CLI

CLI command reference

Last updated

Every command, flag, and REPL shortcut in tempr — plus the tool set the agent drives. New here? Start with the CLI quickstart.

Commands

CommandDoes
tempr "<prompt>"One-shot agent turn: a real tool-calling loop that reads, edits, runs commands, and searches your codebase, then exits.
temprInteractive REPL with persistent cross-session history, line editing, and tab-completion for /commands and @personas.
<something> | temprHeadless/piped mode — runs one turn and writes to stdout. With no prompt argument, stdin is the whole prompt; with one (git diff | tempr "review this"), the piped text follows the prompt as context. See Scripts, pipes & CI.
tempr auth [<LICENSE_KEY>]Sign in. With no key, choose between your browser and pasting your license key (the same license as the IDE). Through the browser, it shows a code and opens the Tempr portal, where you approve the sign-in — on any device, so it works over SSH too; --browser goes straight there. For scripts and CI, pass the key or set TEMPR_LICENSE_KEY. After signing in, it offers to add a provider key if you have none, then to pick a default model.
tempr acpRun as an Agent Client Protocol agent, for an editor such as Zed or JetBrains AI Assistant to start and talk to over stdin and stdout.
tempr logoutClear the stored credential on this machine.
tempr keysYour provider keys — Tempr calls every model with your own key for its provider. list (also plain tempr keys), add [provider] to add or replace one (no provider opens a picker), and remove <provider>. The key is typed at a hidden prompt, piped in on stdin, or read with --from-env <VARIABLE>; it's never passed as an argument, where it would land in shell history. Tempr checks the key with the provider before saving it: one the provider rejects isn't saved unless you confirm or pass --force, and one that couldn't be checked is saved with a note. Azure, AWS Bedrock and custom endpoints are set up on the Portal's Provider keys page instead, and on a Team plan your organization's admin manages keys.
tempr configManage settings: show, set-model <id> (your default model), set-approval-mode <interactive|autopilot|bypass>, allow-command <prefix> / disallow-command <prefix> (the run_command allow-list), allow-site <site> / disallow-site <site> (sites the agent opens pages on without asking: docs.example.com, or *.example.com for its subdomains), set-web-search <on|off> (whether interactive sessions search the web), set-notifications <on|off> (the bell and desktop notification after a long turn), set-sandbox <on|network|off|auto> (whether every run's commands go in the sandbox; auto, the default, sandboxes --yolo and CI runs), and set-crash-reports <on|off>.
tempr historySaved sessions: list (this folder's; --all for every folder's), show <id>, rename <id> <title>, fork <id>, and delete <id>. Resume one with tempr --id <SESSION_ID>.
tempr mcpMCP servers for the terminal agent: list, browse [query] (install from Tempr's curated catalog), add <name> [--cwd <dir>] [--env KEY=VALUE] -- <command> [args...], and remove, enable, and disable, each taking the server's name.
tempr doctorCheck the config directory, server connectivity, sign-in, the model catalog, your default model, and your MCP servers (--skip-mcp to leave those unstarted), and says what the sandbox can do on this machine. Exits 1 if any check fails, including a sandbox turned on that can't run here.
tempr models [filter]List the models your license can use, with prices and context sizes. --ids-only prints one id per line.
tempr usageShow what this machine's turns have cost, by model. --range today|week|month|all (default week); --json for machine-readable totals.
tempr initDraft an AGENTS.md for this workspace from a scan of what's in it. --print writes it to stdout; --force overwrites an existing file.
tempr completion <shell>Print a shell completion script for bash, zsh, fish, or powershell.
tempr updateCheck for a newer release and print the command that installs it. --check only reports, exiting 1 when an update is available.
tempr --versionPrint the installed CLI version (also -v, or tempr version).

Options

These flags apply to a chat or agent run:

