vincentsch/awesome-ai-cli

A curated list of CLI tools that supercharge AI coding agents like Claude Code and Codex CLI

12

5 commits

updated Oct 7, 2026

See the code

See what people are saying

SourceMessageScoreDate

Command-line tools for coding agents - awesome-ai-cli (r/coolgithubprojects)

I maintain this list of command-line tools that agents can call. It covers cloud infrastructure, databases and project trackers. Each entry says what the tool can do.

1

Oct 7, 2026

README

Awesome AI CLI Awesome

CLIs that play nicely with AI coding agents.

Browse the directory at awesomecli.com.

This list is for command-line tools that let an agent inspect or change a repo, service, dataset, product account, or infrastructure account without driving a browser. Tools should expose names, IDs, files, logs, diffs, plans, previews, or JSON.

Good candidates target a project or resource explicitly, run in CI or a non-TTY shell, and show a dry-run, diff, validation result, sandbox, or local artifact before a command changes state.

This list leaves out AI agent apps, package managers, interactive-only TUIs, common shell tools, and browser automation.

Unofficial CLIs are fine when the repo is maintained, the credential flow is documented, and scripts can read the output without scraping a screen.

Contents

Source Control, Reviews, And CI

  • GitHub CLI (gh): Issues, pull requests, releases, Actions runs, repo settings, and GraphQL or REST calls. Many commands support --json and --jq.
  • GitLab CLI (glab): GitLab issues, merge requests, pipelines, releases, and API calls. glab api covers gaps in the higher-level commands and returns JSON.
  • Atlassian CLI (acli): Jira work items, boards, projects, sprints, and JQL queries from the terminal.
  • CircleCI CLI: Config validation, reusable config packing, local job execution where supported, and CI setup checks before a YAML change is pushed.
  • Buildkite CLI (bk): Builds, jobs, pipelines, annotations, artifacts, clusters, agents, and JSON output for list or view commands.
  • TeamCity CLI (teamcity): Builds, queues, agents, logs, artifacts, remote agent terminals, and direct TeamCity REST calls.
  • GitHub Actions act: Local runs for many GitHub Actions jobs. It does not match GitHub-hosted runners exactly, but it catches a lot before hosted CI starts.
  • Sentry CLI: Releases, commits, deploys, source maps, debug files, and event lookup from scripts.

Infrastructure And Cloud

  • Terraform: The familiar plan and apply loop, with change review before infrastructure is touched.
  • OpenTofu: Terraform-compatible infrastructure commands with the same plan-first shape.
  • Pulumi CLI: Infrastructure previews, diffs, stack outputs, and updates from programs written in normal languages.
  • AWS CLI: AWS resources with JSON output, profiles, regions, JMESPath queries, and IAM-based credential scoping.
  • Azure CLI (az): Azure resources with JSON output, JMESPath queries, and service-principal auth.
  • Google Cloud CLI (gcloud): Google Cloud projects, accounts, IAM, deploys, logs, and service-account flows. Pin the project and account on every run.
  • Oracle Cloud Infrastructure CLI (oci): OCI resources with JSON output, JMESPath queries, JSON request files, profiles, OCIDs, compartments, regions, and instance or resource principals.
  • DigitalOcean CLI (doctl): Droplets, databases, Kubernetes, domains, firewalls, registries, and account resources with JSON output.
  • Hetzner Cloud CLI (hcloud): Hetzner Cloud servers, networks, firewalls, volumes, load balancers, SSH keys, primary IPs, DNS zones, and project contexts.
  • Linode CLI: Linode instances, Kubernetes, volumes, firewalls, images, domains, object storage, and JSON output.
  • Vultr CLI (vultr-cli): Instances, Kubernetes, load balancers, DNS, firewalls, object storage, and text, JSON, or YAML output.
  • Render CLI: Services, deploys, logs, Postgres queries, Blueprint validation, non-interactive mode, and JSON or YAML output.
  • Heroku CLI: Apps, releases, config vars, add-ons, logs, Postgres, pipelines, and JSON output on many management commands.
  • Railway CLI: Projects, services, deploys, logs, variables, shell sessions with service env, and CI tokens.
  • Fly.io flyctl: App deploys, machines, volumes, secrets, releases, logs, and WireGuard.
  • Fly.io Sprites CLI (sprite): Persistent Linux environments for agents, with command execution, console access, URL management, checkpoints, restore, and token setup for CI.
  • Fastly CLI: Fastly Compute, VCL services, domains, backends, dictionaries, ACLs, packaging, and deploys.
  • Vercel CLI: Deployments, env vars, project linking, logs, aliases, and preview deployments.
  • Netlify CLI: Local dev, deploy previews, env vars, functions, forms, and site management from the terminal.
  • Cloudflare Wrangler (wrangler): Workers, Pages, D1, KV, R2, Queues, deploys, local dev, and dry-run compilation.
  • Firebase CLI: Firebase deploys, emulators, project config, functions, Firestore indexes, and CI auth.
  • LaunchDarkly CLI (ldcli): Flags, projects, environments, members, segments, experiments, metrics, JSON responses, file-based request bodies, and a local flag dev server. Most mutations are immediate API writes.
  • Laravel Forge CLI (forge): Forge servers, sites, deployments, environment variables, deployment logs, resource logs, resource status, restarts, SSH checks, and remote command execution.
  • Coolify CLI (coolify): Coolify cloud and self-hosted servers, projects, apps, databases, services, contexts, JSON output, and token overrides.
  • SST CLI (sst): App deploys, stages, secrets, logs, stage removal, and deployment diffs before a stage changes.
  • Tailscale CLI: Tailnet status, peers, SSH, serve, funnel, file transfer, and JSON status for automation. Funnel can expose a local service to the public internet.
  • Nomad CLI: Job planning, allocation diffs, and a plan index that protects an apply from racing cluster state.

