Docs CLI Command Reference

CLI command reference

This is the full, organised list of mockarty-cli subcommands. The CLI
groups commands into four “categories” plus a small auth/state cluster.
Use this page when you know roughly what you want to do but don’t
remember the exact verb. For interactive help, run any command with
--help.

The categories are visible in mockarty-cli --help:

  • Cat 1 — Utilities. Pure local helpers (free in every mode).
  • Cat 2 — Install. Setup and lifecycle of the Mockarty installation.
  • Cat 3 — Test runners. The licence-gated workhorses.
  • Cat 4 — TUI. Interactive terminal UI.
  • Auth & state. Login, config, namespace, tokens.

Most commands accept these global flags:

Flag Meaning
--server URL Override Mockarty server URL
--token TOKEN Override API token
--namespace NS Active namespace
--insecure Skip TLS verification (lab use only)
--output FMT table (default), json, wide, quiet
--no-color Disable colored output
--help Show command help

Layered LLM security

mockarty-cli llm-security manages the prompt-injection policy for the active
namespace. The active namespace comes from --namespace, the environment, or
the saved login context, in that order.

Command Purpose
llm-security get Read the local patch, effective policy and provenance.
llm-security events --limit 100 List metadata-only security decisions.
llm-security preview --document policy.json --expected-revision N Validate a draft without saving.
llm-security test --text TEXT Inspect untrusted sample text locally.
llm-security set --document policy.json --expected-revision N Save a revision-fenced policy patch.

Add --installation to get, set, or events for the system-admin view.
See LLM Guardrails for policy examples and access rules.

mockarty-cli connections — immutable external connections

These commands use the configured server, token, and concrete namespace. Descriptor files contain exact secret references, never raw credentials. See Connection Authority.

Command Purpose
connections create --file descriptor.json Create revision 1.
connections get CONNECTION_ID Read the current immutable revision.
connections advance CONNECTION_ID --revision N --file descriptor.json Publish exactly revision N+1.
connections revoke CONNECTION_ID --revision N Revoke exact current revision N.

Cat 1 — Utilities

Free in every mode. No server, no token required.

mockarty-cli ci — CI helpers

Command Purpose
ci run-suite <suite.yaml> Run a CI test suite from a YAML manifest.

mockarty-cli generate — code generation

Command Purpose
generate openapi <spec> Generate mocks from OpenAPI spec.
generate grpc <proto> Generate gRPC server from .proto file.
generate soap <wsdl> Generate SOAP server from WSDL.
generate graphql <schema> Generate GraphQL server from schema.
generate mcp <manifest> Generate MCP server from manifest.
generate har <file> Generate mocks from HAR archive.
generate postman <file> Generate mocks from Postman collection.
generate spec Build an OpenAPI/AsyncAPI document FROM the mocks already on the server.

generate spec runs every other generator backwards: the input is always the
mocks the namespace already has, so it takes no file. The document goes to stdout
and the warnings — the mocks a specification cannot express — go to stderr, so
mockarty-cli generate spec --format openapi > openapi.json writes a file a
consumer can parse. Use --format asyncapi for Kafka/RabbitMQ/NATS/socket/SMTP
mocks, --tags/--folder to narrow the set, and --out to write to a file.

mockarty-cli serve — embedded mini-server

Boot a standalone mock server (HTTP, REST, gRPC) without talking to an
admin node. See Quick start for examples.

mockarty-cli mcp — stdio MCP server for AI agents

Run the CLI as a Model Context Protocol
server over stdio, so AI agents (Claude Code, Cursor, …) can drive Mockarty.
Add it to your MCP client config:

{
  "mcpServers": {
    "mockarty": {
      "command": "mockarty-cli",
      "args": ["mcp"]
    }
  }
}

Free local tools are always available — no server or token required:

Tool Purpose
local_mocks_load Load stub files (mockarty / WireMock / Mockoon auto-detect).
local_mocks_list List the loaded mocks (protocol, method, path).
local_mock_resolve Resolve a request against loaded mocks — test without a port.
local_mock_serve_start Serve loaded mocks over HTTP on 127.0.0.1.
local_mock_serve_stop Stop the local mock server.

