Castia docs
The CLI and the Operator API, documented the way they run: a bounded command set, explicitly advertised capabilities, and one human approval checkpoint.
CLI + Operator API · live campaign delivery not yet connected
cli/The Castia CLI — what it is, authentication, and your first governed session.
cli/commandsThe full command reference — public grammar, available Operator capabilities, action inputs, and what is explicitly unavailable.
cli/authAuthentication & credentials — install paths, human PKCE sign-in, and least-privilege service tokens for agents and CI.
cli/agentsAutomating with agents — the agent contract, output and retry rules, the human-in-the-loop flow, and the Copilot adapter allowlist.
cli/securitySecurity & data transfer — trust boundaries, implemented controls, threat model, and the capability data-flow inventory.
cli/troubleshootingTroubleshooting & revocation — exit codes, common failures, and the credential-revocation incident runbook.
operator-api/Endpoint reference — in preparation.
Built to be read by agents
Every command on these pages is copyable as it runs. A machine-readable index lives at /llms.txt. Agent clients issue bounded requests through approved adapters — Claude and Codex through the CLI, Microsoft Copilot through a server-enforced allowlist that excludes launch and approval; the approval checkpoint stays human either way.