Containers, Kubernetes, And Gateways

  • Docker CLI and Compose: Container inspection, image builds, Compose config rendering, and Compose dry-runs.
  • kubectl: Kubernetes objects, namespaces, diffs, dry-runs, logs, events, and JSON or YAML output, with context and namespace set explicitly.
  • Helm: Chart rendering, generated Kubernetes manifests, and release diff review before cluster changes.
  • Argo CD CLI: GitOps app inspection, diffs, syncs, rollbacks, and app state.
  • Kong decK: Kong Gateway export, validation, diff, and sync through declarative files.
  • Cilium CLI: Cilium install checks, connectivity tests, and network troubleshooting for Kubernetes clusters.

Databases, Data, And Storage

  • Supabase CLI: Local Supabase stacks, database diffs, migrations, generated types, and dry-run pushes.
  • MongoDB Atlas CLI: Atlas projects, clusters, users, backups, alerts, and raw Atlas API calls.
  • Neon CLI: Neon projects, branches, connection strings, database branching, and project linking.
  • PlanetScale CLI (pscale): MySQL branching, deploy requests, service tokens, and safer read-only SQL defaults.
  • Turso CLI: SQLite databases, branches, replicas, tokens, orgs, and locations from scripts.
  • Atlas schema CLI (atlas): Database schema inspection, validation, diffs, linting, tests, migration plans, dry-runs, SQL artifacts, and templated JSON output. This is Ariga Atlas, not MongoDB Atlas.
  • Convex CLI: Projects, deployments, functions, data inspection, logs, env vars, imports, exports, and codegen.
  • Upstash CLI: Redis, Vector, Search, QStash, teams, JSON output by default, and dry-runs on destructive commands.
  • Databricks CLI: Bundle validation, JSON deployment plans, and replay of an approved plan.
  • Snowflake CLI: SQL, stages, Snowpark, Streamlit apps, and object management.
  • dbt CLI (dbt): Warehouse DAG compilation, selection, tests, builds, state comparison, source freshness, docs generation, and JSON artifacts.
  • DuckDB CLI: Local SQL over CSV, JSON, Parquet, SQLite, Postgres exports, and remote files.
  • sqlite-utils: Import CSV, JSON, and JSONL into SQLite, reshape tables, add full-text search, and query the database as JSON.
  • Datasette: A local SQLite database exposed as a searchable JSON API.
  • Steampipe: Cloud and SaaS APIs exposed as SQL tables, with plugin and rate-limit caveats.
  • Dolt: SQL data with Git-like branches, commits, row diffs, merges, and rollback.
  • Algolia CLI (algolia): Applications, indices, objects, settings, synonyms, rules, JSON, JSONL, NDJSON, stdin input, dry-runs, and command schemas for agents.
  • Hugging Face CLI (hf): Hub repos, models, datasets, spaces, files, collections, webhooks, jobs, endpoints, token overrides, JSON output, and ID-only output.
  • dbmate: Database migrations, schema dumps, migration status, rollback, and checks without tying the project to one app framework.
  • MinIO Client (mc): S3-compatible object storage inspection, copy, mirror, and management. The mirror dry-run is the main reason to hand it to an agent.
  • Backblaze B2 CLI (b2): B2 buckets, files, keys, replication, sync, removals, and JSON output.
  • s5cmd: High-volume S3 operations with command files, dry-runs, and structured logs.
  • rclone: Copy, compare, check, and sync files across many storage providers.
  • restic: Encrypted backups with addressable snapshots, checks, restores, and JSON output for scripting.