When a server is configured (--server/--token, env vars, or a saved login
context), every MCP tool of that server is additionally proxied through
under its canonical name — those tools follow your license. If the server is
unreachable or the token is invalid, the CLI logs one warning to stderr and
continues with the local tools only. Pass --local-only to skip proxying.

mockarty-cli recorder — HAR recorder

Capture HTTP traffic via proxy. See Recorder for details.

mockarty-cli sniff — capture-to-HAR reverse proxy

Start a local reverse proxy that records all traffic into a HAR file —
point your application at it, then feed the HAR to mocking, testing or
fuzzing:

mockarty-cli sniff --target http://api.example.com --port 9090 --output traffic.har

mockarty-cli util — offline helpers

Free, air-gapped utilities that need no server and no license:

Command Purpose
util ssh-tunnel Persistent SSH port-forward with profiles and auto-reconnect.
util k8s kubectl-style operations on a Kubernetes cluster.
util gen Generate random data (lorem, names, uuid, jwt, rsa, schema…).
util ci CI helpers: wait, retry, json-diff, hash, base64, env.

mockarty-cli tunnel — TCP / SSH tunnel

Forward local port(s) to a remote Mockarty server — direct TCP, or through
SSH for locked-down hosts (--ssh, key/agent/password auth).

mockarty-cli matcher — check HTTP matching

Use mockarty-cli matcher status with an administrator token when you need to
check how the server chooses a mock for incoming HTTP requests. It shows the
mode for each namespace (off, shadow, or on), the current revision, and
any differences found while comparing matching behavior. Review differences
before enabling the new matcher for a namespace. If the command says the
matcher is not initialized, ask the server administrator to check its setup.
This command only shows status; it does not change the mode.

mockarty-cli init — project scaffold

Generate a project skeleton in the current directory: a declarative
pipeline manifest (mockarty.yaml), ignore file and a sample collection.
Flavors: generic (default), python (pytest plugin), go (Go SDK test).

mockarty-cli extension — browser capture extension

Command Purpose
extension download Pull the latest extension build and extract it locally.
extension launch Start a dedicated Chrome window with the extension pre-loaded.
extension path Print the extraction path.

Cat 2 — Install

Manage the local Mockarty installation.

Command Purpose
install [component...] Download and install Mockarty components (admin, runner, resolver, server-generator, …).
install all Install every component.
`update [component all]`
`uninstall [component all]`
versions Print the installed and available versions.
install bundle Bundle a Mockarty distribution into a tarball for air-gapped transfer.
install bundle-verify <bundle.tar.gz> Check a bundle and its images archive against the bundle manifest, without installing.
install airgap-install <bundle.tar.gz> Install Mockarty from a previously bundled tarball.
setup [mode] Generate configuration files for deployment (Docker Compose / Helm / bare-metal).
`upgrade [component all]`
self-update Replace the running mockarty-cli binary with the latest release (--check, --version X).

Cat 3 — Test runners

The full feature surface. Licence-gated in Community / Licensed mode.

Mock authoring

Command Purpose
mock create Create a mock from CLI flags / file.
mock list List mocks in the active namespace.
mock get <id> Inspect a single mock.
mock delete <id> Soft-delete a mock (recoverable via UI Trash).
mock export Dump mocks to JSON / YAML.
mock import Re-create mocks from JSON / YAML.
mock apply GitOps-style apply from a manifest directory.
mock logs <id> Tail the mock’s hit log.
mock serve Run a fully local mock server with --anon-limit (see below).

mock serve --anon-limit N overrides the default 5-stub cap when the CLI
is in Anonymous mode. Useful for tests that need more stubs without a
server connection.