FlagDoes
-m, --model <MODEL>Use this model for the run, overriding tempr config set-model.
--reasoning <LEVEL>How much the model reasons for this run: none, minimal, low, medium, high, xhigh, max, on, or default. Overrides the level saved with /reasoning for this invocation only; a level the model lacks becomes the nearest one it has.
-y, --yoloRun unattended — approval mode autopilot for this invocation only. File edits, MCP calls, and allow-listed commands run without asking. On Linux its commands run in the sandbox by default, with the network on, so any command goes ahead; elsewhere, commands that aren't allow-listed still ask, and are refused when there's no terminal to ask on. Commands that delete, publish or force-push always ask.
--approval-mode <MODE>Approval mode for this run only: interactive, autopilot, or bypass. Overrides the saved mode without changing it. Note that bypass is stricter than autopilot: file edits run, but every command and MCP call asks.
--askPlain single-turn chat with no tool-calling — quick questions, no file access.
--id <SESSION_ID>Resume a saved session (see tempr history list). A new id is generated and saved automatically when omitted.
-c, --continueResume the most recent session started in this folder.
--jsonEmit newline-delimited JSON (one event per line, then a final result object) instead of formatted text — built for scripting. See the JSON event stream.
--verbosePrint each tool call's full output, and token usage (prompt/completion/total, and cost if known) after each turn.
--max-turns <N>Stop after N steps of the agent loop — guards an unattended run against a model that won't converge. The server clamps it to your plan's ceiling.
--allowed-tools <NAMES>Comma-separated tool names this run may use, e.g. read_file,search_files. An MCP server's name covers all of its tools.
--disallowed-tools <NAMES>Comma-separated tool names this run may not use, applied after --allowed-tools.
--prompt-file <PATH>Read the message from a file instead of the command line — for prompts too long or too quote-heavy to pass as an argument.
--max-cost <usd>Stop once this run's model calls have cost this many US dollars, such as 0.50, sub-agents included. Exits with code 6. Tempr's server enforces it too, stopping a run before its next model call. A model whose price isn't known can't be counted, and the CLI says so. See Capping what a run spends.
--search / --no-searchLet the model search the web for this run, or don't. Without either, an interactive session searches (unless tempr config set-web-search off) and a script (--json, piped input, CI) doesn't. See Web search.
--sandbox / --sandbox-network / --no-sandboxRun this run's commands in the sandbox (Linux), with the network cut off or left on, or not at all, overriding tempr config set-sandbox and the default for --yolo. If a sandbox you asked for can't run here, nothing runs: exit code 7.
--config <PATH>Use a config directory other than ~/.tempr. Works with every command.

REPL slash commands

Inside an interactive tempr session:

CommandDoes
/helpList the slash commands, mentions, approval modes, and flags.
/model [id]Switch the model for this session. No id opens a picker over your catalog.
/reasoning [level]Set how much the current model reasons, saved per model. No level opens a picker over the levels the model offers; default goes back to the model's own.
/persona [name]Switch persona for the rest of the session; no name opens a picker, and /persona none clears it. For a single turn, start the message with @name (Tab completes it).
/mcpList configured MCP servers.
/mcp browse [query]Browse or search Tempr's curated MCP catalog and add a server.
/keysList your provider keys; /keys add [provider] adds one and /keys remove <provider> removes one, without leaving the session.
/resumePick an earlier session from this folder and load its history.
/historyList saved sessions.
/commandsList the command templates you can invoke as /name — built-in, yours in ~/.tempr/commands/, and the workspace's in .tempr/commands/.
/agentsList the built-in personas and your own custom agents (.tempr/agents/ or ~/.tempr/agents/).
/diffShow what the last turn changed on disk.
/undoPut the last turn's file changes back, skipping any file that has changed since.
/clearClear this session's conversation history.
/exitQuit (so do exit, quit, and /quit).
!commandRun a command in this folder yourself — !git status, !npm test — with its output shown as it runs. The output goes in front of your next message, so the agent sees what you saw. Nothing is asked: it's your own command, as if typed in a shell. Ctrl+C stops it.

A turn that runs 30 seconds or more without you rings the terminal bell when it finishes or asks for approval, with a desktop notification in terminals that show one (iTerm2, WezTerm, Ghostty, kitty, rxvt, foot, Konsole). Not in CI or with output redirected; tempr config set-notifications off or TEMPR_NO_NOTIFY turns it off.

The agent tool set

In agent mode, the model drives the same tool families as the IDE — executed locally against your workspace:

Tool familyWhat it does
FilesRead, write, and edit files (read first, then targeted edits).
run_commandRun shell commands, gated by the command-safety allow-list: read-only commands and each ecosystem's build, test, lint and type-check commands (dotnet test, npm test, npm run build, pytest, go test, cargo test, mvn test, ./gradlew build and the like). A command runs in the workspace root or a folder inside it, stops after 2 minutes unless the model asks for up to 10, and long output keeps its start and end. Each turn tells the model which projects the workspace holds and how each builds and tests. In the sandbox, any command may run instead.
Semantic searchEmbedding-based search over the workspace — finds conceptually related code.
SymbolsFind where a name is defined before the places it's used, in C#, TypeScript and JavaScript, Python, Go, Rust, Java, Kotlin, C and C++, Swift, Ruby and PHP, and what a function calls. Lexical, not a language server.
TestsDiscover and run .NET tests with structured pass/fail results. Other projects run their own test command through run_command.
DiagnosticsRead compiler and analyzer diagnostics from dotnet build, or tsc for a TypeScript project at the root.
Workspace graphA .NET workspace's projects and their references, and call-graph context. The .NET-only tools are offered only where there's a .NET project.
Sub-agent delegationHand a focused sub-task to a specialist persona mid-turn.
MCP bridgeExpose tools from your configured MCP servers.
Web pages and packagesweb_fetch reads a page as Markdown and lookup_package finds a package's latest version and links on npm, PyPI, crates.io, the Go module proxy, NuGet or Maven Central. Both run on Tempr's servers, not your machine.
Web searchOn an Anthropic, OpenAI or xAI model, the model searches the web with its provider's own search. See Web search.

