CLI command reference
Last updated
Every command, flag, and REPL shortcut in tempr — plus the tool set the agent drives. New here? Start with the CLI quickstart.
Commands
| Command | Does |
|---|---|
tempr "<prompt>" | One-shot agent turn: a real tool-calling loop that reads, edits, runs commands, and searches your codebase, then exits. |
tempr | Interactive REPL with persistent cross-session history, line editing, and tab-completion for /commands and @personas. |
<something> | tempr | Headless/piped mode — runs one turn and writes to stdout. With no prompt argument, stdin is the whole prompt; with one (git diff | tempr "review this"), the piped text follows the prompt as context. See Scripts, pipes & CI. |
tempr auth [<LICENSE_KEY>] | Sign in. With no key, choose between your browser and pasting your license key (the same license as the IDE). Through the browser, it shows a code and opens the Tempr portal, where you approve the sign-in — on any device, so it works over SSH too; --browser goes straight there. For scripts and CI, pass the key or set TEMPR_LICENSE_KEY. After signing in, it offers to add a provider key if you have none, then to pick a default model. |
tempr acp | Run as an Agent Client Protocol agent, for an editor such as Zed or JetBrains AI Assistant to start and talk to over stdin and stdout. |
tempr logout | Clear the stored credential on this machine. |
tempr keys | Your provider keys — Tempr calls every model with your own key for its provider. list (also plain tempr keys), add [provider] to add or replace one (no provider opens a picker), and remove <provider>. The key is typed at a hidden prompt, piped in on stdin, or read with --from-env <VARIABLE>; it's never passed as an argument, where it would land in shell history. Tempr checks the key with the provider before saving it: one the provider rejects isn't saved unless you confirm or pass --force, and one that couldn't be checked is saved with a note. Azure, AWS Bedrock and custom endpoints are set up on the Portal's Provider keys page instead, and on a Team plan your organization's admin manages keys. |
tempr config | Manage settings: show, set-model <id> (your default model), set-approval-mode <interactive|autopilot|bypass>, allow-command <prefix> / disallow-command <prefix> (the run_command allow-list), allow-site <site> / disallow-site <site> (sites the agent opens pages on without asking: docs.example.com, or *.example.com for its subdomains), set-web-search <on|off> (whether interactive sessions search the web), set-notifications <on|off> (the bell and desktop notification after a long turn), set-sandbox <on|network|off|auto> (whether every run's commands go in the sandbox; auto, the default, sandboxes --yolo and CI runs), and set-crash-reports <on|off>. |
tempr history | Saved sessions: list (this folder's; --all for every folder's), show <id>, rename <id> <title>, fork <id>, and delete <id>. Resume one with tempr --id <SESSION_ID>. |
tempr mcp | MCP servers for the terminal agent: list, browse [query] (install from Tempr's curated catalog), add <name> [--cwd <dir>] [--env KEY=VALUE] -- <command> [args...], and remove, enable, and disable, each taking the server's name. |
tempr doctor | Check the config directory, server connectivity, sign-in, the model catalog, your default model, and your MCP servers (--skip-mcp to leave those unstarted), and says what the sandbox can do on this machine. Exits 1 if any check fails, including a sandbox turned on that can't run here. |
tempr models [filter] | List the models your license can use, with prices and context sizes. --ids-only prints one id per line. |
tempr usage | Show what this machine's turns have cost, by model. --range today|week|month|all (default week); --json for machine-readable totals. |
tempr init | Draft an AGENTS.md for this workspace from a scan of what's in it. --print writes it to stdout; --force overwrites an existing file. |
tempr completion <shell> | Print a shell completion script for bash, zsh, fish, or powershell. |
tempr update | Check for a newer release and print the command that installs it. --check only reports, exiting 1 when an update is available. |
tempr --version | Print the installed CLI version (also -v, or tempr version). |
Options
These flags apply to a chat or agent run:
| Flag | Does |
|---|---|
-m, --model <MODEL> | Use this model for the run, overriding tempr config set-model. |
--reasoning <LEVEL> | How much the model reasons for this run: none, minimal, low, medium, high, xhigh, max, on, or default. Overrides the level saved with /reasoning for this invocation only; a level the model lacks becomes the nearest one it has. |
-y, --yolo | Run unattended — approval mode autopilot for this invocation only. File edits, MCP calls, and allow-listed commands run without asking. On Linux its commands run in the sandbox by default, with the network on, so any command goes ahead; elsewhere, commands that aren't allow-listed still ask, and are refused when there's no terminal to ask on. Commands that delete, publish or force-push always ask. |
--approval-mode <MODE> | Approval mode for this run only: interactive, autopilot, or bypass. Overrides the saved mode without changing it. Note that bypass is stricter than autopilot: file edits run, but every command and MCP call asks. |
--ask | Plain single-turn chat with no tool-calling — quick questions, no file access. |
--id <SESSION_ID> | Resume a saved session (see tempr history list). A new id is generated and saved automatically when omitted. |
-c, --continue | Resume the most recent session started in this folder. |
--json | Emit newline-delimited JSON (one event per line, then a final result object) instead of formatted text — built for scripting. See the JSON event stream. |
--verbose | Print each tool call's full output, and token usage (prompt/completion/total, and cost if known) after each turn. |