Functional test runner

Command Purpose
test run <manifest> Run a Mockarty functional manifest (flow.mockarty.json).
`run [script.js manifest]`

Common flags:

  • --reporter cli|json:file|junit:file|allure:dir|html:dir (repeatable).
  • --namespace NS — override the active namespace.

Performance runner

Command Purpose
perf run [script.js] Run a perf script (k6-compatible).

Local CLI without a server: capped at 500 VU / 2 minutes (see
Feature gating).

Fuzzing

Command Purpose
fuzz Parent command for fuzz targets and runs.

Subcommands match the server’s fuzz API; see mockarty-cli fuzz --help.

Postman / Newman compat

Command Purpose
postman run <collection.json> Newman-compatible Postman collection runner.

Recorder (server-side)

Command Purpose
recorder start Start a server-side recording session.
recorder list List sessions.
recorder get <id> Fetch a session.
recorder stop <id> Stop a recording.
recorder delete <id> Soft-delete a session.
recorder export <id> Export a session to HAR / Postman. --variableize swaps correlated values for variables so the artifact replays against fresh data (preview with recorder variableize).
recorder replay <id> Replay a session.
recorder correlate <id> Correlate a session against a contract / mock.

Contract testing

Command Purpose
contract validate Validate a contract definition.
contract verify Verify provider behaviour against a contract.
contract drift Detect drift between current behaviour and the contract.
contract can-i-deploy Pact’s can-i-deploy check.
contract record-deployment Record a deploy/release in the deployment ledger (CI step).
contract consumer-contracts list List consumer contracts.
contract consumer-contracts check Verify a consumer contract.
contract consumer-contracts deploy-check Deploy gate.
contract health Contract-broker health check.
contract registry list Browse the contract registry.
contract registry versions [id] List version history.
contract pact verify Pact verifier (broker-style).
contract pact import <pact.json> Publish a Pact file to Mockarty as a consumer-driven contract.

Chaos engineering (pre-GA — see Chaos pre-GA)

Command Purpose
chaos run (opt-in) Run an experiment.
chaos abort <id> (opt-in) Abort an active experiment.
chaos list List experiments (read-only).
chaos get <id> Inspect an experiment (read-only).
chaos report <id> Generate a report (JSON/HTML/JUnit/Allure/PDF).
chaos preset list Built-in presets (read-only).
chaos preset run --preset NAME (opt-in) Run a preset.
chaos cluster list (read-only) Configured clusters.
chaos cluster info Active cluster details.
chaos cluster add (opt-in) Register a new cluster.
chaos cluster use <name> (opt-in) Switch active cluster.
chaos cluster test (opt-in) Smoke-test a cluster.
chaos cluster remove <name> (opt-in) Remove a cluster.
chaos operator status Health check on the chaos operator.
chaos operator install (opt-in) Install the operator into a cluster.
chaos operator uninstall (opt-in) Uninstall the operator.

“opt-in” means: pass --i-know-this-is-preview or set
MOCKARTY_CHAOS_PREVIEW=1. Read-only commands work without opt-in.

Collections in git

Command Purpose
collection export-git <id> -d <dir> Export an API-Tester collection to a git-friendly directory tree.
collection import-git <dir> Import a git-friendly collection directory tree.
git-sync add Bind an autotest collection (API + UI tests) to a git repository.
git-sync list List git bindings.
git-sync pull <id> / push <id> Merge with the bound repository (git I/O runs server-side); a file changed on both sides stops with a list — decide with --resolve <path>=local|remote or --prefer local|remote.
git-sync rm <id> Remove a binding.

Test flows (Go DSL)

Command Purpose
flow exec <ir.json> Execute a Mockarty IR document against the server-side runner.
flow gen <ir.json> Generate Go source for a flow from an IR document.

