CLI

orchestrator-zero

The server binary and the operator CLI: run servers, manage nodes, plugins, secrets and jobs.

Orchestrator Zero: mission control for AI agents

Global flags

These work with every command.

FlagTypeDefaultDescription
--contextstring$OZ0_CONTEXT or <config dir>/orchestrator-zero/context.jsonCLI context file written by server init
--log-levelstringinfolog level: debug, info, warn or error

apikey

Manage a tenant's API keys, which apps call the runtime API with (ADR 0050)

orchestrator-zero apikey [command]

Subcommands: create, list, revoke

apikey create

Make a key that an app sends as Authorization: Bearer <key> to the runtime API, on the edge's HTTPS port. It has a role in one tenant: reader follows jobs, operator also starts and cancels them and decides approvals. Operators see what jobs read and wrote unless --no-content. The key works nowhere else: not on the admin API, and not on Temporal's ports. It is shown only now; keep it as a secret.

orchestrator-zero apikey create <name> [flags]
FlagTypeDefaultDescription
--expiresstring90dhow long it lasts, such as 30d or 720h, or never
--jsonboolprint JSON instead of a table
--no-contentboolan operator key that may not see what jobs read and wrote
--rolestringoperatorreader or operator
--tenantstringdefaulttenant

apikey list

List a tenant's API keys, never their secrets

orchestrator-zero apikey list [flags]
FlagTypeDefaultDescription
--jsonboolprint JSON instead of a table
--tenantstringdefaulttenant

apikey revoke

Stop an API key from working, within seconds on every edge

orchestrator-zero apikey revoke <id> [flags]

approval

Decide on steps that wait for a person, such as tool calls in requires_approval

orchestrator-zero approval [command]

Subcommands: approve, deny, list

approval approve

Let a waiting step go ahead

orchestrator-zero approval approve JOB APPROVAL [flags]
FlagTypeDefaultDescription
--commentstringwhy; the agent sees it, and so does the job's history
--tenantstringdefaulttenant

approval deny

Stop a waiting step; the agent is told why

orchestrator-zero approval deny JOB APPROVAL [flags]
FlagTypeDefaultDescription
--commentstringwhy; the agent sees it, and so does the job's history
--tenantstringdefaulttenant

approval list

List what waits for a decision, oldest first

orchestrator-zero approval list [flags]
FlagTypeDefaultDescription
--jobstringonly this job's
--jsonboolprint JSON instead of a table
--tenantstringdefaulttenant

audit

Read the audit log, newest first: who changed what, and what the platform did by itself

orchestrator-zero audit [flags]
FlagTypeDefaultDescription
--actionstringonly this action, or every action under a prefix that ends in a dot, such as node.
--jsonboolprint JSON instead of a table
--limitint3250at most this many entries
--targetstringonly entries about this target, such as a node ID or tenant/plugin

catalog

List the agents, tools and skills a tenant's plugins offer, and the nodes ready to run them

orchestrator-zero catalog [flags]
FlagTypeDefaultDescription
--jsonboolprint JSON instead of a table
--tenantstringdefaulttenant

cluster

Show the cluster

orchestrator-zero cluster [command]

Subcommands: info

cluster info

Show cluster name, CA hash and servers

orchestrator-zero cluster info [flags]
FlagTypeDefaultDescription
--jsonboolprint JSON instead of a table

dev

Start a dev server and a node, install the plugin from its working tree (no commit needed) and reinstall it whenever a file changes. The node's tools (uv, Python, Node.js) are cached between runs; the server starts empty every time.

orchestrator-zero dev [plugin-dir] [flags]
FlagTypeDefaultDescription
--cache-dirstringwhere the dev node keeps uv, Python and Node.js between runs
--node-binarystringnext to this binary, else on PATHorchestrator-zero-node to run
--runtime-bundlestring$OZ0_RUNTIME_BUNDLE, else the newest in ./dist/runtimeruntime bundle directory

job

Follow, cancel and list jobs; start them with run

orchestrator-zero job [command]

