* fix: auto-discover OS trust anchors in the CLI wrapper
The 3.x CLI ships as a Bun-compiled binary. Bun does not read the OS
trust store unless NODE_USE_SYSTEM_CA is set, and even with the flag its
Windows enumeration covers only the `Root` store, not `CA`/Intermediate
(verified empirically across the CLINE-2353 Windows repro rounds). So a
corporate MITM root is not trusted out of the box and inference fails
with "unable to get local issuer certificate". The pre-3.0 (Node) CLI
had no app-level CA handling either; users only succeeded by setting
NODE_EXTRA_CA_CERTS manually. The reporter's ask: have it just work
without the env var.
This follows the CLINE-2353 SDK fetch-threading change. That made the
inference client honor a host-provided proxy/CA-aware fetch, but on the
CLI Bun's global fetch is already proxy-aware and a fetch function
cannot cross the hub-daemon process boundary, so the CLI's missing piece
is trust material, not the fetch. Env vars do inherit across spawns.
The npm `bin/cline` wrapper runs on Node (not Bun), so it can read the
full OS store via tls.getCACertificates("system") (Node >= 22, no flag
required) — including the Windows `CA` store Bun skips — and hand the
certs to the Bun child via NODE_EXTRA_CA_CERTS, which both runtimes
honor. This mirrors the JetBrains plugin's configureCertificates(),
replacing "harvest from the IDE trust store" with "harvest from the OS".
The merge logic lives in a dependency-free, injectable-module CommonJS
helper (bin/ca-certs.cjs) so it is unit-testable and ships verbatim in
the generated wrapper package (publish copies bin/ wholesale). A
user-set NODE_EXTRA_CA_CERTS is merged ahead of the system certs; a
self-reference to the managed bundle is detected to avoid re-appending
every launch; when no system certs are available the user's setting is
left untouched. Writes are atomic (temp + rename) and owner-only.
Adds ca-certs.test.ts (13 cases) covering harvest filtering, user-bundle
PEM/DER/missing handling, newline-separated merge, managed-path
self-reference, and the no-system-certs no-op.
* fix: harden CLI auto-CA harvesting (review follow-ups)
Follow-ups from the CLINE-2353 review of the CLI auto-CA wrapper.
- H1: a legacy NODE_EXTRA_CA_CERTS set to an OS-path-delimited list
("a.pem;b.pem", the CLINE-2324 footgun Node never split) was stat'd as
one file, failed, and silently dropped the user's certs. readUserCerts
now tries the whole value as one file first, then splits on the OS path
delimiter and reads each existing PEM, merging them all.
- M1: skip the rewrite when the managed bundle is already current, instead
of re-harvesting and rewriting on every launch (mirrors the JetBrains
hash-and-skip). configureNodeExtraCaCerts now returns a typed outcome
(unchanged | written | write-failed-reused | write-failed |
no-system-certs) with cert counts.
- M2: tolerate rename-over-existing failures (Windows EPERM/EBUSY when a
concurrent child holds the file open) by removing the target and
retrying, then falling back to a previously-written bundle. Combined
with M1 the steady state no longer rewrites at all.
- M3: the wrapper prints a one-line diagnostic under CLINE_DEBUG=1
(cert counts + managed path, or a warning when no OS certs were found
or the write failed). Runs once per startup.
- M4: corrected the now-stale CLI guidance in shared/net.ts (the CLI no
longer requires users to set NODE_EXTRA_CA_CERTS manually).
- L1: documented the auto-trust behavior, the managed ~/.cline bundle,
the merge-not-replace override semantics, and CLINE_DEBUG in the CLI
README.
- L4: trimmed the helper's file header; DI is still injectable for tests.
ca-certs.test.ts grows to 20 cases: adds readUserCerts (single path,
delimited split, missing-segment skip, managed-bundle exclusion, empty),
the unchanged/second-run skip, and a write-failure outcome via an
fs that throws.
* fix: address CLI auto-CA review issues (temp cleanup, cert count, test)
- writeBundle now hoists the temp path so the outer catch removes a
partially-written temp file (e.g. ENOSPC / ACL failure mid-write).