Test plans & runs

Command Purpose
testplan list / get <id> List / inspect Test Plans.
testplan create -f plan.yaml Create a Test Plan from YAML/JSON.
testplan patch / delete Update / soft-delete a plan.
testplan adhoc Create and dispatch an ad-hoc (ephemeral) plan run.
testplan report <run-id> Download a run report (Allure / JUnit / Markdown / HTML / unified).
testplan compare-runs Diff two runs: regressions, improvements, added, removed.
testplan aggregate-report Transient aggregate report over several runs.
testplan notifications Manage plan-level notification subscriptions.
test-plans merge Merge N run results into a single Allure-style report.
`test-runs list [–mode fuzz chaos
watch plan-run <id> Stream live progress of a plan run to the terminal (CI-friendly exit codes).
me awaiting-manual List case-run steps awaiting your manual resolution.

Test case management (TCM)

Command Purpose
tcm folders Manage the TCM folder tree (create, move, delete).
tcm discover Sync a discovered test-case manifest into the TCM catalogue.
attachments upload <file> Upload an artefact (video, screenshot, log, report) to a case, run or step.

Security agent

Command Purpose
security list-scanners List registered scan providers.
security start-scan Start a scan (--target, --persona, --intensity).
security get-report <id> Scan status, cost and finding counts.
security list-findings <id> Findings for a report (table or JSON).
security export <id> Download the report as SARIF / VEX / HTML / PDF / Allure.
security list-agents List remote pentest agents in the namespace.
security cancel <id> Cancel an in-flight scan.

Secrets storage

Command Purpose
secrets store Manage secret stores (namespace-scoped, encrypted at rest).
secrets entry Manage entries; decrypted values require the secret:read token permission.

AI prompts

Command Purpose
prompts list / get / create / update / delete Manage centralised AI prompts.
prompts versions Inspect and roll back prompt versions.

UI & mobile tests

Command Purpose
ui list List recorded UI tests in the namespace.
`ui export –lang go python`
mobile devices List real devices in the grid.
mobile apps upload / list Manage app builds (APK) for device runs.
mobile run <ui-test-id> Run a UI test on a real device (--app, --runner, --wait).

Recycle bin

Command Purpose
trash list / summary Inspect soft-deleted entities.
trash restore Restore cascade groups with their dependents.
trash purge / empty Permanently delete (IRREVERSIBLE).
trash settings View / update retention settings.

Migration from other tools

Command Purpose
`migrate testit testrail

--report <file> writes the migration preflight: which cases the destination cannot hold as written (no title, no steps, a priority outside its vocabulary, or the same external id twice in one run), credential-shaped fields found INSIDE the migrated data (named by case and field, never by value), and the exact external ids the run created — the list to delete if the migration was a mistake. Re-running is idempotent on those ids, so a partial migration is fixed by repeating it rather than by cleaning up first. The file is written 0600.
| migrate from-allure | Rewrite third-party Allure SDK imports onto Mockarty equivalents. |
| allure … | Drop-in allurectl replacement — ingest allure-results/ into TCM. |
| testit … | Upload JUnit XML (results upload --results/-r) or converted Test IT JSON (--file); manage Mockarty runs/configurations. Existing framework adapters still need replacement or conversion. |

Command Purpose
audit export Export audit logs as csv / json / syslog / cef (admin or support role).
search <type> <query> Unified entity search — same data the UI picker uses (mock, test_plan, perf_config, fuzz_config, chaos_experiment, contract_pact).

Test reports

Command Purpose
results upload <dir-or-zip> Upload locally-produced results (allure/junit/json) to a Mockarty admin node.
results convert <input> Convert between report formats.

CI orchestration

Command Purpose
ci run-suite <suite.yaml> Run a multi-step CI suite manifest.

Cat 4 — TUI

See TUI user guide for the full screen tour.