Queues, Streams, And Realtime

  • NATS CLI: Streams, consumers, KV, object stores, schemas, events, messages, benchmarks, and named contexts.
  • Redpanda rpk: Kafka-compatible topics, records, offsets, consumer groups, schemas, and cluster analysis. Record consumption can be bounded and emitted as JSON.
  • RabbitMQ rabbitmqadmin: Broker inspection plus definition export and import workflows. Treat imports as live mutations.
  • Confluent CLI (confluent): Confluent environments, Kafka clusters, topics, consumers, connectors, schemas, Flink, API keys, audit settings, and JSON or YAML output.
  • Temporal CLI (temporal): Local Temporal dev server, namespaces, workflows, activities, schedules, task queues, JSON output, API keys, and mTLS. Workflow mutations have no preview.
  • ntfy CLI: Notification publishing and subscription streams from shell scripts.

Observability And Incidents

  • Grafana CLI (gcx): Grafana resources, contexts, validation, dry-run pushes, and scriptable output.
  • Grafana LogCLI: Bounded LogQL queries against Loki with JSONL output.
  • New Relic CLI: NRQL, NerdGraph, entities, workloads, deployments, profiles, and JSON output by default.
  • Datadog datadog-ci: Targeted Synthetic test runs from CI with JSON and JUnit reports.
  • Elastic ecctl: Elastic Cloud deployment inspection and management with explicit deployment IDs and JSON output.
  • Axiom CLI: Query, stream, and ingest Axiom datasets from the terminal.
  • Tailpipe: External logs collected into a local analytical store and queried with SQL.
  • Rootly CLI (rootly): Incidents, alerts, services, teams, on-call shifts, deployment pulses, filtering, pagination, API-token auth, and JSON or YAML output.

Security, Secrets, And Supply Chain

  • 1Password CLI (op): Secret references, vault items, service accounts, op run, and JSON output. Prefer injection over printing secrets.
  • Bitwarden CLI (bw): Vault items, folders, collections, organizations, Send objects, JSON templates, jq workflows, and scripted unlock sessions. Treat bw serve as local secret exposure unless you control the machine.
  • Vault CLI: Vault paths, policies, auth methods, leases, and JSON output. It belongs with narrow tokens.
  • Infisical CLI: Secret sync, injection, project and environment targeting, and CI auth.
  • Doppler CLI: Secrets, projects, configs, audit logs, doppler run, secret downloads, per-command config, and service token auth.
  • SOPS: Encrypted YAML, JSON, ENV, INI, and binary files with reviewable diffs.
  • Gitleaks: Git history, worktrees, files, and stdin secret scans with JSON, CSV, JUnit, and SARIF reports.
  • TruffleHog: Git, GitHub, GitLab, S3, Docker, filesystem, and CI secret scans with verification and JSON output.
  • Trivy: Vulnerability, misconfiguration, secret, SBOM, filesystem, repo, and image scans with JSON and SARIF output.
  • Semgrep: Structural code search and security rules with parseable findings.
  • Snyk CLI: Dependency, code, container, IaC, license, and SBOM scans with JSON and SARIF output.
  • Syft: SBOM generation for containers and filesystems in JSON, SPDX, and CycloneDX formats.
  • Grype: Vulnerability scans for images and SBOMs with JSON output and severity gates.
  • Cosign: Container image and blob signing, verification, attestations, and keyless Sigstore workflows.
  • OpenSSF Scorecard: Repository supply-chain checks for GitHub or local repos, with JSON output for policy gates.
  • OSV-Scanner (osv-scanner): Source trees, lockfiles, SBOMs, Git data, and images scanned against OSV, with JSON, SARIF, CI, and offline database workflows.
  • CodeQL CLI (codeql): Code databases, standard or custom security queries, SARIF output, and uploads from third-party CI. Compiled-language extraction can run builds.
  • Checkov: Infrastructure-as-code policy checks with JSON, SARIF, JUnit, and CI exits.
  • TFLint: Terraform linting with provider-aware rules before a full plan.

API Contracts, Testing, And Replay

  • oasdiff: Semantic OpenAPI diffs, breaking-change checks, changelogs, JSON or YAML reports, and CI exits.
  • Redocly CLI: OpenAPI, AsyncAPI, and Arazzo linting and bundling with configurable rules and parseable output.
  • Vacuum: OpenAPI, AsyncAPI, and JSON Schema linting with Spectral-compatible rules and parseable reports.
  • Buf CLI: Protobuf linting, formatting, generation, and breaking-change detection with JSON, JUnit, GitHub Actions, and GitLab output formats.
  • Schemathesis: Property-based tests from OpenAPI or GraphQL, with JUnit, VCR, HAR, and NDJSON reports. Filter mutating endpoints unless they are part of the test.
  • Postman CLI: Collection runs, API tests, spec linting, monitors, Postman workspace sync, and JSON, JUnit, or HTML reports.
  • Newman: Postman collection runs from local files or URLs with CLI, JSON, JUnit, and progress reports.
  • k6: Scriptable load tests with thresholds, summaries, and JSON or NDJSON result streams.
  • Hurl: Plain-text HTTP requests with captures, assertions, and report formats.
  • Bruno CLI (bru): Local runs for Git-friendly API collections, with JSON, JUnit, and HTML reports.
  • Insomnia CLI (inso): Insomnia collection runs, spec linting, config generation, and API test suites for CI.
  • Hoverfly hoverctl: HTTP capture, simulation, diff, and replay using portable simulation files.
  • Mockoon CLI: Headless mock APIs from Mockoon or OpenAPI definitions.