Previously only the inner double-rename failure cleaned up, so repeated
disk-full/permission failures left a stale .tmp per launch in ~/.cline.
The inner Windows-rename fallback now lets its failure fall through to
the single cleanup path instead of duplicating rmSync.
- userCertCount now counts individual certificates (via countCerts, which
tallies BEGIN CERTIFICATE markers) rather than the number of PEM files,
so a user bundle with N intermediates reports N and is comparable to
systemCertCount. countCerts is exported for testing.
- Adds tests for the write-failed-reused branch (stale bundle reused when
the rewrite fails but the old file is still readable) and for countCerts
(one file holding two certs reports 2).
* fix: warn when the CLI wrapper's Node cannot read the OS trust store
tls.getCACertificates("system") needs Node >= 22.15; on older hosts the
auto-CA harvest silently did nothing, which is indistinguishable from a
broken corporate proxy. Distinguish the missing-API case as its own
outcome (api-unavailable) and print a non-debug warning when the user
has no NODE_EXTRA_CA_CERTS of their own. Found in round-5 Windows
validation (wrapper under Node 22.1.0).
* fix: copy only certificate blocks into the managed CA bundle
Combined cert+key PEMs (nginx/haproxy-style server.pem) passed the
old contains-a-certificate check, so a user NODE_EXTRA_CA_CERTS
pointing at one duplicated the private key into the managed bundle,
where it outlives rotation of the original and gets no permission
tightening on Windows. Extract complete BEGIN/END CERTIFICATE blocks
instead; files with none are treated as not PEM, and certificates-only
files pass through byte-identical so the unchanged-skip stays stable.
Raised in PR review.
* fix: show the old-Node trust warning once per Node version
The api-unavailable warning printed on every CLI invocation, turning
an actionable nudge into stderr noise for users pinned to an old Node.
Stamp the warning per Node version under the cline dir: it shows once,
re-arms when the Node version changes, and a bookkeeping failure never
suppresses the diagnostic. Raised in PR review.
16 KiB
Cline CLI
Run Cline in your terminal. Interactive chat for paired sessions, or fully headless for CI/CD and scripting. The CLI shares its agent core with the Cline VS Code extension, JetBrains plugin, and SDK, so plan/act modes, MCP servers, checkpoints, rules, skills, and provider configuration all behave the same across surfaces.
Install
npm install -g cline
For nightly builds:
npm install -g cline@nightly
Platform binaries are published for macOS, Linux, and Windows on arm64 and x64. The cline package resolves the correct binary for your platform via optional dependencies, so no Node, Bun, or Zig runtime is required at install time.
Quick start
Run interactively:
cline
Run a single prompt:
cline "Audit this package and propose fixes"
Pipe input:
cat file.txt | cline "Summarize this"
See cline --help for the full flag reference.
Use any provider
Cline supports the same providers as the VS Code extension. You can sign in to Cline directly, use your ChatGPT Subscription through openai-codex, or bring an API key from Anthropic, OpenAI, Google Gemini, OpenRouter, AWS Bedrock, GCP Vertex, Cerebras, Groq, and any OpenAI-compatible endpoint.
cline auth # interactive sign-in
cline auth cline # OAuth sign-in
cline auth --provider anthropic --apikey sk-... --modelid claude-sonnet-4-6
cline auth without a provider opens the interactive auth setup TUI with the same options as the old CLI flow (Sign in with Cline, Sign in with ChatGPT Subscription, Sign in with OCA, or use your own API key).
OAuth-supported providers (cline, openai-codex, oca) do not auto-launch a browser on normal startup. Authenticate explicitly first with cline auth <provider>. For non-interactive runs, if an OAuth provider is selected and no saved credentials are available, cline fails fast with an authentication message instead of launching a hidden browser flow.