--max-turns <N> | Stop after N steps of the agent loop — guards an unattended run against a model that won't converge. The server clamps it to your plan's ceiling. |
--allowed-tools <NAMES> | Comma-separated tool names this run may use, e.g. read_file,search_files. An MCP server's name covers all of its tools. |
--disallowed-tools <NAMES> | Comma-separated tool names this run may not use, applied after --allowed-tools. |
--prompt-file <PATH> | Read the message from a file instead of the command line — for prompts too long or too quote-heavy to pass as an argument. |
--max-cost <usd> | Stop once this run's model calls have cost this many US dollars, such as 0.50, sub-agents included. Exits with code 6. Tempr's server enforces it too, stopping a run before its next model call. A model whose price isn't known can't be counted, and the CLI says so. See Capping what a run spends. |
--search / --no-search | Let the model search the web for this run, or don't. Without either, an interactive session searches (unless tempr config set-web-search off) and a script (--json, piped input, CI) doesn't. See Web search. |
--sandbox / --sandbox-network / --no-sandbox | Run this run's commands in the sandbox (Linux), with the network cut off or left on, or not at all, overriding tempr config set-sandbox and the default for --yolo. If a sandbox you asked for can't run here, nothing runs: exit code 7. |
--config <PATH> | Use a config directory other than ~/.tempr. Works with every command. |
REPL slash commands
Inside an interactive tempr session:
| Command | Does |
|---|---|
/help | List the slash commands, mentions, approval modes, and flags. |
/model [id] | Switch the model for this session. No id opens a picker over your catalog. |
/reasoning [level] | Set how much the current model reasons, saved per model. No level opens a picker over the levels the model offers; default goes back to the model's own. |
/persona [name] | Switch persona for the rest of the session; no name opens a picker, and /persona none clears it. For a single turn, start the message with @name (Tab completes it). |
/mcp | List configured MCP servers. |
/mcp browse [query] | Browse or search Tempr's curated MCP catalog and add a server. |
/keys | List your provider keys; /keys add [provider] adds one and /keys remove <provider> removes one, without leaving the session. |
/resume | Pick an earlier session from this folder and load its history. |
/history | List saved sessions. |
/commands | List the command templates you can invoke as /name — built-in, yours in ~/.tempr/commands/, and the workspace's in .tempr/commands/. |
/agents | List the built-in personas and your own custom agents (.tempr/agents/ or ~/.tempr/agents/). |
/diff | Show what the last turn changed on disk. |
/undo | Put the last turn's file changes back, skipping any file that has changed since. |
/clear | Clear this session's conversation history. |
/exit | Quit (so do exit, quit, and /quit). |
!command | Run a command in this folder yourself — !git status, !npm test — with its output shown as it runs. The output goes in front of your next message, so the agent sees what you saw. Nothing is asked: it's your own command, as if typed in a shell. Ctrl+C stops it. |
A turn that runs 30 seconds or more without you rings the terminal bell when it finishes or asks for approval, with a desktop notification in terminals that show one (iTerm2, WezTerm, Ghostty, kitty, rxvt, foot, Konsole). Not in CI or with output redirected; tempr config set-notifications off or TEMPR_NO_NOTIFY turns it off.
The agent tool set
In agent mode, the model drives the same tool families as the IDE — executed locally against your workspace:
| Tool family | What it does |
|---|---|
| Files | Read, write, and edit files (read first, then targeted edits). |
run_command | Run shell commands, gated by the command-safety allow-list: read-only commands and each ecosystem's build, test, lint and type-check commands (dotnet test, npm test, npm run build, pytest, go test, cargo test, mvn test, ./gradlew build and the like). A command runs in the workspace root or a folder inside it, stops after 2 minutes unless the model asks for up to 10, and long output keeps its start and end. Each turn tells the model which projects the workspace holds and how each builds and tests. In the sandbox, any command may run instead. |
| Semantic search | Embedding-based search over the workspace — finds conceptually related code. |
| Symbols | Find where a name is defined before the places it's used, in C#, TypeScript and JavaScript, Python, Go, Rust, Java, Kotlin, C and C++, Swift, Ruby and PHP, and what a function calls. Lexical, not a language server. |
| Tests | Discover and run .NET tests with structured pass/fail results. Other projects run their own test command through run_command. |
| Diagnostics | Read compiler and analyzer diagnostics from dotnet build, or tsc for a TypeScript project at the root. |
| Workspace graph | A .NET workspace's projects and their references, and call-graph context. The .NET-only tools are offered only where there's a .NET project. |
| Sub-agent delegation | Hand a focused sub-task to a specialist persona mid-turn. |
| MCP bridge | Expose tools from your configured MCP servers. |
| Web pages and packages | web_fetch reads a page as Markdown and lookup_package finds a package's latest version and links on npm, PyPI, crates.io, the Go module proxy, NuGet or Maven Central. Both run on Tempr's servers, not your machine. |
| Web search | On an Anthropic, OpenAI or xAI model, the model searches the web with its provider's own search. See Web search. |
Which pages the agent opens
Without asking, the agent opens a link that appeared in your messages, in a tool's result, or on a page it has already read in this session, and any page of a well-known documentation site such as docs.python.org, developer.mozilla.org or learn.microsoft.com. For any other address it asks first:
- Yes opens that one page.
