org (live-verified), base URL and config path

tork --help and tork --version are also available.

tork login

Authenticate the CLI with your Tork API key.

--key <key>API key (skips the interactive prompt, for non-interactive use)
--op <ref>Read the key from 1Password via `op read` (e.g. op://Vault/Item/field). Cannot be combined with --key
--jsonMachine-readable result
bash
# Interactive: prompts for the key with masked input,
# validates it live against the API, stores it in ~/.tork/config.json (mode 600)
tork login

# Non-interactive (CI, scripts)
tork login --key tork_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxx

# Read the key from 1Password (requires the op CLI; the key is never printed)
tork login --op "op://Vault/Tork/api_key"

# Machine-readable result
tork login --key "$TORK_API_KEY" --json

The key is validated live against the API before it is stored in ~/.tork/config.json (created with 600 permissions).

tork init

Set up Tork Governance in the current project (SDK install + tork.config.json).

--lang node|pythonSkip stack detection
--mode cloud|localcloud = governance via tork.network (receipts + dashboard, needs an API key); local = on-device PII detection only (no key, dashboard stays empty)
-y, --yesSkip prompts (defaults to Node and cloud mode when unspecified)
--jsonMachine-readable result
bash
# Detects your stack (package.json -> Node, requirements.txt / pyproject.toml -> Python),
# asks how you want to govern, installs the matching SDK and writes tork.config.json
tork init

# Skip stack detection
tork init --lang node
tork init --lang python

# Skip the governance-mode prompt
#   cloud = governance via tork.network (receipts + dashboard, needs an API key; Node only)
#   local = on-device PII detection only (no key; the dashboard stays empty)
tork init --mode cloud
tork init --mode local

# Skip every prompt (defaults to Node and cloud mode when unspecified)
tork init --yes

Cloud mode installs @torknetwork/sdk (Node only). Local mode installs tork-governance from npm or PyPI. Python is local-only in the CLI: the PyPI package makes every governance decision on-device, so --mode cloud --lang python exits 1 with guidance. An existing tork.config.json is never overwritten.

Supply an API key and the SDK additionally reports a metadata-only attestation of each decision — the action taken, PII type labels and counts, a risk classification, policy labels and a salted fingerprint. It never sends input text, output text or PII values. The decision itself is still made on-device and is never delayed or changed by reporting. Those attestations appear in your dashboard and are included in the daily on-chain anchor — each one recorded as a client attestation (capture_mode=edge, attested_by=client), a claim Tork recorded but did not execute and cannot independently verify. Requires tork-governance 0.24.0+ (PyPI) or 0.11.0+ (npm). A decision reported by an on-device SDK is recorded as a client attestation (capture_mode=edge, attested_by=client): a claim Tork recorded but did not execute and cannot independently verify. A decision made by @torknetwork/sdk is recorded as capture_mode=cloud, attested_by=tork — Tork made that call itself. Both are equally immutable once anchored; they differ in what is immutable. A client attestation freezes your claim. A server-governed receipt freezes Tork's own decision.

jsontork.config.json
{
  "org_id": "",
  "agent_id": "default-agent",
  "agent_role": "assistant",
  "session_tracking": true,
  "base_url": "https://tork.network"
}

tork test

Send a synthetic governed request through /api/v1/govern and report the decision.

--content <text>Custom content to govern instead of the synthetic sample
--jsonFull response, decision and latency as JSON
bash
# Sends a synthetic payload (fake SSN + fake email, never real data)
# through POST https://tork.network/api/v1/govern
tork test

# Govern your own content instead of the synthetic sample
tork test --content "Customer card number is 4111 1111 1111 1111"

# Full response, decision and latency as JSON
tork test --json

Uses agent_id, agent_role and session_tracking from tork.config.json when present. Exits 0 on any valid governance decision, 1 with a diagnostic otherwise.

tork doctor

Diagnose your Tork setup: config, key, connectivity, API health, project wiring.

