A curated list of CLI tools that supercharge AI coding agents like Claude Code and Codex CLI
See the codeCLIs that play nicely with AI coding agents.
Browse the directory at awesomecli.com.
This list is for command-line tools that let an agent inspect or change a repo, service, dataset, product account, or infrastructure account without driving a browser. Tools should expose names, IDs, files, logs, diffs, plans, previews, or JSON.
Good candidates target a project or resource explicitly, run in CI or a non-TTY shell, and show a dry-run, diff, validation result, sandbox, or local artifact before a command changes state.
This list leaves out AI agent apps, package managers, interactive-only TUIs, common shell tools, and browser automation.
Unofficial CLIs are fine when the repo is maintained, the credential flow is documented, and scripts can read the output without scraping a screen.
gh): Issues, pull requests,
releases, Actions runs, repo settings, and GraphQL or REST calls. Many
commands support --json and --jq.glab): GitLab issues, merge
requests, pipelines, releases, and API calls. glab api covers gaps in the
higher-level commands and returns JSON.acli):
Jira work items, boards, projects, sprints, and JQL queries from the
terminal.bk): Builds,
jobs, pipelines, annotations, artifacts, clusters, agents, and JSON output
for list or view commands.teamcity):
Builds, queues, agents, logs, artifacts, remote agent terminals, and direct
TeamCity REST calls.act: Local runs for many
GitHub Actions jobs. It does not match GitHub-hosted runners exactly, but it
catches a lot before hosted CI starts.az): Azure
resources with JSON output, JMESPath queries, and service-principal auth.gcloud): Google
Cloud projects, accounts, IAM, deploys, logs, and service-account flows. Pin
the project and account on every run.oci):
OCI resources with JSON output, JMESPath queries, JSON request files,
profiles, OCIDs, compartments, regions, and instance or resource principals.doctl):
Droplets, databases, Kubernetes, domains, firewalls, registries, and account
resources with JSON output.hcloud):
Hetzner Cloud servers, networks, firewalls, volumes, load balancers, SSH
keys, primary IPs, DNS zones, and project contexts.vultr-cli): Instances,
Kubernetes, load balancers, DNS, firewalls, object storage, and text, JSON,
or YAML output.flyctl: App deploys, machines,
volumes, secrets, releases, logs, and WireGuard.sprite):
Persistent Linux environments for agents, with command execution, console
access, URL management, checkpoints, restore, and token setup for CI.wrangler):
Workers, Pages, D1, KV, R2, Queues, deploys, local dev, and dry-run
compilation.ldcli):
Flags, projects, environments, members, segments, experiments, metrics,
JSON responses, file-based request bodies, and a local flag dev server.
Most mutations are immediate API writes.forge): Forge
servers, sites, deployments, environment variables, deployment logs, resource
logs, resource status, restarts, SSH checks, and remote command execution.coolify):
Coolify cloud and self-hosted servers, projects, apps, databases, services,
contexts, JSON output, and token overrides.sst): App deploys, stages,
secrets, logs, stage removal, and deployment diffs before a stage changes.kubectl: Kubernetes
objects, namespaces, diffs, dry-runs, logs, events, and JSON or YAML output,
with context and namespace set explicitly.pscale): MySQL
branching, deploy requests, service tokens, and safer read-only SQL defaults.atlas): Database
schema inspection, validation, diffs, linting, tests, migration plans,
dry-runs, SQL artifacts, and templated JSON output. This is Ariga Atlas, not
MongoDB Atlas.dbt):
Warehouse DAG compilation, selection, tests, builds, state comparison,
source freshness, docs generation, and JSON artifacts.algolia):
Applications, indices, objects, settings, synonyms, rules, JSON, JSONL,
NDJSON, stdin input, dry-runs, and command schemas for agents.hf):
Hub repos, models, datasets, spaces, files, collections, webhooks, jobs,
endpoints, token overrides, JSON output, and ID-only output.mc): S3-compatible
object storage inspection, copy, mirror, and management. The mirror dry-run
is the main reason to hand it to an agent.b2):
B2 buckets, files, keys, replication, sync, removals, and JSON output.rpk:
Kafka-compatible topics, records, offsets, consumer groups, schemas, and
cluster analysis. Record consumption can be bounded and emitted as JSON.rabbitmqadmin:
Broker inspection plus definition export and import workflows. Treat imports
as live mutations.confluent):
Confluent environments, Kafka clusters, topics, consumers, connectors,