Content, CMS, And Media

  • Sanity CLI: Query, inspect, export, and manage Sanity datasets and documents from scripts.
  • Contentful CLI: Contentful space and environment export, migration, and import through JSON files.
  • Directus schema tooling: Directus schema snapshot, diff, and apply between environments.
  • DatoCMS CLI (datocms): Schema migrations, environment diffs, dry-runs, sandbox forks, promotion, maintenance mode, and API-token auth for CI.
  • Storyblok CLI (storyblok): Stories, assets, components, datasources, local JSON artifacts, migrations, dry-runs, snapshots, rollback, and schema diffs.
  • WP-CLI: WordPress content, users, plugins, themes, options, cron, cache, and database operations. The search-replace --dry-run path is worth special attention.
  • Cloudinary CLI (cld): Cloudinary asset search, export, upload, transform, and management.
  • Mux CLI: Video assets, live streams, playback IDs, signed URLs, and local webhook listen, replay, and trigger flows.
  • Shopify CLI: Apps, themes, extensions, functions, deploys, and local previews for Shopify projects.
  • Ghost CLI: Ghost install, upgrade, backup, restart, logs, and diagnostics.

Workspace, CRM, Email, And Messaging

  • Asana CLI (asana): Tasks, projects, comments and other Asana resources with stable JSON output. Supported writes accept --dry-run; previews can still read live state. Unofficial, MIT-licensed and pre-1.0. Maintained by this list’s maintainer.

  • Slack CLI (slack): Slack apps, manifests, triggers, workflows, datastores, app deploys, local run, and logs.

  • Google Workspace CLI (gws): Drive, Gmail, Calendar, Sheets, Docs, Chat, and Admin APIs with JSON-first output. It is pre-1.0 and community-run.

  • CLI for Microsoft 365 (m365): Microsoft 365, Entra ID, Teams, SharePoint, Planner, and Outlook automation with JSON output and JMESPath queries.

  • Notion CLI (ntn): Notion auth, API requests, data sources, file uploads, and Notion Workers.

  • Airtable MCP CLI (airtable-mcp): Airtable bases and records through Airtable's MCP server, with profiles, JSON tool discovery, stdin JSON input, and changing server-side tool schemas.

  • Linear CLI (linear): Unofficial Linear issues, teams, projects, milestones, documents, comments, attachments, branches, and JSON output on query, list, and view commands.

  • HubSpot CLI (hs): HubSpot apps, CMS assets, developer projects, serverless functions, uploads, downloads, and account auth.

  • Salesforce CLI (sf): Orgs, metadata, scratch environments, deploy validation, and JSON output.

  • Twilio CLI: Twilio resources through generated commands, profiles, test credentials, and full JSON API responses.

  • Mattermost mmctl: Server administration over local socket or remote API with JSON output.

  • notmuch: Search, thread, tag, dump, and restore for a local mail corpus, with stable message and thread IDs.

  • Himalaya: IMAP and Maildir operations from the terminal. Test error behavior on your setup before relying on it.

  • Resend CLI: Domains, API keys, contacts, broadcasts, emails, and webhooks with JSON mode outside a TTY.

  • Postmark CLI (postmark): Transactional email sends, server lookup, and template pull or push for CI. It is narrower than Resend.

Payments, Commerce, And Finance

  • Stripe CLI: Webhooks, test events, fixtures, logs, and sandboxed Stripe flows. Keep agents in test mode unless live access is intentional.
  • Ramp CLI: Ramp finance flows with --agent, --no-input, pagination, dry-runs for common actions, and a sandbox-first setup.

Still Looking For

Gaps to research next: maintained CLIs for PagerDuty or Opsgenie incident work, HubSpot CRM data, Help Scout or Zendesk queues, ad platforms, analytics exports, product analytics, data lineage, marketplace operations, and niche CLIs people actually use with agents.

Contributing

Add CLIs that are worth giving to an AI agent. A tool does not belong here just because it has a command.

See criteria.md. One tool per pull request. Link the primary docs, and mention the sharp caveat.

Maintainer

Maintained by Vincent Schmalbach (rungrad).

Vincent builds Go CLIs, SaaS automation, and internal developer tools for clients.