Command Lands on
tui Welcome menu
tui auth Auth Status
tui test-plans Test Plan picker
tui results --plan ID Results viewer
tui mocks Mock list
tui perf Perf configs
tui fuzz Fuzz targets
tui chaos Chaos experiments (pre-GA)

Auth & state

Command Purpose
auth login --server URL OAuth device flow + API-token fallback. See OAuth login.
login Legacy entry point (API-token paste).
logout Remove the persisted token.
health Probe the admin node and print the resolved execution mode.
agent [message] Talk to the built-in AI agent (licensed feature).
license Inspect / refresh the active licence.
refresh Refresh the OAuth access token in-place (long CI jobs).
verify CI pre-flight: server reachable, auth valid, namespace accessible, required features active.
wait Block until the server is healthy and (optionally) mocks are loaded.

Config

Command Purpose
config view Dump the current configuration.
config use-context <name> Switch to a configured context.
config get-contexts List configured contexts.
config set-context <name> Create/update a context.
config delete-context <name> Remove a context.

Namespace

Command Purpose
namespace current Print the active namespace.
namespace use <namespace> Switch active namespace.
namespace list List namespaces you can act in.
namespace create <name> Create a new namespace (admin/support only).

Token

Command Purpose
token list List API tokens issued to the current user.
token create Issue a new long-lived token (for CI).
token delete <id> Revoke a token.

Delegated credentials

Tokens whose namespace set, action set and expiry are frozen by the issuer and
cannot be widened by the holder. Use these for work shared with a contractor, a
CI job or an MCP client, instead of handing over an API token — whose namespace
is a default its holder can change. See
Delegated credentials.

Command Purpose
delegated-credential create Issue a credential; prints the mkd_ bearer once.
delegated-credential list Show the credentials you may manage, with their frozen scope.
delegated-credential rotate <id> Replace the bearer, leaving the scope untouched.
delegated-credential revoke <id> Revoke it permanently (no un-revoke).

create requires --namespaces and --expires. --namespaces is plural on
purpose: it is the SET the credential is frozen to, not the global --namespace
the CLI session works in.

# One namespace, read-only, 30 days.
mockarty-cli delegated-credential create --name ci-reader \
  --namespaces staging --actions read --expires 30d

# A holder uses it exactly as it would use an API token.
MOCKARTY_API_KEY=mkd_... mockarty-cli mock list

Store

Command Purpose
store global get <key> Read a global key.
store global set <key> <value> Write a global key.
store global delete <key> Delete a global key.
store chain get <chain-id> Inspect a chain store.
store chain set <chain-id> <key> <value> Write to a chain store.
store chain delete <chain-id> <key> Delete from a chain store.

Backup

Command Purpose
backup create Trigger a workspace backup (admin only).
backup list List backups.
backup download <id> Download a backup tarball.

Cluster (admin / support)

Command Purpose
cluster status Cluster health.
cluster upgrade Rolling upgrade.
cluster scale <component> Scale a component.
cluster restart <component> Restart a component.
cluster logs <pod-name> Tail pod logs.
cluster add-runner Register a new runner pod.
cluster add-resolver Register a new resolver pod.
cluster remove-integration <name> Remove a configured integration.

Agent knowledge review

Command Purpose
agent knowledge review list [--state candidate] [--limit 50] [--cursor TOKEN] List one lifecycle state: candidate, published, superseded, expired, or deleted.
agent knowledge review show <id> Inspect the exact record, metadata, relations, and mutation history.
agent knowledge review decide <id> --decision publish|reject --expected-version N --reason TEXT --idempotency-key KEY Apply a version-fenced, replay-safe review decision.

For publication, --expires-at, --supersedes, and repeatable --contradicts
describe lifetime and relations. Preview relation targets in Missions → Knowledge
before using their IDs. Reuse the same idempotency key only when retrying the
same decision.

Exit codes

Every command returns 0 only when the work it was asked to do actually
succeeded. A command that reports a failure on screen never exits 0 — a CI
step can rely on the code alone.