Which pages the agent opens

Without asking, the agent opens a link that appeared in your messages, in a tool's result, or on a page it has already read in this session, and any page of a well-known documentation site such as docs.python.org, developer.mozilla.org or learn.microsoft.com. For any other address it asks first:

  • Yes opens that one page.
  • Yes, and trust <site> for this session also opens that site's other pages without asking until you exit.
  • No, or No, and tell the agent why, opens nothing.

To stop being asked about a site for good, run tempr config allow-site <site>. With no terminal to ask on (piped input, --json, or CI set), an address that would have asked is refused and the agent is told why. Every approval mode asks, since reading a page the agent chose can send what's in the address to that site. A URL that carries a key, token or password is only opened if you typed that credential yourself. Tempr's servers can't reach localhost or your own network; for those the agent uses curl through run_command, which you approve like any command. --disallowed-tools web_fetch turns page reading off for a run.

On a Claude model through your Anthropic key, an OpenAI model through your OpenAI key, or a Grok model through your xAI key, the agent can search the web with the provider's own search tool. Each search shows as Searching the web for "…", and the pages it finds are ones the agent may then open with web_fetch without asking. Other providers' models don't search; web_fetch and lookup_package still work for them.

The provider runs each search and bills it to your key: $10 per 1,000 searches on Anthropic and OpenAI, and $5 per 1,000 on xAI, where opening a page counts as a search too, plus the tokens the results add. The cost tempr usage and the Portal's usage page show includes the searches.

An interactive session searches unless you turn it off with tempr config set-web-search off. A script (--json, piped input, or CI set) doesn't, so a CI job's cost and output don't depend on what the web says that day; pass --search to let it. --no-search or --disallowed-tools web_search turns it off for one run.

Sandbox (Linux)

--sandbox runs the agent's commands inside a sandbox: they can change files only in the current folder, the temp folders and the package stores and caches builds write to (npm's, pip's, NuGet's, Go's, Cargo's, Gradle's and Maven's), and they can't open network connections. Reading is open. tempr config set-sandbox on turns it on for every run, and --no-sandbox off for one.

On by default for --yolo and CI. A run on autopilot with nobody deciding command by command (--yolo, --approval-mode autopilot, or autopilot in CI) runs its commands in the sandbox with the network on: the file limits hold, and installs, restores and tests that use localhost still work. Where the sandbox can't run, those runs go ahead unsandboxed, as before, and an interactive session says so. --sandbox cuts off the network as well; --no-sandbox, or tempr config set-sandbox off, keeps --yolo out of the sandbox. Other runs aren't sandboxed unless you ask, since the sandbox would let their commands run without asking.

Inside it, any command runs without asking, in every approval mode, so an unattended run can build, test and try things that have no allow-list entry. Commands that delete, publish or force-push still ask. When a command fails because the sandbox blocked it, a download say, the agent can ask to run it outside the sandbox, which always asks you first; a run with nobody to ask refuses it.

  • What it covers: run_command, the .NET test tools and get_diagnostics. Not !command, which you type yourself, and not MCP servers.
  • Git hooks: a command may not keep changes to .git/hooks, .git/config or .agentcommands.json, which run or allow things later, outside the sandbox. Tempr puts back anything a command changed there, and tells the agent.
  • dotnet: in the sandbox it keeps its own per-user files in ~/.cache/tempr/sandbox-dotnet rather than ~/.dotnet, which holds global tools and stays read-only. It restores into your own ~/.nuget/packages and reads your NuGet package sources.
  • The network: --sandbox-network (or set-sandbox network) keeps the file limits and leaves the network on. Cutting it off blocks TCP connections, so name lookups still work.
  • Where it runs: Linux 5.13 or later, and 6.7 or later to cut off the network, through the kernel's Landlock. It needs no install and no privileges, and works in a container and on Ubuntu 24.04. It isn't available on macOS or Windows yet; inside WSL2 it works. If you ask for it where it can't run, nothing runs: tempr exits with code 7 rather than run your commands unsandboxed. The default for --yolo and CI isn't asking, so it doesn't stop a run.
Tip

The agent loop runs server-side like the IDE, so a dropped connection doesn't lose an in-flight turn — and every session is saved automatically, ready to resume with tempr --id.

Next steps