Modes
Cline CLI runs in a few different shapes depending on what you need:
- Interactive TUI:
clineorcline -iopens a full terminal UI with plan/act toggle, slash commands, file mentions, and live tool approvals - One-shot:
cline "your prompt"runs a single turn and exits - JSON:
cline --json "..."streams NDJSON events for piping into other tools - Yolo:
cline --yolo "..."skips approval prompts and exits when the turn finishes - Zen:
cline --zen "..."fires the task to the background hub daemon and exits immediately (see below)
Headless mode for CI/CD
Run Cline with zero interaction for scripting and automation. Pipe input, get JSON output, chain commands, integrate into CI/CD pipelines.
# One-shot prompt, auto-approve all tools
cline --yolo "Run tests and fix any failures"
# Pipe a diff in for review
git diff origin/main | cline "Review these changes for issues"
# NDJSON output for downstream tooling
cline --json "List all TODO comments" | jq -r 'select(.type == "agent_event" and .event.text) | .event.text'
Features
- Streaming TUI built on OpenTUI with markdown rendering, syntax-highlighted diffs, scrollable chat, and mouse support
- Plan/Act mode toggle for switching between planning and execution
- Native MCP support for connecting custom tools
- Checkpoints with
/undoto rewind workspace state - Sub-agent spawning and agent teams for parallel work
- OAuth login for Cline, ChatGPT Subscription (
openai-codex), and OCA - Configurable thinking budgets per run
- Cron and event-driven schedules for recurring agent work
- Chat connectors for Telegram, Google Chat, and WhatsApp
Usage
# Start Cline CLI without a prompt to enter interactive mode
cline
# Single prompt (one-shot) - includes tools, spawn, and teams
cline "Audit this package and propose fixes"
# Interactive mode with a starting prompt
cline -i "Let's work on this together. First, analyze the current state."
# With a custom system prompt
cline -i -s "You are a pirate" "Tell me about the sea"
# Require approval before each tool call
cline --auto-approve false "Inspect and modify this repository"
# Explicit yolo: enables submit_and_exit and disables spawn/team tools by default
cline --yolo --retries 5 "Refactor this package"
# Override consecutive internal mistake (retry) limit (default: 3)
cline --retries 5 "Fix failing tests"
# Team workflow with persistent name
cline --team-name my-team "Plan, implement, and verify release checklist"
cline --team-name my-team "Continue yesterday's team workflow"
# Show verbose run stats (elapsed time, tokens, estimated cost when available)
cline -v "Explain quantum computing"
# Use a specific provider, model, and access token for a single prompt
cline -P openrouter -m google/gemini-3-pro -k sk-... "Set up a storybook"
# Use a different model with the last used provider
cline -m anthropic/claude-opus-4-6 "Explain string theory"
# Stream structured NDJSON output
cline --json "Summarize this repository"
# Quick provider setup
cline auth --provider anthropic --apikey sk-... --modelid claude-sonnet-4-6
cline auth --provider openai-native --apikey sk-... --modelid gpt-5 --baseurl https://api.example.com/v1
MCP servers
Manage MCP servers with the interactive wizard:
cline mcp
cline config mcp
Open the add-server wizard with the name, transport, and command or URL already filled in with cline mcp install (cline mcp add also works). Stdio servers use everything after -- as the command and arguments:
cline mcp install fs -- npx -y @modelcontextprotocol/server-filesystem /tmp
Remote HTTP and SSE servers take a name, transport, and URL. The wizard still asks for auth details before saving:
cline mcp install ctx7 --transport http https://mcp.context7.com/mcp
cline mcp install events --transport sse https://example.com/sse
Because this command opens the wizard, it requires a TTY.
Connectors
Bridge a chat surface into RPC-backed Cline sessions. Each conversation thread maps to a session with full context. Supported platforms: Telegram, Slack, Google Chat, WhatsApp, and Linear.
# Telegram (polling mode)
cline connect telegram -k 123456:ABCDEF...