Subcommands: cancel, findings, get, list, run, step, trace, watch

job cancel

Cancel a running job and the jobs it delegated to

orchestrator-zero job cancel JOB [flags]
FlagTypeDefaultDescription
--reasonstringwhy, for the job's history
--tenantstringdefaulttenant

job findings

List the jobs whose traces have warnings, newest first, from the summaries the edge keeps for management (ADR 0039). A job's summary is written when it ends and refreshed while it runs, and it outlives Temporal's retention. --code picks one rule, such as possible_loop or retries; --code all lists every job.

orchestrator-zero job findings [flags]
FlagTypeDefaultDescription
--agentstringonly this agent's or flow's jobs
--codestringjobs with any warningonly this rule, such as possible_loop, retries or idle; all lists every job
--jsonboolprint JSON instead of a table
--limitint3250at most this many jobs
--sinceduration24h0m0sjobs that started this long ago at most
--tenantstringdefaulttenant

job get

Show a job: status, answer and cost per branch

orchestrator-zero job get JOB [flags]
FlagTypeDefaultDescription
--jsonboolprint JSON instead of a table
--tenantstringdefaulttenant

job list

List recent jobs

orchestrator-zero job list [flags]
FlagTypeDefaultDescription
--jsonboolprint JSON instead of a table
--limitint20at most this many jobs
--tenantstringdefaulttenant

job run

Run a workflow through the edge's Temporal proxy and print its result as JSON. This talks Temporal directly and is meant for debugging nodes and tools; agents are run with orchestrator-zero run.

orchestrator-zero job run [flags]
FlagTypeDefaultDescription
--addressstringfrom the context, else 127.0.0.1:7233edge Temporal address
--idstringrandomworkflow ID
--inputstringArrayworkflow argument as JSON; repeat for several arguments
--namespacestringfrom the context, else defaultnamespace
--task-queuestringtask queue to run on (required)
--timeoutduration1m0show long to wait for the result
--workflowstringworkflow type name (required)

job step

Show one step's input and output, as job trace lists the steps: a model call's messages and response, a tool call's arguments and result, what a person was asked and what they answered. They can hold customer data, so this needs the content permission, and each look is in the audit log.

orchestrator-zero job step JOB STEP [flags]
FlagTypeDefaultDescription
--jsonboolprint JSON instead of a table
--tenantstringdefaulttenant

job trace

Show a job's trace, built by the edge from the job's Temporal history: each step with when it began, how long it took, where it ran and what it cost, and findings about what looks wrong. It shows the shape of the job, not what its steps read and wrote: job step shows one step's input and output.

orchestrator-zero job trace JOB [flags]
FlagTypeDefaultDescription
--jsonboolprint JSON instead of a table
--tenantstringdefaulttenant

job watch

Follow a job live until it ends, then print its answer and cost

orchestrator-zero job watch JOB [flags]
FlagTypeDefaultDescription
--jsonboolprint JSON instead of a table
--tenantstringdefaulttenant

node

Manage nodes: list, accept, reject, block, unblock, purge, delete, upgrade

orchestrator-zero node [command]

Subcommands: accept, block, delete, list, purge, reject, runtimes, show, unblock, upgrade

node accept

Accept pending nodes, like salt-key -a

orchestrator-zero node accept <node-id>... [flags]
FlagTypeDefaultDescription
--labelstringArraylabel for the node, key=value; repeatable
--tenantstringdefaulttenant the node joins

node block

Block nodes: the edge refuses their next call on every port

orchestrator-zero node block <node-id>... [flags]
FlagTypeDefaultDescription
--reasonstringwhy, for the audit log

node delete

Forget nodes; their keys may join again as new nodes

orchestrator-zero node delete <node-id>... [flags]

node list

List nodes

orchestrator-zero node list [flags]
FlagTypeDefaultDescription
--jsonboolprint JSON instead of a table
--pendingboolonly nodes waiting for approval (same as --state pending)
--statestringonly nodes in this state: pending, accepted, rejected, blocked or purging
--tenantstringonly this tenant's nodes

node purge

Purge nodes (plan §12). Each loses access to work at once. On its next control stream, which a blocked or offline node gets too when it comes back, it receives a command signed with the cluster CA's key, checks the signature, stops its runtimes and plugins, deletes its data directory (keys, plugins, runtimes and tools) and its binary, and is forgotten. The machine must be set up again to rejoin.