schemas, Flink, API keys, audit settings, and JSON or YAML output.temporal):
Local Temporal dev server, namespaces, workflows, activities, schedules,
task queues, JSON output, API keys, and mTLS. Workflow mutations have no
preview.gcx): Grafana resources,
contexts, validation, dry-run pushes, and scriptable output.datadog-ci:
Targeted Synthetic test runs from CI with JSON and JUnit reports.ecctl: Elastic
Cloud deployment inspection and management with explicit deployment IDs and
JSON output.rootly):
Incidents, alerts, services, teams, on-call shifts, deployment pulses,
filtering, pagination, API-token auth, and JSON or YAML output.op): Secret
references, vault items, service accounts, op run, and JSON output. Prefer
injection over printing secrets.bw): Vault items,
folders, collections, organizations, Send objects, JSON templates, jq
workflows, and scripted unlock sessions. Treat bw serve as local secret
exposure unless you control the machine.doppler run, secret downloads, per-command config,
and service token auth.osv-scanner):
Source trees, lockfiles, SBOMs, Git data, and images scanned against OSV,
with JSON, SARIF, CI, and offline database workflows.codeql):
Code databases, standard or custom security queries, SARIF output, and
uploads from third-party CI. Compiled-language extraction can run builds.bru): Local
runs for Git-friendly API collections, with JSON, JUnit, and HTML reports.inso):
Insomnia collection runs, spec linting, config generation, and API test
suites for CI.hoverctl:
HTTP capture, simulation, diff, and replay using portable simulation files.datocms):
Schema migrations, environment diffs, dry-runs, sandbox forks, promotion,
maintenance mode, and API-token auth for CI.storyblok):
Stories, assets, components, datasources, local JSON artifacts, migrations,
dry-runs, snapshots, rollback, and schema diffs.search-replace --dry-run path is worth special attention.cld):
Cloudinary asset search, export, upload, transform, and management.Asana CLI (asana): Tasks,
projects, comments and other Asana resources with stable JSON output. Supported
writes accept --dry-run; previews can still read live state. Unofficial,
MIT-licensed and pre-1.0. Maintained by this list’s maintainer.
Slack CLI (slack): Slack apps,
manifests, triggers, workflows, datastores, app deploys, local run, and logs.
Google Workspace CLI (gws): Drive,
Gmail, Calendar, Sheets, Docs, Chat, and Admin APIs with JSON-first output.
It is pre-1.0 and community-run.
CLI for Microsoft 365 (m365):
Microsoft 365, Entra ID, Teams, SharePoint, Planner, and Outlook automation
with JSON output and JMESPath queries.
Notion CLI (ntn):
Notion auth, API requests, data sources, file uploads, and Notion Workers.
Airtable MCP CLI (airtable-mcp):
Airtable bases and records through Airtable's MCP server, with profiles, JSON
tool discovery, stdin JSON input, and changing server-side tool schemas.
Linear CLI (linear): Unofficial
Linear issues, teams, projects, milestones, documents, comments, attachments,
branches, and JSON output on query, list, and view commands.
HubSpot CLI (hs):
HubSpot apps, CMS assets, developer projects, serverless functions, uploads,
downloads, and account auth.
Salesforce CLI (sf):
Orgs, metadata, scratch environments, deploy validation, and JSON output.
Twilio CLI: Twilio resources through generated commands, profiles, test credentials, and full JSON API responses.
Mattermost mmctl:
Server administration over local socket or remote API with JSON output.
notmuch: Search, thread, tag, dump, and restore for a local mail corpus, with stable message and thread IDs.
Himalaya: IMAP and Maildir operations from the terminal. Test error behavior on your setup before relying on it.
Resend CLI: Domains, API keys, contacts, broadcasts, emails, and webhooks with JSON mode outside a TTY.
Postmark CLI (postmark):
Transactional email sends, server lookup, and template pull or push for CI.
It is narrower than Resend.
--agent, --no-input, pagination, dry-runs for common actions, and a
sandbox-first setup.Gaps to research next: maintained CLIs for PagerDuty or Opsgenie incident work, HubSpot CRM data, Help Scout or Zendesk queues, ad platforms, analytics exports, product analytics, data lineage, marketplace operations, and niche CLIs people actually use with agents.
Add CLIs that are worth giving to an AI agent. A tool does not belong here just because it has a command.
See criteria.md. One tool per pull request. Link the primary docs, and mention the sharp caveat.
Maintained by Vincent Schmalbach (rungrad).
Vincent builds Go CLIs, SaaS automation, and internal developer tools for clients.
