Tork CLI Reference
Authenticate, wire the Tork SDK into a project, send governed test requests, and read receipts and usage from the terminal. Every command supports --json for scripts, CI and AI agents.
What is published, and what is not
The Tork CLI is the npm package @torknetwork/cli (Node.js 20+), with the eight commands listed below. An earlier version of this page documented a Python CLI installed by pip install tork-governance with tork scan, tork policy, MCP configuration scanning, SARIF output, custom security rules and batch scanning. None of that is published: the PyPI package ships no command-line entry point, and the npm CLI has no scan or policy command. Those sections were removed on 24 September 2026.
Installation
Run with npx, install globally with npm, or use Homebrew.
Requires Node.js 20 or newer. The Homebrew formula installs the same npm package.
Four commands to a governed request
The full walkthrough is on the CLI quickstart page.
Step-by-step, with expected output: CLI Quickstart.
Available Commands
tork --help and tork --version are also available.
tork login
Authenticate the CLI with your Tork API key.
| --key <key> | API key (skips the interactive prompt, for non-interactive use) |
| --op <ref> | Read the key from 1Password via `op read` (e.g. op://Vault/Item/field). Cannot be combined with --key |
| --json | Machine-readable result |
The key is validated live against the API before it is stored in ~/.tork/config.json (created with 600 permissions).
tork init
Set up Tork Governance in the current project (SDK install + tork.config.json).
| --lang node|python | Skip stack detection |
| --mode cloud|local | cloud = governance via tork.network (receipts + dashboard, needs an API key); local = on-device PII detection only (no key, dashboard stays empty) |
| -y, --yes | Skip prompts (defaults to Node and cloud mode when unspecified) |
| --json | Machine-readable result |
Cloud mode installs @torknetwork/sdk (Node only). Local mode installs tork-governance from npm or PyPI. Python is local-only in the CLI: the PyPI package makes every governance decision on-device, so --mode cloud --lang python exits 1 with guidance. An existing tork.config.json is never overwritten.
Supply an API key and the SDK additionally reports a metadata-only attestation of each decision — the action taken, PII type labels and counts, a risk classification, policy labels and a salted fingerprint. It never sends input text, output text or PII values. The decision itself is still made on-device and is never delayed or changed by reporting. Those attestations appear in your dashboard and are included in the daily on-chain anchor — each one recorded as a client attestation (capture_mode=edge, attested_by=client), a claim Tork recorded but did not execute and cannot independently verify. Requires tork-governance 0.24.0+ (PyPI) or 0.11.0+ (npm). A decision reported by an on-device SDK is recorded as a client attestation (capture_mode=edge, attested_by=client): a claim Tork recorded but did not execute and cannot independently verify. A decision made by @torknetwork/sdk is recorded as capture_mode=cloud, attested_by=tork — Tork made that call itself. Both are equally immutable once anchored; they differ in what is immutable. A client attestation freezes your claim. A server-governed receipt freezes Tork's own decision.
tork test
Send a synthetic governed request through /api/v1/govern and report the decision.
| --content <text> | Custom content to govern instead of the synthetic sample |
| --json | Full response, decision and latency as JSON |
Uses agent_id, agent_role and session_tracking from tork.config.json when present. Exits 0 on any valid governance decision, 1 with a diagnostic otherwise.
tork doctor
Diagnose your Tork setup: config, key, connectivity, API health, project wiring.
| --json | {checks: [...], summary: {...}} for CI and AI agents |
Checks, in order
- Config file exists with 600 permissions
- API key present and format-valid
- DNS + TLS reachability of the base URL
- /api/v1/health reports healthy
- Key accepted by the server
- tork.config.json present in the current directory (warn only)
- Tork SDK installed in the project — tork-governance (local) or @torknetwork/sdk (cloud), with version (warn only)
- Node.js version 20 or newer
Ends with N passed, N warnings, N failed and exits 1 if anything failed.
tork logs
Show recent governance decisions for your org (backed by the receipts feed).
| --limit <n> | Number of decisions to show (default 20, minimum 1) |
| --follow | Poll for new decisions every 5s (Ctrl+C to stop). Cannot be combined with --json |
| --json | Machine-readable entries |
Each line shows time, action (allow, redact, deny or escalate), PII count, latency and receipt id.
tork receipts
List governance receipts, or fetch and verify one by id.
| [receipt_id] | Optional argument: fetch and verify a single receipt by id |
| --limit <n> | Number of receipts to list (default 20, minimum 1) |
| --json | Full receipt / verification result as JSON |
The single-receipt view shows the receipt id, timestamp, action, PII counts, policy version, content hash, fingerprint, governance DNA and whether a signature is present. When the receipt exposes a fingerprint it is checked against the server's Merkle anchor via POST /api/v1/verify (exit 1 on failure). When it does not, you get a local structure check only — field presence and hash-format sanity, never claimed as cryptographic verification.
tork usage
Show plan usage for the authenticated org (calls used / limit / remaining).
| --json | Raw API response plus the normalised summary |
tork whoami
Show the active key (masked), org (live-verified), base URL and config path.
| --json | Machine-readable result |
When the server cannot be reached the stored org is printed suffixed (cached — could not verify: reason); when the server rejects the key the command exits 1, so scripts never mistake a cached identity for a live one.
Environment variables
Override the stored key, base URL and config directory.
CI usage
Run doctor and test on every pipeline with the key from your secrets store.
With TORK_API_KEY set in the environment nothing is written to disk. Set NO_COLOR=1 or use --json if ANSI colour codes break your log parsing.
Next Steps
Walk through the four-command setup, then wire the SDK into your code.