License

CC0

ai-agents
awesome-list
cli
command-line

vincentsch/awesome-ai-cli

A curated list of CLI tools that supercharge AI coding agents like Claude Code and Codex CLI

12

5 commits

updated Oct 7, 2026

See the code

See what people are saying

SourceMessageScoreDate

Command-line tools for coding agents - awesome-ai-cli (r/coolgithubprojects)

I maintain this list of command-line tools that agents can call. It covers cloud infrastructure, databases and project trackers. Each entry says what the tool can do.

1

Oct 7, 2026

README

Awesome AI CLI Awesome

CLIs that play nicely with AI coding agents.

Browse the directory at awesomecli.com.

This list is for command-line tools that let an agent inspect or change a repo, service, dataset, product account, or infrastructure account without driving a browser. Tools should expose names, IDs, files, logs, diffs, plans, previews, or JSON.

Good candidates target a project or resource explicitly, run in CI or a non-TTY shell, and show a dry-run, diff, validation result, sandbox, or local artifact before a command changes state.

This list leaves out AI agent apps, package managers, interactive-only TUIs, common shell tools, and browser automation.

Unofficial CLIs are fine when the repo is maintained, the credential flow is documented, and scripts can read the output without scraping a screen.

Contents

Source Control, Reviews, And CI

  • GitHub CLI (gh): Issues, pull requests, releases, Actions runs, repo settings, and GraphQL or REST calls. Many commands support --json and --jq.
  • GitLab CLI (glab): GitLab issues, merge requests, pipelines, releases, and API calls. glab api covers gaps in the higher-level commands and returns JSON.
  • Atlassian CLI (acli): Jira work items, boards, projects, sprints, and JQL queries from the terminal.
  • CircleCI CLI: Config validation, reusable config packing, local job execution where supported, and CI setup checks before a YAML change is pushed.
  • Buildkite CLI (bk): Builds, jobs, pipelines, annotations, artifacts, clusters, agents, and JSON output for list or view commands.
  • TeamCity CLI (teamcity): Builds, queues, agents, logs, artifacts, remote agent terminals, and direct TeamCity REST calls.
  • GitHub Actions act: Local runs for many GitHub Actions jobs. It does not match GitHub-hosted runners exactly, but it catches a lot before hosted CI starts.
  • Sentry CLI: Releases, commits, deploys, source maps, debug files, and event lookup from scripts.

Infrastructure And Cloud

  • Terraform: The familiar plan and apply loop, with change review before infrastructure is touched.
  • OpenTofu: Terraform-compatible infrastructure commands with the same plan-first shape.
  • Pulumi CLI: Infrastructure previews, diffs, stack outputs, and updates from programs written in normal languages.
  • AWS CLI: AWS resources with JSON output, profiles, regions, JMESPath queries, and IAM-based credential scoping.
  • Azure CLI (az): Azure resources with JSON output, JMESPath queries, and service-principal auth.
  • Google Cloud CLI (gcloud): Google Cloud projects, accounts, IAM, deploys, logs, and service-account flows. Pin the project and account on every run.
  • Oracle Cloud Infrastructure CLI (oci): OCI resources with JSON output, JMESPath queries, JSON request files, profiles, OCIDs, compartments, regions, and instance or resource principals.
  • DigitalOcean CLI (doctl): Droplets, databases, Kubernetes, domains, firewalls, registries, and account resources with JSON output.
  • Hetzner Cloud CLI (hcloud): Hetzner Cloud servers, networks, firewalls, volumes, load balancers, SSH keys, primary IPs, DNS zones, and project contexts.
  • Linode CLI: Linode instances, Kubernetes, volumes, firewalls, images, domains, object storage, and JSON output.
  • Vultr CLI (vultr-cli): Instances, Kubernetes, load balancers, DNS, firewalls, object storage, and text, JSON, or YAML output.
  • Render CLI: Services, deploys, logs, Postgres queries, Blueprint validation, non-interactive mode, and JSON or YAML output.
  • Heroku CLI: Apps, releases, config vars, add-ons, logs, Postgres, pipelines, and JSON output on many management commands.
  • Railway CLI: Projects, services, deploys, logs, variables, shell sessions with service env, and CI tokens.
  • Fly.io flyctl: App deploys, machines, volumes, secrets, releases, logs, and WireGuard.
  • Fly.io Sprites CLI (sprite): Persistent Linux environments for agents, with command execution, console access, URL management, checkpoints, restore, and token setup for CI.
  • Fastly CLI: Fastly Compute, VCL services, domains, backends, dictionaries, ACLs, packaging, and deploys.
  • Vercel CLI: Deployments, env vars, project linking, logs, aliases, and preview deployments.
  • Netlify CLI: Local dev, deploy previews, env vars, functions, forms, and site management from the terminal.
  • Cloudflare Wrangler (wrangler): Workers, Pages, D1, KV, R2, Queues, deploys, local dev, and dry-run compilation.
  • Firebase CLI: Firebase deploys, emulators, project config, functions, Firestore indexes, and CI auth.
  • LaunchDarkly CLI (ldcli): Flags, projects, environments, members, segments, experiments, metrics, JSON responses, file-based request bodies, and a local flag dev server. Most mutations are immediate API writes.
  • Laravel Forge CLI (forge): Forge servers, sites, deployments, environment variables, deployment logs, resource logs, resource status, restarts, SSH checks, and remote command execution.
  • Coolify CLI (coolify): Coolify cloud and self-hosted servers, projects, apps, databases, services, contexts, JSON output, and token overrides.
  • SST CLI (sst): App deploys, stages, secrets, logs, stage removal, and deployment diffs before a stage changes.
  • Tailscale CLI: Tailnet status, peers, SSH, serve, funnel, file transfer, and JSON status for automation. Funnel can expose a local service to the public internet.
  • Nomad CLI: Job planning, allocation diffs, and a plan index that protects an apply from racing cluster state.

Containers, Kubernetes, And Gateways

  • Docker CLI and Compose: Container inspection, image builds, Compose config rendering, and Compose dry-runs.
  • kubectl: Kubernetes objects, namespaces, diffs, dry-runs, logs, events, and JSON or YAML output, with context and namespace set explicitly.
  • Helm: Chart rendering, generated Kubernetes manifests, and release diff review before cluster changes.
  • Argo CD CLI: GitOps app inspection, diffs, syncs, rollbacks, and app state.
  • Kong decK: Kong Gateway export, validation, diff, and sync through declarative files.
  • Cilium CLI: Cilium install checks, connectivity tests, and network troubleshooting for Kubernetes clusters.

Databases, Data, And Storage

  • Supabase CLI: Local Supabase stacks, database diffs, migrations, generated types, and dry-run pushes.
  • MongoDB Atlas CLI: Atlas projects, clusters, users, backups, alerts, and raw Atlas API calls.
  • Neon CLI: Neon projects, branches, connection strings, database branching, and project linking.
  • PlanetScale CLI (pscale): MySQL branching, deploy requests, service tokens, and safer read-only SQL defaults.
  • Turso CLI: SQLite databases, branches, replicas, tokens, orgs, and locations from scripts.
  • Atlas schema CLI (atlas): Database schema inspection, validation, diffs, linting, tests, migration plans, dry-runs, SQL artifacts, and templated JSON output. This is Ariga Atlas, not MongoDB Atlas.
  • Convex CLI: Projects, deployments, functions, data inspection, logs, env vars, imports, exports, and codegen.
  • Upstash CLI: Redis, Vector, Search, QStash, teams, JSON output by default, and dry-runs on destructive commands.
  • Databricks CLI: Bundle validation, JSON deployment plans, and replay of an approved plan.
  • Snowflake CLI: SQL, stages, Snowpark, Streamlit apps, and object management.
  • dbt CLI (dbt): Warehouse DAG compilation, selection, tests, builds, state comparison, source freshness, docs generation, and JSON artifacts.
  • DuckDB CLI: Local SQL over CSV, JSON, Parquet, SQLite, Postgres exports, and remote files.
  • sqlite-utils: Import CSV, JSON, and JSONL into SQLite, reshape tables, add full-text search, and query the database as JSON.
  • Datasette: A local SQLite database exposed as a searchable JSON API.
  • Steampipe: Cloud and SaaS APIs exposed as SQL tables, with plugin and rate-limit caveats.
  • Dolt: SQL data with Git-like branches, commits, row diffs, merges, and rollback.
  • Algolia CLI (algolia): Applications, indices, objects, settings, synonyms, rules, JSON, JSONL, NDJSON, stdin input, dry-runs, and command schemas for agents.
  • Hugging Face CLI (hf): Hub repos, models, datasets, spaces, files, collections, webhooks, jobs, endpoints, token overrides, JSON output, and ID-only output.
  • dbmate: Database migrations, schema dumps, migration status, rollback, and checks without tying the project to one app framework.
  • MinIO Client (mc): S3-compatible object storage inspection, copy, mirror, and management. The mirror dry-run is the main reason to hand it to an agent.
  • Backblaze B2 CLI (b2): B2 buckets, files, keys, replication, sync, removals, and JSON output.
  • s5cmd: High-volume S3 operations with command files, dry-runs, and structured logs.
  • rclone: Copy, compare, check, and sync files across many storage providers.
  • restic: Encrypted backups with addressable snapshots, checks, restores, and JSON output for scripting.