A curated list of CLI tools that supercharge AI coding agents like Claude Code and Codex CLI
See the codeCLIs that play nicely with AI coding agents.
Browse the directory at awesomecli.com.
This list is for command-line tools that let an agent inspect or change a repo, service, dataset, product account, or infrastructure account without driving a browser. Tools should expose names, IDs, files, logs, diffs, plans, previews, or JSON.
Good candidates target a project or resource explicitly, run in CI or a non-TTY shell, and show a dry-run, diff, validation result, sandbox, or local artifact before a command changes state.
This list leaves out AI agent apps, package managers, interactive-only TUIs, common shell tools, and browser automation.
Unofficial CLIs are fine when the repo is maintained, the credential flow is documented, and scripts can read the output without scraping a screen.
gh): Issues, pull requests,
releases, Actions runs, repo settings, and GraphQL or REST calls. Many
commands support --json and --jq.glab): GitLab issues, merge
requests, pipelines, releases, and API calls. glab api covers gaps in the
higher-level commands and returns JSON.acli):
Jira work items, boards, projects, sprints, and JQL queries from the
terminal.bk): Builds,
jobs, pipelines, annotations, artifacts, clusters, agents, and JSON output
for list or view commands.teamcity):
Builds, queues, agents, logs, artifacts, remote agent terminals, and direct
TeamCity REST calls.act: Local runs for many
GitHub Actions jobs. It does not match GitHub-hosted runners exactly, but it
catches a lot before hosted CI starts.az): Azure
resources with JSON output, JMESPath queries, and service-principal auth.gcloud): Google
Cloud projects, accounts, IAM, deploys, logs, and service-account flows. Pin
the project and account on every run.oci):
OCI resources with JSON output, JMESPath queries, JSON request files,
profiles, OCIDs, compartments, regions, and instance or resource principals.doctl):
Droplets, databases, Kubernetes, domains, firewalls, registries, and account
resources with JSON output.hcloud):
Hetzner Cloud servers, networks, firewalls, volumes, load balancers, SSH
keys, primary IPs, DNS zones, and project contexts.vultr-cli): Instances,
Kubernetes, load balancers, DNS, firewalls, object storage, and text, JSON,
or YAML output.flyctl: App deploys, machines,
volumes, secrets, releases, logs, and WireGuard.sprite):
Persistent Linux environments for agents, with command execution, console
access, URL management, checkpoints, restore, and token setup for CI.wrangler):
Workers, Pages, D1, KV, R2, Queues, deploys, local dev, and dry-run
compilation.ldcli):
Flags, projects, environments, members, segments, experiments, metrics,
JSON responses, file-based request bodies, and a local flag dev server.
Most mutations are immediate API writes.forge): Forge
servers, sites, deployments, environment variables, deployment logs, resource
logs, resource status, restarts, SSH checks, and remote command execution.coolify):
Coolify cloud and self-hosted servers, projects, apps, databases, services,
contexts, JSON output, and token overrides.sst): App deploys, stages,
secrets, logs, stage removal, and deployment diffs before a stage changes.kubectl: Kubernetes
objects, namespaces, diffs, dry-runs, logs, events, and JSON or YAML output,
with context and namespace set explicitly.pscale): MySQL
branching, deploy requests, service tokens, and safer read-only SQL defaults.atlas): Database
schema inspection, validation, diffs, linting, tests, migration plans,
dry-runs, SQL artifacts, and templated JSON output. This is Ariga Atlas, not
MongoDB Atlas.dbt):
Warehouse DAG compilation, selection, tests, builds, state comparison,
source freshness, docs generation, and JSON artifacts.algolia):
Applications, indices, objects, settings, synonyms, rules, JSON, JSONL,
NDJSON, stdin input, dry-runs, and command schemas for agents.hf):
Hub repos, models, datasets, spaces, files, collections, webhooks, jobs,
endpoints, token overrides, JSON output, and ID-only output.mc): S3-compatible
object storage inspection, copy, mirror, and management. The mirror dry-run
is the main reason to hand it to an agent.b2):
B2 buckets, files, keys, replication, sync, removals, and JSON output.rpk:
Kafka-compatible topics, records, offsets, consumer groups, schemas, and
cluster analysis. Record consumption can be bounded and emitted as JSON.rabbitmqadmin:
Broker inspection plus definition export and import workflows. Treat imports
as live mutations.confluent):
Confluent environments, Kafka clusters, topics, consumers, connectors,
