Skip to main content

ACT CLI & Build Tools

Host and build ACT (Agent Component Tools) WebAssembly components.

This repo contains two tools:

  • act — run, call, inspect, and serve ACT components from local files, HTTP URLs, or OCI registries. Components built for wasm32-wasip2 (with async) and wasm32-wasip3 run the same way, under the same capability grants
  • act-build — post-process compiled WASM components: embed metadata, skills, and custom sections

Install

# act (CLI host)
npm i -g @actcore/act
pip install act-cli
cargo install act-cli

# act-build (build tool)
npm i -g @actcore/act-build
pip install act-build
cargo install act-build

Pre-built binaries available on GitHub Releases and Docker (ghcr.io/actcore/act).

act — Component Host

# Discover tools in a component
act info --tools actpkg.dev/library/sqlite

# Call a tool. sqlite is session-based: --session-args opens a session for
# this one call. --allow lets it touch /data and nothing else.
act call actpkg.dev/library/sqlite query \
  --args '{"sql":"SELECT sqlite_version()"}' \
  --session-args '{"database_path":"/data/app.db"}' \
  --allow 'fs=/data/**'

# Serve over MCP stdio
act run --mcp actpkg.dev/library/sqlite --allow 'fs=/data/**'

# Serve over MCP Streamable HTTP, at http://[::1]:3000/mcp
act run --mcp --http -l '[::1]:3000' actpkg.dev/library/sqlite --allow 'fs=/data/**'

Components can be referenced as:

  • OCI refs: actpkg.dev/library/sqlite (a tag or @sha256: digest is optional)
  • HTTP URLs: https://example.com/component.wasm
  • Local paths: ./component.wasm

Remote components are cached in ~/.cache/act/components/.

Commands

Command Description
run Serve a component over MCP — stdio (--mcp) or Streamable HTTP (--mcp --http -l)
call Call a tool directly, print result to stdout
info Show component metadata, tools, and schemas (--tools, --format text|json|toon)
skill Extract the Agent Skills a component embeds
pull Download a component from OCI or HTTP to a local file
session Show a session-based component's open-args-schema
store Manage the local component store (list, update, gc)
inspect Read a component's raw manifest or tool list without instantiating it
secret Store credentials a component declares (there is no get)
login Provision a declared credential by prompting

Granting capabilities

The default mode is ask: an interactive run prompts, a headless one denies. Grants come from flags, or per profile in ~/.config/act/config.toml.

Flag Effect
--allow fs the whole declared ceiling of wasi:filesystem
--allow 'fs=/data/**' only /data/**, read-write (fs=/data/**:ro for read-only)
--allow 'http=https://api.example.com' one host (and scheme)
--allow 'sockets=db.local:5432/tcp' one host, port and protocol
--allow 'db:drop=test_*' a component-defined class, narrowed by key
--deny 'fs=/data/secret/**' carve a rule out of whatever else was granted
--grant '<json>' the full form, for anything the shorthand doesn't cover

Aliases: fs = wasi:filesystem, http = wasi:http, sockets = wasi:sockets, creds = act:credentials; output always shows the full id. IPv6 goes in brackets (http=[::1]:8080). A rule never exceeds what the component declared. act run --help lists every class and its shorthand.

Audit trail

run and call write a structured audit trail to stderr: what component is running and under what capability modes, every capability decision as it resolves, and a per-call summary. It is on by default and independent of RUST_LOG — only --no-audit (or [audit] enabled = false in the config file) turns it off.

audit: act-cli/tests/fixtures/fs-canary.wasm sha256:f17cda │ act:credentials=deny wasi:filesystem=ask wasi:http=deny wasi:sockets=deny
audit: ⚠ declared ask, no prompt channel — every access will be denied: wasi:filesystem
audit: ? ask-deny  wasi:filesystem  /tmp/probe.txt   no prompt channel  mode:ask
audit: ● read  tool-error 1ms  args:43ebc7  req:0005a4

That's a real, captured transcript of one headless call with no --grant: the first line is the instantiation header (component, digest, resolved mode per capability class); the second warns that a declared ask capability has no prompt channel to answer it, so every access degrades to deny; the third is the immediate denial (denials and asks print the moment they resolve, never batched); the fourth is the per-call rollup — outcome, duration, an args: digest of the tool arguments (or the full values with --audit-args), and a req: id for joining this line back to a client log. Allowed operations coalesce into that rollup line instead of one line each, e.g. filesystem: 12 read under /data/**.