orchestrator-zero node purge <node-id>... --yes [flags]
FlagTypeDefaultDescription
--yesboolconfirm that the nodes are to delete themselves

node reject

Reject pending nodes

orchestrator-zero node reject <node-id>... [flags]

node runtimes

List the runtime versions the edge serves, newest first, and how many of a tenant's nodes run each

orchestrator-zero node runtimes [flags]
FlagTypeDefaultDescription
--jsonboolprint JSON instead of a table
--tenantstringdefaultcount this tenant's nodes

node show

Show one node

orchestrator-zero node show <node-id> [flags]
FlagTypeDefaultDescription
--jsonboolprint JSON instead of a table

node unblock

Let blocked nodes back in

orchestrator-zero node unblock <node-id>... [flags]

node upgrade

Tell nodes which runtime version to run (ADR 0028). A node starts the new version next to the one it runs, new jobs move to it once most of the tenant's nodes run it, and the old version stops when no job is pinned to it any more. --runtime "" lets the nodes keep what they run.

--binary tells nodes to replace their own binary with the one the edge serves (ADR 0047): each node checks the release's signature against the keys it trusts, swaps the binary, and restarts its runtimes.

orchestrator-zero node upgrade [node-id...] [flags]
FlagTypeDefaultDescription
--all-instringevery accepted node of this tenant
--binaryboolreplace the node binary with the one the edge serves, signed (ADR 0047)
--jsonboolprint JSON instead of a table
--runtimestringthe runtime version to run: one the edge serves

operator

Manage this operator's certificate

orchestrator-zero operator [command]

Subcommands: renew

operator renew

Make a new key, have the cluster sign a certificate for it, and put both in place of the ones in the CLI context. The certificate in use must still be valid. Once it has expired, issue new credentials on a server with orchestrator-zero server operator issue.

orchestrator-zero operator renew [flags]

plugin

Build, check and install plugins

orchestrator-zero plugin [command]

Subcommands: approve-tools, install, lint, list, new, remove, test, update

plugin approve-tools

A plugin's tools are snapshotted when the first node lists them (ADR 0049). A node that later lists a function differently, such as a remote MCP server that changed a description or a schema, makes the change pending, and nodes refuse to call the functions that changed. plugin list shows the change; look at it (orchestrator-zero catalog --json has the listings) before you approve it.

orchestrator-zero plugin approve-tools <name> [flags]
FlagTypeDefaultDescription
--tenantstringdefaulttenant

plugin install

Install a plugin from a Git repository. The edge resolves the ref (default: the latest release tag, or the default branch) to a commit and locks it, checks the plugin like plugin lint, and packs it; nodes download it from the edge, never from Git. Installing an installed plugin updates it: a version with evals runs them on a test node first, and a new version of a plugin that runs on two or more nodes rolls out to canaries first, step by step through health and quality gates (rollout show).

orchestrator-zero plugin install <git-url> [flags]
FlagTypeDefaultDescription
--all-at-onceboolgive a new version to every node at once, instead of rolling it out to canaries first
--batchint32half of the restnodes in each later step of a rollout
--canaryint321nodes in a rollout's first step
--jsonboolprint JSON instead of a table
--no-gateboolinstall a version with evals at once, without running them on a test node first
--pathstringthe plugin's folder in the repository, for repositories that hold several
--refstringlatest release tag, else the default branchbranch, tag or full commit SHA
--secretstringtenant secret with a token for a private repository over HTTPS (the token, or user:token)
--selectstringArrayonly nodes with this label, key=value; repeatable
--soakduration1mhow long each step of a rollout is watched before its gates
--start-timeoutduration5mhow long a step's nodes may take to run the new version
--tenantstringdefaulttenant to install into

plugin lint

Check a plugin the way the edge does before it installs one: oz0-plugin.yaml (unknown fields are errors), the agents it lists, its skills and the files they refer to. Exits non-zero on errors.