Queues, Streams, And Realtime

  • NATS CLI: Streams, consumers, KV, object stores, schemas, events, messages, benchmarks, and named contexts.
  • Redpanda rpk: Kafka-compatible topics, records, offsets, consumer groups, schemas, and cluster analysis. Record consumption can be bounded and emitted as JSON.
  • RabbitMQ rabbitmqadmin: Broker inspection plus definition export and import workflows. Treat imports as live mutations.
  • Confluent CLI (confluent): Confluent environments, Kafka clusters, topics, consumers, connectors, schemas, Flink, API keys, audit settings, and JSON or YAML output.
  • Temporal CLI (temporal): Local Temporal dev server, namespaces, workflows, activities, schedules, task queues, JSON output, API keys, and mTLS. Workflow mutations have no preview.
  • ntfy CLI: Notification publishing and subscription streams from shell scripts.

Observability And Incidents

  • Grafana CLI (gcx): Grafana resources, contexts, validation, dry-run pushes, and scriptable output.
  • Grafana LogCLI: Bounded LogQL queries against Loki with JSONL output.
  • New Relic CLI: NRQL, NerdGraph, entities, workloads, deployments, profiles, and JSON output by default.
  • Datadog datadog-ci: Targeted Synthetic test runs from CI with JSON and JUnit reports.
  • Elastic ecctl: Elastic Cloud deployment inspection and management with explicit deployment IDs and JSON output.
  • Axiom CLI: Query, stream, and ingest Axiom datasets from the terminal.
  • Tailpipe: External logs collected into a local analytical store and queried with SQL.
  • Rootly CLI (rootly): Incidents, alerts, services, teams, on-call shifts, deployment pulses, filtering, pagination, API-token auth, and JSON or YAML output.

Security, Secrets, And Supply Chain

  • 1Password CLI (op): Secret references, vault items, service accounts, op run, and JSON output. Prefer injection over printing secrets.
  • Bitwarden CLI (bw): Vault items, folders, collections, organizations, Send objects, JSON templates, jq workflows, and scripted unlock sessions. Treat bw serve as local secret exposure unless you control the machine.
  • Vault CLI: Vault paths, policies, auth methods, leases, and JSON output. It belongs with narrow tokens.
  • Infisical CLI: Secret sync, injection, project and environment targeting, and CI auth.
  • Doppler CLI: Secrets, projects, configs, audit logs, doppler run, secret downloads, per-command config, and service token auth.
  • SOPS: Encrypted YAML, JSON, ENV, INI, and binary files with reviewable diffs.
  • Gitleaks: Git history, worktrees, files, and stdin secret scans with JSON, CSV, JUnit, and SARIF reports.
  • TruffleHog: Git, GitHub, GitLab, S3, Docker, filesystem, and CI secret scans with verification and JSON output.
  • Trivy: Vulnerability, misconfiguration, secret, SBOM, filesystem, repo, and image scans with JSON and SARIF output.
  • Semgrep: Structural code search and security rules with parseable findings.
  • Snyk CLI: Dependency, code, container, IaC, license, and SBOM scans with JSON and SARIF output.
  • Syft: SBOM generation for containers and filesystems in JSON, SPDX, and CycloneDX formats.
  • Grype: Vulnerability scans for images and SBOMs with JSON output and severity gates.
  • Cosign: Container image and blob signing, verification, attestations, and keyless Sigstore workflows.
  • OpenSSF Scorecard: Repository supply-chain checks for GitHub or local repos, with JSON output for policy gates.
  • OSV-Scanner (osv-scanner): Source trees, lockfiles, SBOMs, Git data, and images scanned against OSV, with JSON, SARIF, CI, and offline database workflows.
  • CodeQL CLI (codeql): Code databases, standard or custom security queries, SARIF output, and uploads from third-party CI. Compiled-language extraction can run builds.
  • Checkov: Infrastructure-as-code policy checks with JSON, SARIF, JUnit, and CI exits.
  • TFLint: Terraform linting with provider-aware rules before a full plan.

API Contracts, Testing, And Replay

  • oasdiff: Semantic OpenAPI diffs, breaking-change checks, changelogs, JSON or YAML reports, and CI exits.
  • Redocly CLI: OpenAPI, AsyncAPI, and Arazzo linting and bundling with configurable rules and parseable output.
  • Vacuum: OpenAPI, AsyncAPI, and JSON Schema linting with Spectral-compatible rules and parseable reports.
  • Buf CLI: Protobuf linting, formatting, generation, and breaking-change detection with JSON, JUnit, GitHub Actions, and GitLab output formats.
  • Schemathesis: Property-based tests from OpenAPI or GraphQL, with JUnit, VCR, HAR, and NDJSON reports. Filter mutating endpoints unless they are part of the test.
  • Postman CLI: Collection runs, API tests, spec linting, monitors, Postman workspace sync, and JSON, JUnit, or HTML reports.
  • Newman: Postman collection runs from local files or URLs with CLI, JSON, JUnit, and progress reports.
  • k6: Scriptable load tests with thresholds, summaries, and JSON or NDJSON result streams.
  • Hurl: Plain-text HTTP requests with captures, assertions, and report formats.
  • Bruno CLI (bru): Local runs for Git-friendly API collections, with JSON, JUnit, and HTML reports.
  • Insomnia CLI (inso): Insomnia collection runs, spec linting, config generation, and API test suites for CI.
  • Hoverfly hoverctl: HTTP capture, simulation, diff, and replay using portable simulation files.
  • Mockoon CLI: Headless mock APIs from Mockoon or OpenAPI definitions.