schemas, Flink, API keys, audit settings, and JSON or YAML output.temporal):
Local Temporal dev server, namespaces, workflows, activities, schedules,
task queues, JSON output, API keys, and mTLS. Workflow mutations have no
preview.gcx): Grafana resources,
contexts, validation, dry-run pushes, and scriptable output.datadog-ci:
Targeted Synthetic test runs from CI with JSON and JUnit reports.ecctl: Elastic
Cloud deployment inspection and management with explicit deployment IDs and
JSON output.rootly):
Incidents, alerts, services, teams, on-call shifts, deployment pulses,
filtering, pagination, API-token auth, and JSON or YAML output.op): Secret
references, vault items, service accounts, op run, and JSON output. Prefer
injection over printing secrets.bw): Vault items,
folders, collections, organizations, Send objects, JSON templates, jq
workflows, and scripted unlock sessions. Treat bw serve as local secret
exposure unless you control the machine.doppler run, secret downloads, per-command config,
and service token auth.osv-scanner):
Source trees, lockfiles, SBOMs, Git data, and images scanned against OSV,
with JSON, SARIF, CI, and offline database workflows.codeql):
Code databases, standard or custom security queries, SARIF output, and
uploads from third-party CI. Compiled-language extraction can run builds.bru): Local
runs for Git-friendly API collections, with JSON, JUnit, and HTML reports.inso):
Insomnia collection runs, spec linting, config generation, and API test
suites for CI.hoverctl:
HTTP capture, simulation, diff, and replay using portable simulation files.datocms):
Schema migrations, environment diffs, dry-runs, sandbox forks, promotion,
maintenance mode, and API-token auth for CI.storyblok):
Stories, assets, components, datasources, local JSON artifacts, migrations,
dry-runs, snapshots, rollback, and schema diffs.search-replace --dry-run path is worth special attention.cld):
Cloudinary asset search, export, upload, transform, and management.Asana CLI (asana): Tasks,
projects, comments and other Asana resources with stable JSON output. Supported
writes accept --dry-run; previews can still read live state. Unofficial,
MIT-licensed and pre-1.0. Maintained by this list’s maintainer.
Slack CLI (slack): Slack apps,
manifests, triggers, workflows, datastores, app deploys, local run, and logs.
Google Workspace CLI (gws): Drive,
Gmail, Calendar, Sheets, Docs, Chat, and Admin APIs with JSON-first output.
It is pre-1.0 and community-run.
CLI for Microsoft 365 (m365):
Microsoft 365, Entra ID, Teams, SharePoint, Planner, and Outlook automation
with JSON output and JMESPath queries.
Notion CLI (ntn):
Notion auth, API requests, data sources, file uploads, and Notion Workers.
Airtable MCP CLI (airtable-mcp):
Airtable bases and records through Airtable's MCP server, with profiles, JSON
tool discovery, stdin JSON input, and changing server-side tool schemas.
Linear CLI (linear): Unofficial
Linear issues, teams, projects, milestones, documents, comments, attachments,
branches, and JSON output on query, list, and view commands.
HubSpot CLI (hs):
HubSpot apps, CMS assets, developer projects, serverless functions, uploads,
downloads, and account auth.
Salesforce CLI (sf):
Orgs, metadata, scratch environments, deploy validation, and JSON output.
Twilio CLI: Twilio resources through generated commands, profiles, test credentials, and full JSON API responses.
Mattermost mmctl:
Server administration over local socket or remote API with JSON output.
notmuch: Search, thread, tag, dump, and restore for a local mail corpus, with stable message and thread IDs.
Himalaya: IMAP and Maildir operations from the terminal. Test error behavior on your setup before relying on it.
Resend CLI: Domains, API keys, contacts, broadcasts, emails, and webhooks with JSON mode outside a TTY.
Postmark CLI (postmark):
Transactional email sends, server lookup, and template pull or push for CI.
It is narrower than Resend.
--agent, --no-input, pagination, dry-runs for common actions, and a
sandbox-first setup.Gaps to research next: maintained CLIs for PagerDuty or Opsgenie incident work, HubSpot CRM data, Help Scout or Zendesk queues, ad platforms, analytics exports, product analytics, data lineage, marketplace operations, and niche CLIs people actually use with agents.
Add CLIs that are worth giving to an AI agent. A tool does not belong here just because it has a command.
See criteria.md. One tool per pull request. Link the primary docs, and mention the sharp caveat.
Maintained by Vincent Schmalbach (rungrad).
Vincent builds Go CLIs, SaaS automation, and internal developer tools for clients.