MCP over HTTP (run --mcp --http)

act run --mcp --http -l <addr> serves the same MCP server as stdio over Streamable HTTP, at one endpoint: /mcp. --http requires --mcp. The earlier REST binding (/info, /tools, …) was removed in 0.12.0.

act-build — Component Build Tool

# Embed act:component metadata, act:skill, and WASM custom sections
act-build pack target/wasm32-wasip2/release/my_component.wasm

# Validate without modifying
act-build validate target/wasm32-wasip2/release/my_component.wasm

# Publish as a CNCF Wasm OCI Artifact
act-build push my_component.wasm ghcr.io/you/my-component:0.1.0 \
  --also-tag latest \
  --source https://github.com/actpkg/my-component \
  --skip-if-identical

Metadata is resolved via merge-patch from project manifests:

  1. Base from Cargo.toml, pyproject.toml, or package.json (name, version, description)
  2. Inline patch from the same manifest ([package.metadata.act], [tool.act], or "act" in package.json)
  3. act.toml — highest priority, applied last

act-build push produces artifacts conformant with the CNCF TAG-Runtime Wasm OCI Artifact spec: manifest config has media type application/vnd.wasm.config.v0+json (with architecture, os, layerDigests, and component.{exports,imports} derived from the component's exports and imports), and the layer is application/wasm.

Authentication is resolved in order: OCI_USERNAME/OCI_PASSWORD env, then GITHUB_TOKEN for ghcr.io, then ~/.docker/config.json (or $DOCKER_CONFIG/config.json), then anonymous.

Platform Support

Architecture Linux (GNU) Linux (musl) macOS Windows Docker
x86_64 ✓ ✓ ✓ ✓ ✓
aarch64 ✓ ✓ ✓ ✓ ✓
riscv64 ✓ ✓ — — ✓

RISC-V (riscv64) is a first-class target. Regressions on RISC-V are release-blocking.

Runtime requirement: glibc 2.34

A glibc build of act or act-build requires glibc 2.34 or newer — Debian 12, Ubuntu 22.04, RHEL 9 and later. This is a supported-platform commitment, not an incidental build setting: it is asserted in CI, and lowering it is a breaking change.

Which channels it applies to:

Channel Affected
npm (@actcore/act, @actcore/act-build) No — Linux packages ship musl binaries
PyPI manylinux wheels Yes — 2.34; the riscv64 wheel needs 2.39
GitHub Releases *-linux-*-gnu Yes — 2.34
GitHub Releases *-linux-*-musl, Docker No

The floor is one symbol. DNS SVCB/HTTPS lookups call res_query(3), which glibc did not export under that name before 2.34 — earlier releases had only __res_query, and a modern glibc keeps that as a compat symbol new code cannot link against, so there is no spelling that satisfies both. Nothing else in the binary requires past glibc 2.33.

On an older distribution, use a musl build: musl exports the symbol outright and carries no floor. Building from source does not lift the requirement — it is the same call — so musl is the answer there, not cargo build.

Building

cargo build --release        # both tools
cargo build -p act-cli       # act only
cargo build -p act-build     # act-build only

Set RUST_LOG=act=debug for verbose output.

License

MIT OR Apache-2.0

Release files for act-cli 0.14.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for act-cli 0.14.3
File Size Uploaded
act_cli-0.14.3.tar.gz 403.5 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for act-cli 0.14.3
File
act_cli-0.14.3-py3-none-win_arm64.whl Python 3 none Windows ARM64 Details
act_cli-0.14.3-py3-none-win_amd64.whl Python 3 none Windows x86-64 Details
act_cli-0.14.3-py3-none-musllinux_1_2_x86_64.whl Python 3 none Linux musl 1.2+ x86-64 Details
act_cli-0.14.3-py3-none-musllinux_1_2_riscv64.whl Python 3 none Linux musl 1.2+ RISC-V 64 Details
act_cli-0.14.3-py3-none-musllinux_1_2_aarch64.whl Python 3 none Linux musl 1.2+ ARM64 Details
act_cli-0.14.3-py3-none-manylinux_2_39_riscv64.whl Python 3 none Linux glibc 2.39+ RISC-V 64 Details
act_cli-0.14.3-py3-none-manylinux_2_34_x86_64.whl Python 3 none Linux glibc 2.34+ x86-64 Details
act_cli-0.14.3-py3-none-manylinux_2_34_aarch64.whl Python 3 none Linux glibc 2.34+ ARM64 Details
act_cli-0.14.3-py3-none-macosx_11_0_arm64.whl Python 3 none macOS 11.0+ ARM64 Details
act_cli-0.14.3-py3-none-macosx_10_12_x86_64.whl Python 3 none macOS 10.12+ x86-64 Details

Total release size: 158.9 MB

Release files / act_cli-0.14.3.tar.gz

Download URL act_cli-0.14.3.tar.gz
Size 403.5 kB
Tags Source
SHA-256 checksum
How to use checksums
40769d0393a8cc5183136d7f7cad7ad36e85133b57b23343c1e198b92f0eb422
BLAKE2b-256 checksum
How to use checksums
72afccd78c656f45327a536d4229fd5bdae258f69618758315b04f9950ae0fb1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 25, 2026.

Transparency log

Release files / act_cli-0.14.3-py3-none-win_arm64.whl

Download URL act_cli-0.14.3-py3-none-win_arm64.whl
Size 15.1 MB
Tags Python 3 Windows ARM64
SHA-256 checksum
How to use checksums
e64c79ef1708a286767fb036c69c12111322b0da8ff6154b5ef41f65f43b11d7
BLAKE2b-256 checksum
How to use checksums
db774c0c2f76d2d10dadfbd45be3d9bd81d73b13f816d89ca79ae661b3384907
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 25, 2026.

Transparency log

Release files / act_cli-0.14.3-py3-none-win_amd64.whl

Download URL act_cli-0.14.3-py3-none-win_amd64.whl
Size 17.0 MB
Tags Python 3 Windows x86-64
SHA-256 checksum
How to use checksums
55970ec069a53a4d622b7c5bbc5447fce761dfac6acf283db170d548ce733035
BLAKE2b-256 checksum
How to use checksums
9d22a85ba805e9bedc5640c4c13dec0d15ce491a7bbf5cd5567e8f7a7ad3e6fa
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 25, 2026.

Transparency log

Release files / act_cli-0.14.3-py3-none-musllinux_1_2_x86_64.whl

Download URL act_cli-0.14.3-py3-none-musllinux_1_2_x86_64.whl
Size 16.5 MB
Tags Linux musl 1.2+ x86-64 Python 3
SHA-256 checksum
How to use checksums
df958a308952f32d867f662427397d412c44ed3ee9b7f173f09659834d5dc0c2
BLAKE2b-256 checksum
How to use checksums
2a42858a63b932697be2d7a9cbe0b10d72cb10dd6b07f19f362894d90b0d55c7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 25, 2026.

Transparency log

Release files / act_cli-0.14.3-py3-none-musllinux_1_2_riscv64.whl

Download URL act_cli-0.14.3-py3-none-musllinux_1_2_riscv64.whl
Size 16.1 MB
Tags Linux musl 1.2+ RISC-V 64 Python 3
SHA-256 checksum
How to use checksums
e1122036ce15f9f1cdf7f4f4b463288fadbaa7db3f18ae41105bd7823610b90d
BLAKE2b-256 checksum
How to use checksums
ae9dfd32f46ab7c824175635b6c80510513db45f354dfce4863e2121f3b610e3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 25, 2026.

Transparency log

Release files / act_cli-0.14.3-py3-none-musllinux_1_2_aarch64.whl

Download URL act_cli-0.14.3-py3-none-musllinux_1_2_aarch64.whl
Size 15.0 MB
Tags Linux musl 1.2+ ARM64 Python 3
SHA-256 checksum
How to use checksums
f09481cb8322bc074fc034b9572d000655573765867ed25664bb59122a72ef43
BLAKE2b-256 checksum
How to use checksums
d7888191b4a32905d91466bef28e170f68b66aadd60c8dade4996e10bb2e37e0
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 25, 2026.

Transparency log

Release files / act_cli-0.14.3-py3-none-manylinux_2_39_riscv64.whl

Download URL act_cli-0.14.3-py3-none-manylinux_2_39_riscv64.whl
Size 16.1 MB
Tags Linux glibc 2.39+ RISC-V 64 Python 3
SHA-256 checksum
How to use checksums
dfc61ffb5fc26d2359dde2b090fe2b578f1b1df146d9c742f1d2934205e46a96
BLAKE2b-256 checksum
How to use checksums
ca04b69ec684b5a774ef27921d63ada275268264b362a95cce181159fb6e1f99
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 25, 2026.

Transparency log

Release files / act_cli-0.14.3-py3-none-manylinux_2_34_x86_64.whl

Download URL act_cli-0.14.3-py3-none-manylinux_2_34_x86_64.whl
Size 16.7 MB
Tags Linux glibc 2.34+ x86-64 Python 3
SHA-256 checksum
How to use checksums
94f0a078279520a07ad96bd718fa27d4d8094ded17a3b0d292831848bc8ed35a
BLAKE2b-256 checksum
How to use checksums
fb1df4ab369a6992942c747de6b5169216f6ad1e92aeb7b45f8665bad8d26c68
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 25, 2026.

Transparency log

Release files / act_cli-0.14.3-py3-none-manylinux_2_34_aarch64.whl

Download URL act_cli-0.14.3-py3-none-manylinux_2_34_aarch64.whl
Size 15.1 MB
Tags Linux glibc 2.34+ ARM64 Python 3
SHA-256 checksum
How to use checksums
217baca9eeea025356a94c0f328027c851b472b2699605b623c800cfc3b50396
BLAKE2b-256 checksum
How to use checksums
73ca81205db3a9f4ae23f64dd0075f0f53896369ca5282eba95de221d0396de1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 25, 2026.

Transparency log

Release files / act_cli-0.14.3-py3-none-macosx_11_0_arm64.whl

Download URL act_cli-0.14.3-py3-none-macosx_11_0_arm64.whl
Size 14.8 MB
Tags Python 3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
40ce7dfa7e0afade33d133108b951a3f70055038205068d40f223ae606796761
BLAKE2b-256 checksum
How to use checksums
e6a3c3f68df1a139b0a50d11511081451720de5a1a2016fccb08f3e8a2f80686
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 25, 2026.

Transparency log

Release files / act_cli-0.14.3-py3-none-macosx_10_12_x86_64.whl

Download URL act_cli-0.14.3-py3-none-macosx_10_12_x86_64.whl
Size 16.1 MB
Tags Python 3 macOS 10.12+ x86-64
SHA-256 checksum
How to use checksums
368852d9760e4da7bc3fa86fdba0f22e24d9d577c0bf2622683cb92bb79a8651
BLAKE2b-256 checksum
How to use checksums
9e69fbe943ad3c8e76102bb985689fe70a37238955f9efa00d3c3fc8e7bd99dd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 25, 2026.

Transparency log
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page