Skip to content
Install

CLI reference

Pentect commands and what they do.

Run pentect help for the short list installed with your version. Pentect returns a non-zero exit code when it blocks input, cannot start a client, or cannot complete a requested change.

Launch clients

CommandPurpose
pentect codexLaunch Codex CLI through Pentect
pentect claudeLaunch Claude Code through Pentect
pentect opencodeLaunch OpenCode with a temporary Pentect provider
pentect piLaunch Pi with a temporary Pentect provider
pentect codex appLaunch Codex App for this protected session
pentect claude appLaunch Claude Desktop for this protected session

Unavailable client commands

Antigravity, Aider, Continue, Cline, Roo Code, Zed, Goose, Junie, and Gemini CLI are not implemented in the public CLI. Commands such as pentect aider and pentect gemini return an unknown-command error. Their documentation pages describe status only; they do not indicate working protection.

For Codex and Claude, --set-default adds a reviewed function to the current shell's user profile. The normal codex or claude command then launches through Pentect. --unset-default removes only the block Pentect added.

sh
pentect codex --set-default
pentect codex --unset-default

PowerShell, Bash, Zsh, and Fish are supported. Add --yes only in automation where you have already reviewed the profile change.

App launchers

Add an optional clickable launcher for a desktop App:

sh
pentect codex app --install-launcher
pentect claude app --install-launcher
OptionResult
--install-launcherAdd or refresh the current user's Pentect launcher
--remove-launcherRemove only the launcher owned by Pentect
--yesSkip the confirmation in reviewed automation

Windows and macOS are supported. Both commands show the exact target and ask before changing it. The launcher does not store a custom --app, --upstream, or --plugins value; use the normal terminal launch for those one-time options.

Use --upstream URL to choose a compatible gateway for one launch. Use --upstream-header-env HEADER=ENV_NAME to add a gateway credential without putting its value in command arguments. The source variable is removed from the launched client process. Use --plugins SOURCE to add a plugin for one launch. App commands also support --app PATH and --check.

On Windows, pentect claude app separately confirms the session-only current-user certificate needed for Claude Desktop HTTPS protection. Its --yes option skips Pentect's prompt; it does not bypass a Windows Root-store security confirmation, or make the certificate permanent or machine-wide.

Codex and Claude arguments are forwarded directly:

sh
pentect codex exec --full-auto
pentect claude --model sonnet
pentect opencode --model gpt-5
pentect pi --model gpt-5

--check validates app discovery and routing without leaving the app open. --plugins accepts a local plugin directory or a github:@OWNER/REPOSITORY/path source. Separate multiple sources with commas.

Protect local input and execution

CommandPurpose
pentect maskMask UTF-8 text from stdin
pentect read PATHPrint a masked preview of a file
pentect exec "COMMAND"Restore known handles, run the command, and mask its output
pentect view HANDLEShow handle details without revealing its value
pentect log [--json] [--once [--tail N] | --follow | --path]Show bounded persistent diagnostics or follow protection events
pentect metrics [--json]Show local counts by secret type and protection surface

Image statistics distinguish blocked operations from blocked images: one tool operation containing three blocked images counts as one operation and three images.

mask

Mask UTF-8 standard input. It infers structured formats from content when no path is available.

sh
printf '%s' 'TOKEN=fake-value' | pentect mask
cat .env | pentect mask
printf '%s' 'CASE-12345678' | pentect mask --plugins ./company-policy

read

Read a path with filename-aware format detection and print only the protected preview:

sh
pentect read .env
pentect read terraform.tfvars

When file remembering is enabled, read also records safe local recovery metadata for handles found in that file.

mask and read stay separate because they have different recovery contracts. mask is a stateless stdin filter with a fresh one-run key. read uses the path and can retain handle metadata in the active local store. Merging them would either discard that metadata or make a simple pipe unexpectedly stateful.

exec

exec restores known handles before execution and masks stdout and stderr:

It requires a command name. It does not interpret arbitrary text as a secret, file path, or value to resolve. See the task-oriented command guide for POSIX shell and PowerShell examples.

FormBehavior
pentect exec "COMMAND"Run through the native shell
pentect exec -- PROGRAM ARG...Run a program directly; restored secrets in arguments are refused by default
pentect exec --allow-secret-argv -- PROGRAM ARG...Explicitly allow restored secrets in process arguments
pentect exec --secret-stdin HANDLE -- PROGRAM ARG...Write one restored handle directly to the program's stdin
pentect exec --stdinRead the shell script from UTF-8 stdin
pentect exec --live "COMMAND"Stream masked output instead of buffering it
--script-shell native|bash|powershellChoose the shell for script forms
--session NAMEUse an explicit local session instead of the current-directory session

Use the direct program form when possible. It avoids another layer of shell quoting. If an argument contains a known handle, Pentect refuses to restore it because command arguments can be visible to other processes owned by the same user. Prefer target-program support for stdin, a file descriptor, or protected configuration that avoids secret arguments. A shell command keeps plaintext out of the model-facing command, but the shell can still expand it into a child process argument. Use --allow-secret-argv only when the target program requires a secret argument and you have reviewed that exposure. --live keeps interactive progress visible but still masks output in chunks before it is written.

