Explicit instance
login-web names the NexusClaw instance instead of relying on an ambiguous target.
Developers / Governed DX
NexusClaw CLI brings organization login, target resolution, source sync, workforce training, release, and observation into the terminal while preserving platform permissions, workspace isolation, audit, and Release Gate.
It is not an administrative backdoor around the product control plane. Every remote write uses controlled APIs; target mismatch, source conflict, insufficient access, or missing release evidence fails explicitly.
01 / Identity & Target Context
Browser login uses OAuth 2.1 PKCE. Credentials are encrypted on the machine and never enter the project repository. Only non-secret environment descriptors and workspace bindings are shared. Remote commands verify org alias, instance URL, and workspace UUID before sending a request.
login-web names the NexusClaw instance instead of relying on an ambiguous target.
Flags, environment descriptor, manifest, and org credential converge on one target.
Machine A and B authenticate separately; Git carries the project and revision evidence.
Missing or inconsistent bindings stop before network access.
Developer machine
encrypted credential
OAuth 2.1 + PKCE
browser callback
Org alias dev
instance + identity
TargetContext
single resolution
Workspace UUID
remote isolation boundary
Machine A
nexus org login-web --alias dev
~/.nexusclaw/auth/dev.json
Machine B
nexus org login-web --alias dev
independent credential · same project
02 / Source & Revision Workflow
The YAML manifest is canonical and JSON is a validated generated projection. Source Tracking compares local, remote, and baseline. Pull and push support dry-run and path selection; conflicts block by default.
Check manifest, environment descriptors, and local package contracts.
Separate local, remote, drift, and conflict states.
Compare runtime, source, package, or composer.
Produce a plan without changing baselines or remote state.
Write selected paths and record before / after revision.
Use deployment history or package versions through existing audit paths.
03 / Workforce Lifecycle
Workforce commands are thin authenticated clients. Learning candidates still pass simulation, approval, and Release Gate. Provider configuration and workforce promote, rollback, and revoke require short-lived MFA step-up.
Role skills currently expose a read-only directory, so fake create/update/delete verbs are absent. Knowledge distillation has no on-demand mutation, so there is no workforce distill run. When the backend contract does not exist, the CLI does not pretend it does.
01 · Signal
Extract a learning signal from real execution.
02 · Draft
Generate and apply an explicit asset candidate.
03 · Simulate
Run tests and pre-release evidence.
04 · Approve
Route the release decision to an authorized person.
05 · Publish / roll back
Use registered owners and paired rollback paths.
04 / Automation & Evidence
Supported commands emit one `nexusclaw.cli-result/v1` document with `--json`: stable exit code, command, phase, data, diagnostics, evidence, and next commands. Secret fields, tokens, stacks, and raw provider responses are centrally scrubbed.
Query package version, Git SHA, and content digest directly.
Sort by file, JSON path, rule, and code.
JSON mode contains no spinner, color, banner, or prose.
beforeRevision, afterRevision, history, and rollback results form a continuous ledger.
Two machines read the same manifest, environment descriptors, and revision ledger from Git while holding independent org sessions. If the server revision advances, an older machine fails push instead of overwriting newer work.
Machine A
own login · revision 18
Machine B
own login · revision 19
Customer Evaluation Checklist
Install the CLI, complete PKCE login, and resolve exactly one workspace.
Create remote drift, then confirm visible status, blocked push, and no dry-run write.
Remove approval or evidence and confirm publish returns the real blocker.
Confirm one JSON document, stable exit code, and no token or secret field.
The CLI requires Node.js 18+ and a reachable NexusClaw instance. It does not replace Git, CI, or platform permissions, and it does not wrap unimplemented backend capabilities as commands. Public examples use placeholder instances and workspaces with no real credentials.
We will start from a clean-machine login and walk through target binding, diff, dry-run, controlled write, Release Gate, machine output, and rollback evidence.