Fullsend CLI
The fullsend CLI manages the complete fullsend lifecycle: provisioning GCP infrastructure, configuring GitHub, enrolling repositories, and running agents locally.
Installation
Download the latest binary from GitHub Releases. For detailed setup instructions, see Getting Started.
Command groups
| Command group | Description |
|---|---|
fullsend agent | Generate a custom agent and manage agent registrations — new, add, list, set, update, remove |
fullsend github | Configure GitHub repos — setup and single-value config updates |
fullsend inference | Manage inference credentials — GCP Workload Identity Federation for Agent Platform, and OpenAI WIF enrolment for GPT on pi or codex |
fullsend mint | Deploy and manage the OIDC token mint service |
fullsend repos | Manage per-repo installations at scale via declarative manifest |
Additional commands
| Command | Description |
|---|---|
fullsend run | Execute an agent locally in a sandbox. See running agents locally. |
fullsend poll | Discover forge events and dispatch agent pipelines. --forge gitlab runs the cron poller (ADR 0067). --input-driver jira-poll polls Jira (see Jira integration). --input-driver gitlab-webhook is the GitLab dispatcher job's webhook fast-path (ADR 0125). It reads the native webhook body from the file-type TRIGGER_PAYLOAD variable, re-validates it against the GitLab API, and creates each routed stage's pipeline (typed inputs, FULLSEND_DISPATCH_SECRET HMAC) with the poller-role credential. It requires --project, which has no CI_PROJECT_PATH fallback. It deduplicates against the poller's per-mode state on the fullsend-poll-state-slash and fullsend-poll-state-events branches, so an event the webhook dispatched is not dispatched again by the poller, and the reverse. Shared poller state is occurrence-aware (label additions are keyed on the resource label event ID, dispatched keys are retained for the webhook freshness window, and a failed label dispatch is handed back to the poller as a pending retry); legacy persisted keys keep working. Older pollers do not recognise the new label keys, so before a rollback or mixed-version run, follow the ADR 0132 guidance to drain in-flight poll jobs or pin every poller to one version. |
fullsend lock [agent-name] | Pin remote dependencies to lock.yaml |
fullsend scan | Run security scanners on agent input/output |
fullsend eval-measure | Score wild-run traces into eval-measurements.jsonl. See Eval measurements. |
Global flags
All commands that interact with GitHub resolve authentication via GH_TOKEN, GITHUB_TOKEN, or gh auth token (in that order). Explicit token flags such as --token and --forge-token override the chain. For GitLab, set GITLAB_TOKEN or pass --gitlab-token to repos subcommands. The CLI runs preflight checks and tells you exactly which OAuth scopes are missing before making any changes.
For the complete command tree with implementation details, see CLI internals.