# Slack (webhook mode)
cline connect slack --bot-token $SLACK_BOT_TOKEN --signing-secret $SLACK_SIGNING_SECRET --base-url https://your-domain.com
# Slack (socket mode)
cline connect slack --bot-token $SLACK_BOT_TOKEN --app-token $SLACK_APP_TOKEN
# Google Chat (webhook mode)
cline connect gchat --base-url https://your-domain.com
# WhatsApp (webhook mode)
cline connect whatsapp --base-url https://your-domain.com
# Linear (webhook mode)
cline connect linear --api-key $LINEAR_API_KEY --base-url https://your-domain.com
# Stop connector bridges and delete their sessions
cline connect --stop
cline connect --stop telegram
In chat surfaces, connector slash commands include /help, /start, /new, /clear, /whereami, /tools, /yolo, /cwd <path>, /schedule, /abort, and /exit. Run cline connect <adapter> --help to see the full flag list for any adapter.
Schedules
Schedule agents on cron-like intervals or external events.
cline schedule create "Daily code review" \
--cron "0 9 * * MON-FRI" \
--prompt "Review PRs opened yesterday and summarize issues." \
--workspace /path/to/repo \
--provider cline \
--model openai/gpt-5.3-codex \
--timeout 3600 \
--tags automation,review
cline schedule list
cline schedule get <schedule-id>
cline schedule trigger <schedule-id>
cline schedule history <schedule-id> --limit 20
cline schedule export <schedule-id> > daily-review.yaml
cline schedule import ./daily-review.yaml
Schedules can route results back to chat surfaces with --delivery-adapter, --delivery-bot, and --delivery-thread.
Options
| Flag | Description |
|---|---|
-s, --system <prompt> |
Override the system prompt |
-P, --provider <id> |
Provider id (default: cline) |
-m, --model <id> |
Model id (default: anthropic/claude-sonnet-4.6) |
-k, --key <api-key> |
API key override for this run |
-p, --plan |
Run in plan mode (default is act mode) |
-i, --tui |
Interactive TUI multi-turn mode |
-t, --timeout <seconds> |
Optional run timeout in seconds |
-c, --cwd <path> |
Working directory for tools |
--config <path> |
Configuration directory (used for CLI home resolution) |
--hooks-dir <path> |
Additional hooks directory hint for runtime hook injection |
--acp |
ACP (Agent Client Protocol) mode |
--thinking [none|low|medium|high|xhigh] |
Model thinking level when supported. Defaults to medium when the flag is provided without a level; thinking is off when the flag is omitted. |
--compaction <agentic|basic|off> |
Context compaction mode. Defaults to basic; use agentic for LLM compaction or off to disable. |
--retries <count> |
Maximum consecutive mistakes (retries) before halting (default: 3) |
--json |
Output NDJSON instead of styled text |
--data-dir <path> |
Use isolated local state at <path> instead of ~/.cline (enables sandbox mode automatically) |
--auto-approve [true|false] |
Set tool auto-approval for all tools |
--kanban |
Run the external kanban app |
-y, --yolo |
Skip tool approval prompts, enable submit_and_exit, and disable spawn/team tools by default |
-z, --zen |
Dispatch the task to the background hub and exit the CLI immediately |
--team-name <name> |
Override the runtime team state name |
-h, --help |
Show help and exit |
-v, --verbose |
Show verbose runtime diagnostics |
-V, --version |
Show version and exit |
--json is non-interactive and requires either a prompt argument or piped stdin. --key takes precedence over environment variables.
Top-level commands
cline config- Open the interactive config viewcline history|h [options]- List session history or manage saved sessionscline version- Show CLI versioncline update [options]- Check for CLI and kanban updatescline auth <provider>- Authenticate or seed provider credentialscline connect <adapter>- Run a chat connector bridge (telegram,gchat,whatsapp)cline connect --stop [adapter]- Stop connector bridge processes and their sessionscline schedule <command>- Create and manage scheduled runscline doctor- Inspect local CLI health and stale processescline doctor fix- Kill stale local RPC listeners and old CLI processescline doctor log- Open the CLI runtime log filecline hook- Handle a hook payload from stdincline hub- Manage the local hub daemoncline kanban- Run the externalkanbanapp, installing it first when needed
Zen mode
--zen (alias -z) runs a task in the background hub daemon and exits the CLI immediately. It is intended for long-running tasks you want to fire off and walk away from.
cline --zen "Refactor the authentication module and add unit tests"
Behavior:
- The CLI starts (or reuses) the local hub daemon, submits the task, then exits. It does not stream output or stay attached to the session.