Three codes carry a fixed meaning across the whole CLI, so a pipeline can
branch on them without knowing which command ran:

Code Meaning
0 The work ran and the result is good.
1 The work ran and the result is bad — a test failed, a contract was violated, a security finding was raised, nothing was executed.
2 The work did not run — a mistyped subcommand, an unknown flag, a missing required flag, no server configured, or a feature your licence does not include.

2 matters most in CI: it is the code that separates “your tests are red”
from “your pipeline step is misconfigured”. A mistyped subcommand
(mockarty-cli perf runn script.js) and an unknown flag both exit 2 — they
never look like a passing step.

Command 0 Non-zero
run every test passed and every requested report was written 1 — a test failed, a request errored, a requested report could not be written, or nothing was executed (empty collection, or a --folder filter that matched no request)
test run every step passed and every requested report was written 1 — a step failed or broke, a requested report could not be written, or no step ran at all (every step skipped — usually a typo in dependsOn)
postman run every assertion passed 1 — an assertion failed or the collection executed no request; 2 — the collection/environment could not be parsed, or an --export-* file could not be written
perf run the load test ran and no threshold was breached 99 — a threshold was breached, the run stopped abnormally, a scenario did not run, or the run measured nothing; 2 — a requested --out file could not be written
fuzz the scan ran and found nothing 1 — findings were raised, every request was blocked, or the scan issued no request at all; 2 — the engine could not start, a requested report could not be written, or a free-tier cap was hit
contract validate / verify / drift / can-i-deploy / deploy-check / pact verify the check ran and the contract holds 1 — violations, drift, or a blocked deploy; 2 — a missing flag or an unreadable spec. The same verdict applies with -o json.
ci run-suite every job ran and passed 1 — any job failed, including a job kind the suite does not execute; 2 — a requested report could not be written
mock create every mock in the file was created 1 — any mock was rejected; the count says how many of how many
mock import every mock was imported 1 — any mock failed; the count says how many of how many
mock apply every mock was applied and pruned 1 — any apply or prune failed
mock export every mock reached the disk 1 — any mock could not be read or written; the count says how many of how many landed
mock convert every file converted 1 — any file was skipped or could not be written

mock convert --report preflight.json also writes what an import has to answer before anyone trusts it: which files were understood (and as which format), what was approximated (the gaps), which credentials the SOURCE artefacts carry — named by file, kind and JSON path, never by value — and what undoing the conversion means (the convert path writes files only, so it is a deletion, and the report says exactly which directory). The file is written 0600: it is a map of where credentials live.
| results upload | every result in the bundle was stored on the server | 1 — the directory held no result, or the server stored only part of the bundle (the count says how many of how many); 2 — no server configured, or the server does not accept result uploads (nothing was stored). Use --dry-run when you only want the local summary. |
| allure upload | every *-result.json and referenced attachment reached Mockarty | 1 — any result or attachment failed to upload, an upload was interrupted, or the directory held no results |
| allure export | at least one *-result.json was written, plus the sidecars | 1 — the run carried no result, a --filter-by-* excluded every result, a sidecar could not be written, or (with --plan-id) any run in the suite failed to export |
| allure launch create | the launch exists and LAUNCH_ID= was printed | 2 — the server answered without a launch id, so nothing can be attached to the launch |
| allure launch close | the launch closed and its recorded outcome is green | 1 — the launch closed as failed, or it received no results at all. --abort records an aborted pipeline and keeps its own verdict. |
| testit results upload | every parsed result reached Mockarty | 1 — empty or malformed input, or any result did not reach the server (the count says how many of how many) |
| testit import | the export was ingested (cases created or updated) | 1 — a work item failed, or nothing at all was imported; 2 — the server’s summary could not be read, so the import cannot be confirmed |
| collection export-git | the tree was written to --dir | 1 — the server returned an empty archive (no file was written) |
| collection import-git | every request in the tree was imported | 1 — any request failed (HTTP 207 partial import) or none was imported; 2 — the server’s summary could not be read |
| recorder import-ui-actions | every parsed action was accepted by the session | 1 — no UI action was recognised in the file (wrong dialect), or the session kept fewer actions than were sent. --dry-run fails on the same empty-parse condition. |
| mobile run | the run was dispatched (and, with --wait, passed) | 1 — the run failed, or a device in --all-devices / --device-selector could not be dispatched to; 2 — the server accepted the run without returning a task id, so it cannot be tracked |
| mobile apps upload | the build was stored and its id printed | 2 — the server returned no artifact id, so nothing can reference the build |
| chaos cluster test | connected AND the capability probe completed | 1 — the capability probe failed; the cluster is not confirmed usable for experiments |
| chaos cluster info | every section of the report was read | 1 — a section (namespaces, nodes, capabilities) could not be read |
| chaos operator install | RBAC and the deployment were created | 1 — a prerequisite (ServiceAccount, ClusterRole, binding) could not be created; the operator is not deployed |
| chaos operator status | the operator is deployed and ready | 1 — not installed, or fewer replicas ready than desired |
| chaos operator uninstall | every object was removed | 1 — an object is still on the cluster (a leftover ClusterRole keeps cluster-wide permissions bound) |
| health | the server answered and reports itself healthy | 1 — the server is unreachable or reports a non-healthy status |
| verify | every requested check passed | 1 — a check failed; 2 — no server configured |
| testplan run --wait | the run finished with no failed item | 1 failed · 2 cancelled · 3 wait timed out |