--json{checks: [...], summary: {...}} for CI and AI agents
bash
# Runs every setup check and keeps going through failures.
# Exits 1 if anything failed.
tork doctor

# {checks: [...], summary: {...}} for CI and AI agents
tork doctor --json

Checks, in order

  1. Config file exists with 600 permissions
  2. API key present and format-valid
  3. DNS + TLS reachability of the base URL
  4. /api/v1/health reports healthy
  5. Key accepted by the server
  6. tork.config.json present in the current directory (warn only)
  7. Tork SDK installed in the project — tork-governance (local) or @torknetwork/sdk (cloud), with version (warn only)
  8. Node.js version 20 or newer

Ends with N passed, N warnings, N failed and exits 1 if anything failed.

tork logs

Show recent governance decisions for your org (backed by the receipts feed).

--limit <n>Number of decisions to show (default 20, minimum 1)
--followPoll for new decisions every 5s (Ctrl+C to stop). Cannot be combined with --json
--jsonMachine-readable entries
bash
# Recent governance decisions for your org (backed by GET /api/v1/receipts).
# Oldest first, so the latest decision is at the bottom.
tork logs

# Show more decisions (default 20)
tork logs --limit 50

# Poll every 5 seconds and print new decisions as they arrive (Ctrl+C to stop).
# --follow cannot be combined with --json.
tork logs --follow

# Machine-readable entries
tork logs --json

Each line shows time, action (allow, redact, deny or escalate), PII count, latency and receipt id.

tork receipts

List governance receipts, or fetch and verify one by id.

[receipt_id]Optional argument: fetch and verify a single receipt by id
--limit <n>Number of receipts to list (default 20, minimum 1)
--jsonFull receipt / verification result as JSON
bash
# List recent receipts (default 20)
tork receipts
tork receipts --limit 50

# Fetch one receipt by id and verify it
tork receipts tork_rcpt_xxx

# Full receipt / verification result as JSON
tork receipts tork_rcpt_xxx --json

The single-receipt view shows the receipt id, timestamp, action, PII counts, policy version, content hash, fingerprint, governance DNA and whether a signature is present. When the receipt exposes a fingerprint it is checked against the server's Merkle anchor via POST /api/v1/verify (exit 1 on failure). When it does not, you get a local structure check only — field presence and hash-format sanity, never claimed as cryptographic verification.

tork usage

Show plan usage for the authenticated org (calls used / limit / remaining).

--jsonRaw API response plus the normalised summary
bash
# Plan usage for the authenticated org, from GET /api/v1/usage:
# plan name, usage bar, calls used / limit, calls remaining, billing period.
# Warns at 80% of the limit and again at 100%.
tork usage

# Raw API response plus the normalised summary
tork usage --json

tork whoami

Show the active key (masked), org (live-verified), base URL and config path.

--jsonMachine-readable result
bash
# Active key (masked to tork_****last4), org, base URL and config path.
# The org is checked live; if the server rejects the key the command exits 1.
tork whoami
tork whoami --json

When the server cannot be reached the stored org is printed suffixed (cached — could not verify: reason); when the server rejects the key the command exits 1, so scripts never mistake a cached identity for a live one.

Environment variables

Override the stored key, base URL and config directory.

bash
# Overrides the stored key — nothing is written to disk (ideal for CI)
export TORK_API_KEY=tork_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxx

# Overrides the API base URL (default https://tork.network)
export TORK_BASE_URL=https://tork.network

# Overrides ~/.tork (tests / sandboxes)
export TORK_CONFIG_DIR=/tmp/tork-ci

# Disables coloured output
export NO_COLOR=1

CI usage

Run doctor and test on every pipeline with the key from your secrets store.

yaml.github/workflows/governance-check.yml
# .github/workflows/governance-check.yml
jobs:
  governance:
    runs-on: ubuntu-latest
    env:
      TORK_API_KEY: ${{ secrets.TORK_API_KEY }}
    steps:
      - uses: actions/checkout@v4
      - uses: actions/setup-node@v4
        with: {node-version: 20}
      - run: npx @torknetwork/cli doctor --json
      - run: npx @torknetwork/cli test --json

With TORK_API_KEY set in the environment nothing is written to disk. Set NO_COLOR=1 or use --json if ANSI colour codes break your log parsing.

Next Steps

Walk through the four-command setup, then wire the SDK into your code.

Documentation

Learn to integrate TORK

Upgrade Plan

Current: free

Support

Get help from our team