Content, CMS, And Media

  • Sanity CLI: Query, inspect, export, and manage Sanity datasets and documents from scripts.
  • Contentful CLI: Contentful space and environment export, migration, and import through JSON files.
  • Directus schema tooling: Directus schema snapshot, diff, and apply between environments.
  • DatoCMS CLI (datocms): Schema migrations, environment diffs, dry-runs, sandbox forks, promotion, maintenance mode, and API-token auth for CI.
  • Storyblok CLI (storyblok): Stories, assets, components, datasources, local JSON artifacts, migrations, dry-runs, snapshots, rollback, and schema diffs.
  • WP-CLI: WordPress content, users, plugins, themes, options, cron, cache, and database operations. The search-replace --dry-run path is worth special attention.
  • Cloudinary CLI (cld): Cloudinary asset search, export, upload, transform, and management.
  • Mux CLI: Video assets, live streams, playback IDs, signed URLs, and local webhook listen, replay, and trigger flows.
  • Shopify CLI: Apps, themes, extensions, functions, deploys, and local previews for Shopify projects.
  • Ghost CLI: Ghost install, upgrade, backup, restart, logs, and diagnostics.

Workspace, CRM, Email, And Messaging

  • Asana CLI (asana): Tasks, projects, comments and other Asana resources with stable JSON output. Supported writes accept --dry-run; previews can still read live state. Unofficial, MIT-licensed and pre-1.0. Maintained by this list’s maintainer.

  • Slack CLI (slack): Slack apps, manifests, triggers, workflows, datastores, app deploys, local run, and logs.

  • Google Workspace CLI (gws): Drive, Gmail, Calendar, Sheets, Docs, Chat, and Admin APIs with JSON-first output. It is pre-1.0 and community-run.

  • CLI for Microsoft 365 (m365): Microsoft 365, Entra ID, Teams, SharePoint, Planner, and Outlook automation with JSON output and JMESPath queries.

  • Notion CLI (ntn): Notion auth, API requests, data sources, file uploads, and Notion Workers.

  • Airtable MCP CLI (airtable-mcp): Airtable bases and records through Airtable's MCP server, with profiles, JSON tool discovery, stdin JSON input, and changing server-side tool schemas.

  • Linear CLI (linear): Unofficial Linear issues, teams, projects, milestones, documents, comments, attachments, branches, and JSON output on query, list, and view commands.

  • HubSpot CLI (hs): HubSpot apps, CMS assets, developer projects, serverless functions, uploads, downloads, and account auth.

  • Salesforce CLI (sf): Orgs, metadata, scratch environments, deploy validation, and JSON output.

  • Twilio CLI: Twilio resources through generated commands, profiles, test credentials, and full JSON API responses.

  • Mattermost mmctl: Server administration over local socket or remote API with JSON output.

  • notmuch: Search, thread, tag, dump, and restore for a local mail corpus, with stable message and thread IDs.

  • Himalaya: IMAP and Maildir operations from the terminal. Test error behavior on your setup before relying on it.

  • Resend CLI: Domains, API keys, contacts, broadcasts, emails, and webhooks with JSON mode outside a TTY.

  • Postmark CLI (postmark): Transactional email sends, server lookup, and template pull or push for CI. It is narrower than Resend.

Payments, Commerce, And Finance

  • Stripe CLI: Webhooks, test events, fixtures, logs, and sandboxed Stripe flows. Keep agents in test mode unless live access is intentional.
  • Ramp CLI: Ramp finance flows with --agent, --no-input, pagination, dry-runs for common actions, and a sandbox-first setup.

Still Looking For

Gaps to research next: maintained CLIs for PagerDuty or Opsgenie incident work, HubSpot CRM data, Help Scout or Zendesk queues, ad platforms, analytics exports, product analytics, data lineage, marketplace operations, and niche CLIs people actually use with agents.

Contributing

Add CLIs that are worth giving to an AI agent. A tool does not belong here just because it has a command.

See criteria.md. One tool per pull request. Link the primary docs, and mention the sharp caveat.

Maintainer

Maintained by Vincent Schmalbach (rungrad).

Vincent builds Go CLIs, SaaS automation, and internal developer tools for clients.

License

CC0

ai-agents
awesome-list
cli
command-line