Five of these deserve a note because they are easy to get wrong in a pipeline:

  • A run that executes nothing is a failure, not a pass. --folder matches a
    request-name prefix, not a folder path, so a filter that matches nothing
    is a common way to end up testing nothing. The same applies to a test run
    manifest where a dependsOn typo skips every step.
  • A load test that measures nothing is a failure. If the summary shows
    Requests: 0, look at the ERROR: lines above it — an iteration that throws
    (a missing import http from "k6/http", for example) leaves nothing to
    measure.
  • A report you asked for and did not get is a failure. If
    --reporter junit:report.xml cannot write the file, the command fails even
    when every test passed — otherwise CI collects an artefact that does not
    exist.
  • An upload or export that delivered nothing is a failure. allure upload,
    testit results upload and results upload fail on an empty results
    directory, and fail again when the server stores only part of what was sent —
    a run history missing rows is worse than one that never claimed to exist.
    allure export fails when it writes no *-result.json, because allure generate cannot build a report from the empty directory it just produced.
  • -o json never changes the verdict. The machine-readable output of a
    contract gate carries the same exit code as the human-readable one.

Autonomous-mission retention

mockarty-cli autonomy settings get reads the current namespace policy. autonomy settings set changes the autonomous run wall with --run-window-minutes, or clears that override with --inherit-run-window. The same command changes --event-days / --payload-days, or clears them with --inherit-event / --inherit-payload. Use --request-id <stable-id> and reuse that value after a timeout or lost response; a new invocation without the flag intentionally starts a new mutation receipt.

Delivery-policy environments

These commands require an administrator credential and a configured authority
connection. Request JSON contains id (create only), projectId, class,
profile, auditId, and evidenceId; it must not contain approval seals.

mockarty-cli delivery-policy environments list --status active --limit 50
mockarty-cli delivery-policy environments get staging
mockarty-cli delivery-policy environments create --file environment.json --idempotency-key staging-v1
mockarty-cli delivery-policy environments advance staging --file environment-v2.json --etag '"dp-env:..."' --idempotency-key staging-v2
mockarty-cli delivery-policy environments revoke staging --etag '"dp-env:..."'
mockarty-cli delivery-policy grants get grant-123

Completion scripts

mockarty-cli completion bash > /etc/bash_completion.d/mockarty-cli
mockarty-cli completion zsh  > "${fpath[1]}/_mockarty-cli"
mockarty-cli completion fish > ~/.config/fish/completions/mockarty-cli.fish
mockarty-cli completion powershell | Out-String | Invoke-Expression

Where to next