- Because there is no human in the loop once the CLI exits, zen sessions run with full tool auto-approval (same semantics as
--yolo).spawn/teamtools are disabled by default for safety, consistent with yolo-mode defaults. - If the Cline menubar app is running, it subscribes to hub
ui.notifyevents and will surface a system notification when the task completes. - If the menubar app is not running, there is no live UI for the task. Use
cline historylater to find the session and inspect the result. --zenis incompatible with--data-dir(the implicit sandbox requires a local backend that exits with the CLI) and with--tui(there is no terminal UI to render into).
Tool approval
Tool calls are auto-approved by default. Use --auto-approve false to require review before tool execution.
cline --auto-approve false "Inspect and modify this repository"
When approval is required, the CLI prompts in TTY mode:
Approve tool "<tool_name>" with input <preview>? [y/N]
- Enter
yoryesto approve. - Enter anything else (or press Enter) to reject.
- If stdin/stdout is not a TTY, required-approval calls are denied in terminal mode.
Desktop-integrated approval mode is also supported via env wiring (CLINE_TOOL_APPROVAL_MODE=desktop and CLINE_TOOL_APPROVAL_DIR=<path>). In desktop mode, CLI writes a request JSON file and waits for a matching decision JSON file.
Environment variables
ANTHROPIC_API_KEY- API key for AnthropicCLINE_API_KEY- API key for Cline (when using-P cline)OPENAI_API_KEY- API key for OpenAI (when using-P openai)OPENROUTER_API_KEY- API key for OpenRouter (when using-P openrouter)AI_GATEWAY_API_KEY- API key for Vercel AI Gateway (when using-P vercel-ai-gateway)V0_API_KEY- API key for v0 (when using-P v0)CLINE_DATA_DIR- Base data directory for sessions/settings/teams/hooksCLINE_SANDBOX- Set to1to force sandbox modeCLINE_SANDBOX_DATA_DIR- Override sandbox state directoryCLINE_TEAM_DATA_DIR- Override team persistence directoryCLINE_BUILD_ENV- Runtime build mode for SDK-owned subprocess launchesCLINE_DEBUG_HOST- Host for development inspector listeners (default127.0.0.1)CLINE_DEBUG_PORT_BASE- Base inspector port for development child processesCLINE_TOOL_APPROVAL_MODE- Approval mode (desktopuses file IPC; unset uses terminal prompt)CLINE_TOOL_APPROVAL_DIR- Directory for desktop approval request/decision filesCLINE_LOG_ENABLED- Set to0/falseto disable runtime file loggingCLINE_LOG_LEVEL- Runtime log level (trace|debug|info|warn|error|fatal|silent, defaultinfo)CLINE_LOG_PATH- Runtime log file path (default<CLINE_DATA_DIR>/logs/cline.log)CLINE_LOG_NAME- Logger name embedded in runtime log recordsCLINE_DEBUG- Set to1/trueto print wrapper diagnostics (e.g. the CA bundle summary)
--key takes precedence over environment variables.
Certificate trust
The CLI automatically trusts your operating system's certificate store, so it
works behind corporate TLS-inspecting proxies and with self-signed/internal
endpoints without any setup. On launch the cline wrapper harvests the OS trust
anchors and writes them to ~/.cline/cli-node-extra-ca-certs.pem, then points
the runtime's NODE_EXTRA_CA_CERTS at that bundle. The file is regenerated when
it changes and is safe to delete (it is rebuilt on the next run).
If you set NODE_EXTRA_CA_CERTS yourself, your certificates are merged into
that bundle alongside the system store rather than replacing it. Run with
CLINE_DEBUG=1 to see how many OS and user CAs were loaded and where the bundle
was written.
Contributing
See DEVELOPMENT.md for local development setup, monorepo structure, and TUI architecture. See DISTRIBUTION.md for how the CLI is packaged and distributed.