For an interactive client launched through Pentect, the first Ctrl+C is left to the client so it can cancel the current operation without exiting. Press it again within two seconds to request shutdown; Pentect allows a short cleanup period before forcing the client to exit. Interrupts farther apart stay client-owned cancellations. When input is not a terminal, one interrupt starts that bounded shutdown period immediately.

For programs that accept a credential on stdin, --secret-stdin avoids both secret arguments and environment inheritance:

sh
pentect exec --secret-stdin '<<SUDO_PASSWORD_...>>' -- sudo -S -p '' cat ./ROOT_ONLY.txt

The handle must be one complete known handle from the active session. Pentect writes the recovered bytes exactly once and closes stdin; it does not append a newline. stdout and stderr are still masked. The target program can still use or forward bytes it intentionally reads, so this narrows local exposure but is not network-destination authorization.

view

view parses a handle and prints its label, ID, and safe length hint. It does not require or reveal the real value.

Advanced commands

Advanced commands are available, but are kept separate in pentect help because they can write plaintext or are mainly useful for debugging workflows.

resolve

resolve reads stdin when no path is given. With paths, it replaces known handles in each file in place. Unknown handle-shaped text causes an error instead of being guessed.

sh
pentect view '<<DATABASE_URL_4ce8a3b0a6f64e12>>'
cat masked.txt | pentect resolve > plaintext.txt
pentect resolve config.masked.toml

Treat redirected or in-place resolved output as plaintext secret material.

Installation health

CommandPurpose
pentect doctorCheck readiness
pentect doctor --jsonPrint results as JSON
pentect doctor --fixShow and apply approved fixes
pentect doctor --fix --yesApply all offered fixes without another prompt
pentect update [VERSION]Install the latest release, or an exact published version for rollback
pentect update --checkCheck without installing
pentect update --forceReinstall even when the selected version is already present
pentect uninstallRemove Pentect but keep project data
pentect versionPrint the installed version

An explicit version is exact: pentect update v0.0.69 --check confirms that the published tag can be selected without downloading it, and pentect update v0.0.69 downloads and installs that version. Exact selection may install a release marked as a prerelease, but never a draft. Installation still verifies the platform artifact against its published SHA-256 checksum. Pentect does not automatically move the installation back to the latest version afterward.

Direct and npm installations perform the exact-version replacement. For apt, Homebrew, AUR, or another recorded package manager, Pentect stops and names the exact requested version instead of running a generic upgrade command that could silently select a different release.

Plugins

CommandPurpose
plugins search [QUERY]Search the first-party catalog
plugins inspect SOURCEShow the manifest, hooks, binary, and requested access
plugins add SOURCE [--yes] [--project] [--profile NAME]Verify, approve, and enable a plugin for the user (or this project)
plugins remove NAME [--project]Disable a user plugin (or a project plugin)
plugins list [--json]Show enabled and installed plugins
plugins config NAME KEY=VALUE [--project]Save one setting in the selected scope
plugins config NAME --unset KEY [--project]Remove one setting in the selected scope
plugins setup NAME [--yes] [--project] [--profile NAME]Review changed hooks or access and run declared environment setup
plugins test SOURCE [--json]Validate a manifest or installed binary
plugins update [NAME] [--yes] [--project]Update user plugins (or project plugins)
plugins new NAMECreate a Rust Wasm plugin project
plugins dev PATH [--yes]Build, approve, and activate a local development build
plugins publish PATHBuild a release bundle in dist

SOURCE can be a local directory or github:@OWNER/REPOSITORY/path. Use --plugins SOURCE on a client or mask command when you need a plugin for only one launch. Plugin-management commands use user scope by default; pass --project for .pentect/config.toml, the project lock, approval, settings, and runtime data.

Approval flags skip an interactive confirmation; they do not skip checksum, build-record, manifest, or sandbox checks.

Output for scripts

Commands with --json produce machine-readable JSON. Human output can change for clarity, so scripts should use JSON where offered. Pentect uses a non-zero exit code for invalid arguments, blocked content, launch failures, and failed updates. A launched program keeps its own exit code.

See Plugins for the full workflow.

Pentect is open source.