graphban-cli
gban — the client for a human at a terminal.
Five surfaces existed before this and none of them was for a person at a shell prompt:
graphban talks to the database from inside the container, gbfleet supervises processes,
gbagent is a spawned child, the web app is a browser, and /api/mcp is for agents. Issuing
a seat, seeing why an agent is stuck, or re-tasking one meant opening a browser.
Specified by PRD-40.
Install
Not on PyPI yet, so it installs from the repository. uv tool install puts it on your PATH
in its own environment, which is what you want for a CLI:
uv tool install "git+https://github.com/asc-me/graphban.git#subdirectory=cli"
Add gbfleet too if you run waves — it is a separate package, and gban fleet hands off to it:
uv tool install "git+https://github.com/asc-me/graphban.git#subdirectory=fleet"
uv tool update-shell once, if uv says the bin directory is not on your PATH. Upgrade either
with uv tool upgrade graphban-cli (or --all); reinstalling from the same URL also works,
since the spec is a branch rather than a pin.
With pip instead, into an environment you already have:
pip install "graphban-cli @ git+https://github.com/asc-me/graphban.git#subdirectory=cli"
gban pulls nothing: client.py is urllib.request throughout, and the install lands
exactly one distribution. gbfleet brings httpx and its four transitive dependencies, which
is why they are separate packages and not one.
gban login --server https://cloud.agentldgr.dev
gban doctor # both halves: the ledger, and the local fleet
gban agents # the roster, and why an agent is stuck
gban agents role SA-A4 planner # what used to need a browser
gban seats issue worker worker planner # one entry per agent
gban keys # which key is that agent on
gban fleet up --seats-file seats.txt --adapter claude # hands off to gbfleet
seats issue takes one role per agent, repeats included, because that is the server's
own shape: two agents on one seat share a session and cannot review each other. Each code is
printed once and written nowhere — a CLI that helpfully saved them would invent a second
credential at rest that no route and no test knows about.
agents prints what an agent was last refused, and why. That line is the reason the verb
exists: a roster saying "idle worker" for an agent being told no on every call it makes is
what made the Super-Arc diagnosis take a database query.
agents role re-tasks a live agent within its credential's ceiling and never past it. A
role the key does not permit is the server's refusal, printed in the server's own words;
widening a ceiling means minting a different credential, and keeping those two acts apart is
the point of having a ceiling. It lands on the agent's next poll.
gban login wants a real terminal
It refuses without one, rather than prompting. getpass falls back to a plain echoing
read when it cannot turn echo off — it warns, but the warning arrives after the person has
decided to type — so a login through a pipe, a heredoc or an editor's command runner would
put the password in the scrollback. There is no non-interactive login yet (PRD-40 open
question 2: an API key cannot reach the JWT routes, so CI would need a service session).
Why not gb
Because gb is already git branch on a large share of developer machines, and an alias
beats a binary on PATH. The deployed walk hit it on the very first command and got git's
usage text; nothing inside the process can detect that, because by the time gb would have
run, the alias did not.
It is not one alias but a whole namespace. oh-my-zsh's git plugin — which is where most of
these come from — defines sixteen gb* aliases and ten grb*, so gb, gba, grb and
gbl are all spoken for. gban is outside it, still short, and still says which product it
belongs to.
Licence — Apache-2.0, deliberately not the repository's FSL-1.1
The repository is FSL-1.1-Apache-2.0. This directory is
Apache-2.0, for the reasons PRD-22 §8 gives for fleet/ — every one of which
applies here identically. gban is inert without a Graphban server and holds no authority of
its own, so FSL's Competing Use clause protects the server and protects nothing here. It is a
laptop-installed developer CLI, which is exactly the kind of dependency that has to clear a
corporate licence policy scanner.
Why it is in this repository
Not a second repository, for the reason fleet/README.md gives for
the supervisor, with more force: the client↔server contract has no schema anywhere, and a
cross-repo break would present as absence reading clean — gban still runs, nothing errors, the
verb quietly stops meaning what it said. The evidence is recent and specific: ROLES lost
reviewer in one PR while another added a test naming it, and CI caught the pair inside
seventeen minutes because both lived in one repository. Split across two, that lands as a bug
report from somebody whose gban agents role ... reviewer started refusing.
Not inside backend/, because graphban-api pulls fastapi, sqlalchemy, pgvector, psycopg,
alembic, redis and cryptography, and this installs on a laptop. tests/test_packaging.py
derives its forbidden set from the backend's own dependency list rather than a denylist
somebody maintains.
What it is not
It is not a second web app: no board, no PRD editor, no search. Every verb is either something a human currently opens a browser for, or a diagnosis nothing else gives.
It is not graphban, which talks to the local database from inside the container and
stays exactly as it is. Mixing "against the DB in the container" and "over HTTP from a laptop"
into one command is an ambiguity that ends with somebody purging the wrong instance.
It holds no state the server does not and computes nothing the server computes. Every verb is one endpoint, called once (PRD-40 D11); an ordering between two calls would be a rule, and a rule in the client is a second definition of something the server already enforces.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file graphban_cli-0.1.0.tar.gz.
File metadata
- Download URL: graphban_cli-0.1.0.tar.gz
- Upload date:
- Size: 35.2 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
19cd1598b1dffeebba1aba33fb8978a1636f5fbd35692b9692eb274fb75f9de1
|
|
| MD5 |
80882176fc148480772574355ceb9d0c
|
|
| BLAKE2b-256 |
1b0291627442ed2cc1b2e080457b9c04ae07f019656203745a60984d271d8f0e
|
Provenance
The following attestation bundles were made for graphban_cli-0.1.0.tar.gz:
Publisher:
release-cli.yml on asc-me/graphban
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
graphban_cli-0.1.0.tar.gz -
Subject digest:
19cd1598b1dffeebba1aba33fb8978a1636f5fbd35692b9692eb274fb75f9de1 - Sigstore transparency entry: 2754078478
- Sigstore integration time:
-
Permalink:
asc-me/graphban@600efe2fb538f222607f584f28314fcc63853273 -
Branch / Tag:
refs/tags/cli-v0.1.0 - Owner: https://github.com/asc-me
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release-cli.yml@600efe2fb538f222607f584f28314fcc63853273 -
Trigger Event:
push
-
Statement type:
File details
Details for the file graphban_cli-0.1.0-py3-none-any.whl.
File metadata
- Download URL: graphban_cli-0.1.0-py3-none-any.whl
- Upload date:
- Size: 24.0 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
8766f0baedbfcb21c317dd3b93c7a6c59130d21b8b42e0917058afc20ec8fab8
|
|
| MD5 |
74ed718f66cdb278f2b5bf4dcb219db3
|
|
| BLAKE2b-256 |
0330f2fd7dcc5ef1d46eb0da4a1e9194fc45a1370cf090877d18e8b3ffd21994
|
Provenance
The following attestation bundles were made for graphban_cli-0.1.0-py3-none-any.whl:
Publisher:
release-cli.yml on asc-me/graphban
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
graphban_cli-0.1.0-py3-none-any.whl -
Subject digest:
8766f0baedbfcb21c317dd3b93c7a6c59130d21b8b42e0917058afc20ec8fab8 - Sigstore transparency entry: 2754078479
- Sigstore integration time:
-
Permalink:
asc-me/graphban@600efe2fb538f222607f584f28314fcc63853273 -
Branch / Tag:
refs/tags/cli-v0.1.0 - Owner: https://github.com/asc-me
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release-cli.yml@600efe2fb538f222607f584f28314fcc63853273 -
Trigger Event:
push
-
Statement type: