Zylch CLI
Thin CLI client for Zylch AI - your AI assistant for email, calendar, and relationship intelligence.
Architecture
The CLI is a thin client that communicates with the Zylch API server. All business logic, AI processing, and data storage happens on the server. The CLI handles:
- User authentication (Firebase OAuth via browser)
- Service connections (Google, Microsoft, Anthropic)
- Interactive chat with slash command support
- Local caching for offline access
- Modifier queue for offline operations
┌─────────────┐ HTTP API ┌──────────────┐
│ Zylch CLI │ ───────────────────────► │ Zylch Server │
│ (Thin) │ ◄─────────────────────── │ (FastAPI) │
└─────────────┘ └──────────────┘
│ │
▼ ▼
Local Cache Supabase
(SQLite) (PostgreSQL)
Installation
pip install zylch-cli
From source
git clone https://github.com/malemi/zylch-cli.git
cd zylch-cli
pip install -e .
Quick Start
# Start the CLI (connects to production server by default)
zylch
# Or connect to a specific server
zylch --server-url http://localhost:9000
Configuration
Configuration is stored in ~/.zylch/cli_config.json:
{
"api_server_url": "https://api.zylchai.com",
"session_token": "",
"owner_id": "",
"email": "",
"local_db_path": "~/.zylch/local_data.db",
"enable_offline": true,
"max_offline_days": 7,
"auto_sync_on_start": false
}
Commands
Session & Authentication (Client-side)
| Command | Description |
|---|---|
/login |
Login via browser (Firebase OAuth) |
/logout |
Logout and clear session |
/status |
Show CLI status and cache stats |
/new |
Start new conversation |
/quit, /exit |
Exit Zylch |
Integrations (Client-side)
| Command | Description |
|---|---|
/connect |
Show all service connection status |
/connect anthropic |
Set your Anthropic API key (required for chat) |
/connect google |
Connect Google (Gmail, Calendar) via OAuth |
/connect microsoft |
Connect Microsoft (Outlook, Calendar) |
/connect --reset |
Disconnect all services |
Data & Sync (Server-side)
| Command | Description |
|---|---|
/sync [days] |
Sync emails & calendar from connected services |
/gaps |
Show relationship gaps analysis |
/briefing |
Get daily briefing |
/archive |
Email archive management (--help for details) |
/cache |
Cache management (--help for details) |
AI & Memory (Server-side)
| Command | Description |
|---|---|
/memory |
Behavioral memory management (--help for details) |
/model [haiku|sonnet|opus|auto] |
Switch AI model tier |
/trigger |
Event automation (--help for details) |
Sharing (Server-side)
| Command | Description |
|---|---|
/share <email> |
Share data with another user |
/revoke <email> |
Revoke sharing access |
/sharing |
Show current sharing status |
Other (Server-side)
| Command | Description |
|---|---|
/mrcall |
Link to MrCall assistant |
/tutorial |
Interactive tutorial |
/help |
Show all commands |
Authentication Flow
- User runs
/login - CLI starts local HTTP server on
localhost:8765 - Browser opens to
{server}/api/auth/oauth/initiate - User completes Firebase/Google OAuth in browser
- Server redirects to
localhost:8765/callback?token=... - CLI captures JWT token, saves to config
- Token used for all subsequent API calls
Token Expiry: Firebase JWT tokens expire after ~1 hour. The CLI checks token expiry locally before making requests. If expired, user is prompted to /login again.
Service Connection Flow (Google/Microsoft)
- User runs
/connect google - CLI calls
/api/auth/google/authorizeto get OAuth URL - Browser opens to Google consent screen
- User authorizes Gmail/Calendar access
- Callback stores tokens in Supabase (server-side)
- CLI receives success confirmation
Important: OAuth tokens are stored in Supabase, not locally. This allows the same credentials to work across CLI and web dashboard.
Offline Support
The CLI includes offline capabilities:
-
Local Cache: SQLite database at
~/.zylch/local_data.db- Cached emails, calendar events, contacts
- 7-day TTL for cached data
-
Modifier Queue: Operations queued when offline
- Email drafts, sends
- Calendar event creation
- Synced when connection restored via
POST /api/data/modifier
Project Structure
zylch-cli/
├── zylch_cli/
│ ├── __init__.py
│ ├── cli.py # Main CLI (Click + Rich + prompt_toolkit)
│ ├── api_client.py # HTTP client for Zylch API
│ ├── config.py # Configuration + JWT parsing
│ ├── oauth_handler.py # Browser OAuth flow
│ ├── local_storage.py # SQLite cache
│ └── modifier_queue.py # Offline operation queue
├── pyproject.toml # Poetry configuration
└── README.md
Key Files
| File | Purpose |
|---|---|
cli.py |
Main entry point, slash commands, chat loop with autocomplete |
api_client.py |
All HTTP calls to api.zylchai.com |
config.py |
Load/save config, JWT expiry parsing |
oauth_handler.py |
Local callback server for OAuth |
local_storage.py |
SQLite caching for offline access |
modifier_queue.py |
Queue offline operations for later sync |
API Endpoints Used
Authentication
POST /api/auth/login- Login with Firebase tokenPOST /api/auth/logout- Invalidate sessionGET /api/auth/session- Get session infoPOST /api/auth/refresh- Refresh token (exists but not auto-used)
Service Connections
GET /api/auth/google/status- Check Google connectionGET /api/auth/google/authorize- Get Google OAuth URLPOST /api/auth/google/revoke- Disconnect GoogleGET /api/auth/anthropic/status- Check Anthropic keyPOST /api/auth/anthropic/key- Save Anthropic API keyPOST /api/auth/anthropic/revoke- Delete Anthropic key
Chat
POST /api/chat/message- Send message (includes slash commands)GET /api/chat/history- Get conversation history
Data
GET /api/data/emails- List email threadsGET /api/data/calendar- List calendar eventsGET /api/data/contacts- List contactsPOST /api/data/modifier- Apply offline modifications
Health
GET /health- Server health check
Development
# Install with dev dependencies
pip install -e ".[dev]"
# Run CLI
zylch
# Run tests
pytest
# Format code
black zylch_cli/
ruff check zylch_cli/
Production URLs
| Service | URL |
|---|---|
| API Server | https://api.zylchai.com |
| Web Dashboard | https://app.zylchai.com |
| Website | https://zylchai.com |
Known Gaps
-
Token Refresh: The
refresh_token()method exists but isn't called automatically. Users must manually/loginwhen token expires. -
Microsoft Support: Endpoints exist but not fully implemented yet.
-
Keychain Storage: Tokens stored in plaintext JSON. TODO: Use system keychain.
What This CLI Does NOT Do
- Access Google/Microsoft APIs directly (server handles this)
- Store OAuth credentials locally (only session token)
- Process emails/calendar locally (server-side)
- Run AI models (server uses your Anthropic key)
All business logic lives on the server (api.zylchai.com).
Release files for zylch-cli 0.9.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| zylch_cli-0.9.2.tar.gz | 33.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| zylch_cli-0.9.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 67.0 kB
Release files / zylch_cli-0.9.2.tar.gz
| Download URL | zylch_cli-0.9.2.tar.gz |
|---|---|
| Size | 33.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
1502b6a9d1d0452bcb19df39590867e2f460f081c826782c579bcfbff161de09
|
|
BLAKE2b-256 checksum How to use checksums |
d463af608efa1ca1cf0550e6e7914488b4ce61c881046535b5f1dc35d3c75583
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jan 16, 2026.
Transparency logRelease files / zylch_cli-0.9.2-py3-none-any.whl
| Download URL | zylch_cli-0.9.2-py3-none-any.whl |
|---|---|
| Size | 33.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
0518f59e22c29c585434bae126f6829410f379c07cfc78a286f586459057bde4
|
|
BLAKE2b-256 checksum How to use checksums |
495617d4b3273156abc850db4db559eee847c99d4477e463e5acb1f2bc516625
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jan 16, 2026.
Transparency log