- Yes, and trust <site> for this session also opens that site's other pages without asking until you exit.
- No, or No, and tell the agent why, opens nothing.
To stop being asked about a site for good, run tempr config allow-site <site>. With no terminal to ask on (piped input, --json, or CI set), an address that would have asked is refused and the agent is told why. Every approval mode asks, since reading a page the agent chose can send what's in the address to that site. A URL that carries a key, token or password is only opened if you typed that credential yourself. Tempr's servers can't reach localhost or your own network; for those the agent uses curl through run_command, which you approve like any command. --disallowed-tools web_fetch turns page reading off for a run.
Web search
On a Claude model through your Anthropic key, an OpenAI model through your OpenAI key, or a Grok model through your xAI key, the agent can search the web with the provider's own search tool. Each search shows as Searching the web for "…", and the pages it finds are ones the agent may then open with web_fetch without asking. Other providers' models don't search; web_fetch and lookup_package still work for them.
The provider runs each search and bills it to your key: $10 per 1,000 searches on Anthropic and OpenAI, and $5 per 1,000 on xAI, where opening a page counts as a search too, plus the tokens the results add. The cost tempr usage and the Portal's usage page show includes the searches.
An interactive session searches unless you turn it off with tempr config set-web-search off. A script (--json, piped input, or CI set) doesn't, so a CI job's cost and output don't depend on what the web says that day; pass --search to let it. --no-search or --disallowed-tools web_search turns it off for one run.
Sandbox (Linux)
--sandbox runs the agent's commands inside a sandbox: they can change files only in the current folder, the temp folders and the package stores and caches builds write to (npm's, pip's, NuGet's, Go's, Cargo's, Gradle's and Maven's), and they can't open network connections. Reading is open. tempr config set-sandbox on turns it on for every run, and --no-sandbox off for one.
On by default for --yolo and CI. A run on autopilot with nobody deciding command by command (--yolo, --approval-mode autopilot, or autopilot in CI) runs its commands in the sandbox with the network on: the file limits hold, and installs, restores and tests that use localhost still work. Where the sandbox can't run, those runs go ahead unsandboxed, as before, and an interactive session says so. --sandbox cuts off the network as well; --no-sandbox, or tempr config set-sandbox off, keeps --yolo out of the sandbox. Other runs aren't sandboxed unless you ask, since the sandbox would let their commands run without asking.
Inside it, any command runs without asking, in every approval mode, so an unattended run can build, test and try things that have no allow-list entry. Commands that delete, publish or force-push still ask. When a command fails because the sandbox blocked it, a download say, the agent can ask to run it outside the sandbox, which always asks you first; a run with nobody to ask refuses it.
- What it covers:
run_command, the .NET test tools andget_diagnostics. Not!command, which you type yourself, and not MCP servers. - Git hooks: a command may not keep changes to
.git/hooks,.git/configor.agentcommands.json, which run or allow things later, outside the sandbox. Tempr puts back anything a command changed there, and tells the agent. - dotnet: in the sandbox it keeps its own per-user files in
~/.cache/tempr/sandbox-dotnetrather than~/.dotnet, which holds global tools and stays read-only. It restores into your own~/.nuget/packagesand reads your NuGet package sources. - The network:
--sandbox-network(orset-sandbox network) keeps the file limits and leaves the network on. Cutting it off blocks TCP connections, so name lookups still work. - Where it runs: Linux 5.13 or later, and 6.7 or later to cut off the network, through the kernel's Landlock. It needs no install and no privileges, and works in a container and on Ubuntu 24.04. It isn't available on macOS or Windows yet; inside WSL2 it works. If you ask for it where it can't run, nothing runs:
temprexits with code 7 rather than run your commands unsandboxed. The default for--yoloand CI isn't asking, so it doesn't stop a run.
The agent loop runs server-side like the IDE, so a dropped connection doesn't lose an in-flight turn — and every session is saved automatically, ready to resume with tempr --id.
Next steps
- Scripts, pipes & CI — headless patterns, the JSON event stream, and automation examples.
- Agent modes & personas — the persona lineup and how delegation works.
- MCP servers — connect your own tools and data sources.