orchestrator-zero plugin lint [dir] [flags]
FlagTypeDefaultDescription
--jsonboolprint the checked bundle and problems as JSON

plugin list

List installed plugins and how each node is doing with them

orchestrator-zero plugin list [flags]
FlagTypeDefaultDescription
--jsonboolprint JSON instead of a table
--tenantstringonly this tenant's plugins

plugin new

Create a plugin from a template

orchestrator-zero plugin new <dir> [flags]
FlagTypeDefaultDescription
--descriptionstringone line about what the plugin does
--namestringthe directory's nameplugin name
--templatestringpython-tooltemplate: python-agent, python-tool

plugin remove

Uninstall a plugin; nodes stop it and delete it

orchestrator-zero plugin remove <name> [flags]
FlagTypeDefaultDescription
--tenantstringdefaulttenant

plugin test

Start a dev server and a node with the plugin from its working tree, run every case of its evals as a job, one at a time, and grade the answers. A case with a recording (evals/cassettes/<eval>/<case>.jsonl) is answered from it, without calling a model; others call the real API with ANTHROPIC_API_KEY or OPENAI_API_KEY from the environment. --record calls the real API for every case and keeps the answers. Exits non-zero when an eval passes fewer cases than its threshold.

orchestrator-zero plugin test [plugin-dir] [flags]
FlagTypeDefaultDescription
--cache-dirstringwhere the test node keeps uv, Python and Node.js between runs
--cassettesstring<plugin>/evals/cassetteswhere the recordings live
--evalstringrun only this eval
--jsonboolprint JSON instead of a table
--liveboolcall the real API for every case, ignoring recordings
--llm-anthropic-urlstringhttps://api.anthropic.comAnthropic API address for live calls
--llm-openai-urlstringhttps://api.openai.comOpenAI API address for live calls
--node-binarystringnext to this binary, else on PATHorchestrator-zero-node to run
--recordboolcall the real API for every case and keep the answers as the cases' recordings
--runtime-bundlestring$OZ0_RUNTIME_BUNDLE, else the newest in ./dist/runtimeruntime bundle directory

plugin update

Resolve an installed plugin's ref again. A new commit runs its evals on a test node first, when it has any, and rolls out to canaries first when the plugin runs on two or more nodes (ADR 0052).

orchestrator-zero plugin update <name> [flags]
FlagTypeDefaultDescription
--all-at-onceboolgive a new version to every node at once, instead of rolling it out to canaries first
--batchint32half of the restnodes in each later step of a rollout
--canaryint321nodes in a rollout's first step
--jsonboolprint JSON instead of a table
--no-gateboolroll out a version with evals at once, without running them on a test node first
--soakduration1mhow long each step of a rollout is watched before its gates
--start-timeoutduration5mhow long a step's nodes may take to run the new version
--tenantstringdefaulttenant

rollout

Rollouts move a tenant's nodes to a new version in steps, the canary first, through health and quality gates, and roll back by themselves. rollout start rolls out a runtime version; a new version of an installed plugin rolls out when plugin install installs it, once its quality gate passes if it has one. A tenant runs one rollout at a time; plugin rollouts wait for their turn.

orchestrator-zero rollout [command]

Subcommands: abort, list, show, start

rollout abort

Roll a running rollout back, or drop a waiting one

orchestrator-zero rollout abort <rollout-id> [flags]

rollout list

List rollouts, newest first

orchestrator-zero rollout list [flags]
FlagTypeDefaultDescription
--jsonboolprint JSON instead of a table
--tenantstringonly this tenant's rollouts

rollout show

Show a rollout's steps and verdicts

orchestrator-zero rollout show <rollout-id> [flags]
FlagTypeDefaultDescription
--jsonboolprint JSON instead of a table

rollout start

Start a rollout of a runtime version to a tenant's online nodes. Each step assigns the version to its nodes, waits until they run it, sends them their share of new jobs, and watches them for --soak. A step passes when its nodes stay healthy and jobs on the new version fail no more than on the old one; a step that fails rolls the upgraded nodes back by itself.

orchestrator-zero rollout start --runtime <version> [flags]
FlagTypeDefaultDescription
--batchint32half of the restnodes in each later step
--canaryint321nodes in the first step
--jsonboolprint JSON instead of a table
--runtimestringthe runtime version to move to: one the edge serves
--soakduration1mhow long each step is watched before its gates
--start-timeoutduration5mhow long a step's nodes may take to run the new version
--tenantstringdefaulttenant

run

Start a job for an agent and wait for its answer. INPUT is text, or JSON for agents with an input schema; "-" reads it from stdin. What the job and each agent it delegated to cost goes to stderr.

While the job runs, what its agents write and the tools they call stream to stderr (--quiet stops that). Jobs are durable: if you stop waiting, the job keeps running; follow it with job watch or job get.

orchestrator-zero run AGENT [INPUT] [flags]
FlagTypeDefaultDescription
--budgetfloatthe agent's limits.max_cost_usdmost the job and the jobs it delegates to may spend on LLM calls, in US dollars
--detachboolprint the job ID and return without waiting
--idstringjob ID (default: a new random one); a job with this ID that still runs is followed instead
--jsonboolprint JSON instead of a table
--quiet (-q)booldo not stream what the agents do; print only the answer and the cost
--tenantstringdefaulttenant to run in
--timeoutdurationlongest the job may run, on top of the agent's own limits
--waitdurationuntil the job endslongest to wait for the answer

secret

Manage tenant secrets, such as LLM API keys

orchestrator-zero secret [command]

Subcommands: delete, list, set

FlagTypeDefaultDescription
--tenantstringdefaulttenant

secret delete

Delete a secret

orchestrator-zero secret delete <NAME> [flags]

secret list

List secret names (never values)

orchestrator-zero secret list [flags]
FlagTypeDefaultDescription
--jsonboolprint JSON instead of a table

secret set

Store a secret; the value comes from stdin, --from-env or --from-file, never from the command line

orchestrator-zero secret set <NAME> [flags]
FlagTypeDefaultDescription
--from-envstringread the value from this environment variable
--from-filestringread the value from this file

server

Run an orchestrator-zero server

orchestrator-zero server [command]

Subcommands: backup, dist, init, operator, restore, start

server backup

Write one archive of every management table, read in one snapshot while servers keep running, and for a dev server its Temporal database too. The master key is not in it: keep that apart, and give it to server restore. The archive holds job content and sealed secrets, so store it as you store the database. A cluster's Temporal databases are backed up with PostgreSQL's own tools.

orchestrator-zero server backup --out FILE [flags]
FlagTypeDefaultDescription
--data-dirstring~/.local/share/orchestrator-zeroserver data directory
--dbstringPostgreSQL URL of the management database (or set OZ0_DB)
--devboola dev server's data directory (--data-dir) instead of a cluster's database
--out (-o)stringthe archive to write, such as oz0-backup.tar.gz

server dist

Manage what the edge serves to nodes: node binaries and runtimes

orchestrator-zero server dist [command]

Subcommands: pull

server dist pull

Mirror a release into the dist directory the edge serves (ADR 0047). URL is where a release's dist folder is served: manifest.json, manifest.json.sig and the files they name. The release's signature must be by a key this server binary trusts, and every file must match its digest; the manifest goes in place last, so nodes see the new release whole or not at all. Then node upgrade --binary moves nodes to it.

orchestrator-zero server dist pull URL [flags]
FlagTypeDefaultDescription
--dist-dirstringthe dist folder next to this binary's folderthe edge's dist directory

server init

Create a cluster once, before its first server starts. It creates the PostgreSQL databases and schemas, writes the master key, creates the cluster's CAs, the first tenant and the first operator, whose credentials go to --operator-dir.

orchestrator-zero server init [flags]
FlagTypeDefaultDescription
--advertisestring127.0.0.1server address to put in the operator's CLI context
--cluster-namestringoz0cluster name (lowercase letters, digits, dashes)
--data-dirstring~/.local/share/orchestrator-zeroserver data directory
--dbstringPostgreSQL URL of the management database, e.g. postgres://oz0@db:5432/oz0 (or set OZ0_DB)
--history-shardsint1024Temporal history shards; can never change
--master-key-outstring<data-dir>/master.keywhere to write the master key
--operatorstringadminfirst operator
--operator-dirstring<config dir>/orchestrator-zero/<cluster>where to write the operator's credentials
--tenantstringdefaultfirst tenant; its Temporal namespace has the same name

server operator

Issue operator credentials on a server's own machine

orchestrator-zero server operator [command]

