Skip to content

feat: add kody api command mirroring MCP api tool - #19

Merged
kody-bot merged 1 commit into
mainfrom
cursor/cli-api-command-b06c
Oct 1, 2026
Merged

kody-bot merged 1 commit into
mainfrom
cursor/cli-api-command-b06c

Conversation

@kentcdodds

Copy link
Copy Markdown
Owner

Why

Agents and scripts with CLI auth (auth bootstrap / KODY_API_TOKEN) need a way to call any Open API operationId without going through MCP. This adds a thin CLI twin of the MCP api tool.

Usage

# Auth: --token / KODY_API_TOKEN → stored auth bootstrap token
kody api usageGet --params '{}'
kody api metaGetCurrentUser --params '{}'
kody api search --params '{"query":"email","limit":5}'

Same shape as MCP api: operationId + flat params object (path/query/body fields together). Resolves method/path from https://api.kody.codes/openapi.json. Always prints JSON.

Auth

Uses existing requireApiToken / resolveScopedApiToken:

  1. --token / KODY_API_TOKEN
  2. Stored bootstrap/API token from kody auth bootstrap --code
  3. Clear error (Open API needs a scoped kody_at_…; kody login OAuth is not accepted for general /v1 ops)

Safety

  • Refuses cliCredentialBootstrapRedeem — redeem returns a token; use kody auth bootstrap --code instead (stores, never prints).
  • tokenCreate / tokenRotate still work and may print a one-time token value (same as MCP api); prefer env storage over pasting into chat.
  • Errors go through existing redaction for kody_at_ / kody_bc_.

Scope kept small

No api list / operation discovery CLI beyond a clear unknown-operationId error pointing at /openapi.json.

Version bump

Repo uses semantic-release (0.0.0-semantically-released). This feat: commit will publish a minor bump on merge to main. No manual package.json version edit.

Verification

  • npm run validate (typecheck, tests, build) — green locally
  • Live smoke (after auth bootstrap): kody api usageGet --params '{}' → { "plan": "pro", ... }
  • Unit/integration coverage for OpenAPI indexing, path/query/body split, unknown op, redeem refusal, and CLI end-to-end with mocked fetch

Relation to MCP api

Identical call shape (operationId + params). MCP invokes operations in-process; the CLI loads /openapi.json and issues the corresponding HTTPS request with a scoped Bearer token.

Open in Web Open in Cursor 

Thin Open API wrapper: operationId + flat --params JSON, with the same
scoped-token auth as whoami/search/execute. Refuses bootstrap redeem so
tokens are never printed; prefer auth bootstrap instead.

Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
@kody-bot

kody-bot commented Oct 1, 2026

Copy link
Copy Markdown
Owner

bugbot run

@cursor

cursor Bot commented Oct 1, 2026

Copy link
Copy Markdown

Skipping Bugbot: Unable to authenticate your request. Please make sure Bugbot is properly installed and configured for this repository.

@kentcdodds

Copy link
Copy Markdown
Owner Author

bugbot run

@cursor

cursor Bot commented Oct 1, 2026

Copy link
Copy Markdown

Skipping Bugbot: Bugbot is disabled for this repository. Visit the Bugbot dashboard to update your settings.

@kody-bot
kody-bot merged commit 80ef4fb into main Oct 1, 2026
5 checks passed
@kody-bot
kody-bot deleted the cursor/cli-api-command-b06c branch October 1, 2026 23:59
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown

🎉 This PR is included in version 1.9.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants