radmah-cli
The rady command-line interface for the RadMah AI platform.
(radmah is registered as an alias for operators who prefer the
full brand — both resolve to the same binary.)
Requires Python 3.10 or newer. Versions in lockstep with radmah-sdk
(rady --version reports the installed version).
What it does
rady auth login # persistent OS-keyring credential
rady fabricate preview "200 account records" # create a reviewed draft
rady fabricate approve <preview-id> # generate after approval
rady chat # interactive AI assistant REPL
rady jobs list # see your recent platform jobs
rady jobs wait <id> # block on a running job
rady jobs evidence <id> # sealed evidence bundle summary
rady fhir synth --seed 7 -o bundle.json # FHIR R4 bundle (metered job)
rady contract hash --file contract.json # canonical Contract-K hash
rady plan list # ADS campaign templates
rady plan campaign <id> # a campaign's draft plan
rady ics mitre-coverage # ATT&CK for ICS depth by status
rady --help lists every command group. Every listed command calls the
public API through the SDK.
rady fhir synth, rady contract hash, rady plan and rady ics mitre-coverage were restored in 1.4.0 (they need radmah-sdk 1.4.0). They
now use the CLI-wide exit codes, which differ from the in-process versions
removed in 1.3.0: an unknown campaign id exits 4 (was 1), a contract the API
rejects exits 2 (was 3), a failed FHIR job exits 1 (was 4). rady ics mitre-coverage --json prints the API's view grouped by status
(by_status, technique_ids_by_status), a different schema from the
in-process report; the static-catalogue, benchmark-export and label-only
sample figures are not served by the API. These commands have no public
API route yet, so they print a "moved" notice and exit 2: arrow,
benchmark, cctp, hash, lift, sandbox, fhir observation, mitre coverage and scada verify-causal.
Architecture
- One package, same commands across Free, Sovereign, and
Enterprise tiers — the only difference is the
--base-url(orRADMAH_API_URL) the user points it at. Free + Sovereign default tohttps://api.radmah.ai; Enterprise customers point it at their own deployment's API URL (e.g.https://radmah.example.com). Anhttps://deployment on your private network (an RFC 1918 address or a name under.internal) needs an explicit opt-in:rady --allow-private-base-url <command>(the flag goes before the command) orexport RADMAH_ALLOW_PRIVATE_BASE_URL=1, the same setting the SDK reads; exportRADMAH_CA_BUNDLEwhen its certificate comes from your own CA.http://localhost(this machine) needs neither. Anhttp://URL to any other host is refused, because the key would cross the network unencrypted, unless you opt in by name for that command withrady --allow-insecure-http <command>(the flag also accepts that typed URL as a private-network endpoint) or for every command withexport RADMAH_ALLOW_INSECURE_HTTP=1(the same setting the SDK reads; it lifts only the cleartext refusal, so a privatehttp://endpoint also needsRADMAH_ALLOW_PRIVATE_BASE_URL=1); even thenradyprints a one-line warning on stderr. Use the deployment'shttps://URL instead.RADMAH_ALLOW_PRIVATE_BASE_URL=0refuses private endpoints outright. Every command,rady ics techniquesandrady jobs errorincluded, goes through the SDK's transport and these rules. Cloud metadata endpoints are always refused, and a server's region redirect never carries the key from a public host, or from anhttp://endpoint, to a host on your network. - Credentials are stored in the OS-native credential store (macOS
Keychain, Windows Credential Manager, Linux Secret Service) via the
keyringlibrary. No plaintext API keys on disk. - All engine execution happens server-side — the CLI is a thin wrapper around the SDK which is a thin wrapper around the REST API. No engine code ever reaches the user's machine through this package, and every command works from this package alone.
- Rich output everywhere — progress spinners, colored outcome markers, tables, hints. The CLI is chatty by design.
Install
python3 -m pip install radmah-cli
rady --version
The install pulls radmah-sdk as a dependency. rady (and its
radmah alias) appear on $PATH via the [project.scripts] entry
in pyproject.toml.
Licence
Proprietary (LicenseRef-Proprietary); see the LICENSE file shipped with
the package. You may read the source and use the unmodified package to access
the RadMah AI platform under your account agreement; you may not copy, modify,
redistribute or reuse it.
Metadata
Release files for radmah-cli 1.4.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| radmah_cli-1.4.0.tar.gz | 136.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| radmah_cli-1.4.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 292.3 kB
Release files / radmah_cli-1.4.0.tar.gz
| Download URL | radmah_cli-1.4.0.tar.gz |
|---|---|
| Size | 136.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
1371e53f6bca9adb4d9ad22c5f209b9a7b04f3984dc80e34f1b937dea73a8b82
|
|
BLAKE2b-256 checksum How to use checksums |
9f92e2eed0a03caeea6262e54d18f65340230e67c78a775f6b9f6e6332652211
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / radmah_cli-1.4.0-py3-none-any.whl
| Download URL | radmah_cli-1.4.0-py3-none-any.whl |
|---|---|
| Size | 156.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
67ddbea4edc165bf9d72efafc0a444d0d03f75515de3e4e0cf7b319119154fc6
|
|
BLAKE2b-256 checksum How to use checksums |
b9033a463df9ed50efebe6d1111f65a554de7f308c8d9bc28f9f363e659c560a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|