Subcommands: issue

server operator issue

Issue a key, a certificate and a CLI context for an operator (default admin), and add the operator if the cluster has none of that name. It runs on a server's machine: it reads the database and the master key, so whoever can run it is trusted like a server. A context already in --operator-dir keeps its addresses. An operator whose certificate still works renews it with orchestrator-zero operator renew.

orchestrator-zero server operator issue [NAME] [flags]
FlagTypeDefaultDescription
--advertisestring127.0.0.1server address for a new CLI context
--data-dirstring~/.local/share/orchestrator-zeroserver data directory
--dbstringPostgreSQL URL of the management database (or set OZ0_DB)
--devboola dev server's data directory (--data-dir): its database and master key, and its operator directory
--master-key-filestring<data-dir>/master.keymaster key file
--namespacestringdefaultnamespace for a new CLI context
--operator-dirstring<config dir>/orchestrator-zero/<name>where to write the credentials

server restore

Restore an archive from server backup into an empty database: --db for a cluster, or a new dev data directory with --dev --data-dir. It checks every file's digest, and that the master key unseals the backup's CAs, before it writes anything. Then it inserts every row in one transaction and migrates to this binary's schema. Nodes keep their certificates and reconnect; operators get new credentials with server operator issue, which a dev server does by itself when it starts.

orchestrator-zero server restore FILE --master-key-file KEY [flags]
FlagTypeDefaultDescription
--data-dirstring~/.local/share/orchestrator-zeroserver data directory
--dbstringPostgreSQL URL of the management database (or set OZ0_DB)
--devboola dev server's data directory (--data-dir) instead of a cluster's database
--master-key-filestringthe master key of the cluster the backup is from

server start

Start the server. With --dev, management, edge and an embedded Temporal run in one process on SQLite, which is meant for development and tests. Without it the server joins the cluster that server init created in PostgreSQL.

orchestrator-zero server start [flags]
FlagTypeDefaultDescription
--advertisestringfirst non-loopback IPv4address other servers and nodes reach this server on
--data-dirstring~/.local/share/orchestrator-zeroserver data directory (with --dev: keep dev state here instead of a temporary directory)
--dbstringPostgreSQL URL of the management database (or set OZ0_DB)
--devboolrun in dev mode: one process, embedded Temporal on SQLite
--dist-dirstringthe dist folder next to this binary's folderwhat make dist built, which the edge serves to new nodes
--edge-api-portint7443edge HTTPS port for join, renew and the control stream
--edge-temporal-portint7233port where nodes reach Temporal through the edge
--ipstring127.0.0.1 with --dev, else 0.0.0.0IP address to bind listeners to
--llm-anthropic-urlstringhttps://api.anthropic.comAnthropic API address for the LLM gateway
--llm-openai-urlstringhttps://api.openai.comOpenAI-compatible API address for the LLM gateway
--management-portint8443management HTTPS port for the admin API
--master-key-filestring<data-dir>/master.keymaster key file written by server init
--metrics-listenstringserve /metrics for Prometheus on this address over plain HTTP, such as 127.0.0.1:9464 (not authenticated: keep it private)
--namestringhost nameserver name in the cluster
--otlp-endpointstringsend traces over OTLP/HTTP to this URL, such as http://collector:4318: the server's own, and the nodes', which the edge relays
--otlp-headerstringToString[]a header for every trace export, such as Authorization=Bearer ...; repeatable
--sanstringsextra host name or IP for the edge certificate, such as a load balancer; repeatable
--temporal-frontend-membership-portint6933Temporal frontend membership port
--temporal-frontend-portint7234Temporal frontend gRPC port
--temporal-history-membership-portint6934Temporal history membership port
--temporal-history-portint7235Temporal history gRPC port
--temporal-log-levelstringWARNlog level for Temporal's own logs
--temporal-matching-membership-portint6935Temporal matching membership port
--temporal-matching-portint7236Temporal matching gRPC port
--temporal-portint7234dev mode: port of the embedded Temporal frontend
--temporal-ui-portint8233dev mode: port of the Temporal web UI (0 disables it)
--temporal-worker-membership-portint6939Temporal worker membership port
--temporal-worker-portint7239Temporal worker gRPC port

tenant

Manage tenants

orchestrator-zero tenant [command]

Subcommands: budget, create, list

tenant budget

Set the most a tenant may spend in a calendar month (UTC) on model calls and on what plugins report. Once it is spent, the gateway refuses the tenant's model calls until the month ends or the budget is raised.

orchestrator-zero tenant budget <tenant> <usd> [flags]
FlagTypeDefaultDescription
--jsonboolprint JSON instead of a table

tenant create

Create a tenant and its Temporal namespace

orchestrator-zero tenant create <id> [flags]
FlagTypeDefaultDescription
--display-namestringhuman-readable name
--jsonboolprint JSON instead of a table

tenant list

List tenants

orchestrator-zero tenant list [flags]
FlagTypeDefaultDescription
--jsonboolprint JSON instead of a table

token

Manage join tokens

orchestrator-zero token [command]

Subcommands: create, list, revoke

token create

Create a join token; nodes that use it are accepted without approval

orchestrator-zero token create [flags]
FlagTypeDefaultDescription
--descriptionstringwhat the token is for
--jsonboolprint JSON instead of a table
--labelstringArraylabel for joining nodes, key=value; repeatable
--max-usesuint32how many nodes may join with it (0: unlimited)
--tenantstringdefaulttenant the nodes join
--ttlduration24h0m0show long the token is valid (0: forever)

token list

List join tokens

orchestrator-zero token list [flags]
FlagTypeDefaultDescription
--jsonboolprint JSON instead of a table
--tenantstringonly this tenant's tokens

token revoke

Revoke a join token; nodes that joined with it stay

orchestrator-zero token revoke <token-id> [flags]

usage

Show LLM tokens and cost by job, agent and model

orchestrator-zero usage [flags]
FlagTypeDefaultDescription
--jobstringonly this job (workflow id)
--jsonboolprint JSON instead of a table
--sinceduration24h0m0show far back
--tenantstringdefaulttenant

user

Manage web UI accounts and their roles in tenants

orchestrator-zero user [command]

Subcommands: add, grant, list, password, remove, revoke

user add

Add a web UI account; without --password-stdin a password is generated and printed once

orchestrator-zero user add NAME [flags]
FlagTypeDefaultDescription
--password-stdinboolread the password from stdin instead of generating one
--rolestringreaderadmin (every tenant, and the cluster), reader (reads every tenant) or member (only its tenants: see user grant)

user grant

Give an account a role in a tenant (ADR 0046), replacing the one it had there. Readers look; operators also start and cancel jobs and decide approvals; admins also change the tenant's nodes, plugins, secrets, tokens and budget; owners also decide who is a member. --content says whether the account may see what the tenant's jobs read and wrote; without it, operators and above may and readers may not.

orchestrator-zero user grant NAME [flags]
FlagTypeDefaultDescription
--contentbooloperators and abovewhether the account may see what the tenant's jobs read and wrote
--rolestringreader, operator, admin or owner
--tenantstringdefaulttenant

user list

List web UI accounts

orchestrator-zero user list [flags]
FlagTypeDefaultDescription
--jsonboolprint JSON instead of a table

user password

Set a new password and sign the user out everywhere; without --password-stdin one is generated

orchestrator-zero user password NAME [flags]
FlagTypeDefaultDescription
--password-stdinboolread the password from stdin instead of generating one

user remove

Remove a web UI account and sign it out

orchestrator-zero user remove NAME [flags]

user revoke

Take an account's role in a tenant away

orchestrator-zero user revoke NAME [flags]
FlagTypeDefaultDescription
--tenantstringdefaulttenant

version

Print the version

orchestrator-zero version [flags]
Copyright © 2026