# Command reference

> Every command and option.

## Setup and account

| Command | What it does |
|---|---|
| `aisync scan [--from DIR]` | Finds hardcoded tokens. Reads local files only, no login |
| `aisync login [--repo owner/name] [--branch B]` | Connects a repo with your gh login, creating it as private if missing |
| `aisync logout` | Forgets the repo and key on this machine. Your gh login stays |
| `aisync status` | Login, repo, store lock state, profiles |
| `aisync list` | Profiles, their config folders, and what is applied here |

## Profiles

| Command | What it does |
|---|---|
| `aisync new NAME [--extends BASE] [--config-dir DIR]` | Creates a profile in the repo |
| `aisync capture NAME [--from DIR] [--server S]… [--vault MOUNT/PREFIX] [--force]` | Makes a profile from this machine's setup. MCP tokens move to the encrypted store (or Vault) |
| `aisync diff NAME` | Shows what a pull would change |
| `aisync pull NAME [--dry-run] [--force]` | Applies the profile. `--force` takes the repo's version on conflict (yours is backed up) |
| `aisync push NAME [-m MSG] [--add PATH]… [--add-server S]… [--secrets] [--force]` | Uploads your changes. `--secrets` moves new plain-text tokens to the store; `--force` keeps yours on conflict |
| `aisync run NAME [-- ARGS…]` | Runs claude with the profile's config folder and environment |

## Secrets

| Command | What it does |
|---|---|
| `aisync secret list` | Lists names |
| `aisync secret set NAME [VALUE]` | Adds or replaces; prompts for the value if omitted |
| `aisync secret get NAME` | Prints the value |
| `aisync secret rm NAME` | Removes it |
| `aisync secret prune [--dry-run]` | Removes secrets no profile uses |
| `aisync passwd` | Changes the passphrase and re-encrypts the store |
| `aisync unlock` | Enters the passphrase on this machine and keeps the key |
| `aisync vault login --addr URL` | Stores a Vault token |
| `aisync vault token` | Prints it for scripts: `VAULT_TOKEN=$(aisync vault token)` |
| `aisync keystore [file\|keychain]` | Where this machine keeps keys. Use file on unattended Macs |

## Other

| Command | What it does |
|---|---|
| `aisync ui [--port N] [--no-open]` | Opens the admin UI |
| `aisync exec --repo R -- CMD…` | What Claude Code runs to start an MCP server. Run it yourself to see a server's error |
| `aisync headers --repo R K=V…` | headersHelper for HTTP MCP servers |
| `aisync version` | Version |

## Environment variables

| Name | Meaning |
|---|---|
| `GH_TOKEN`, `GITHUB_TOKEN` | Used instead of `gh auth token` when set |
| `AISYNC_KEYSTORE` | Overrides what `aisync keystore` saved (CI) |
| `AISYNC_PASSPHRASE` | Use this instead of asking for the passphrase (CI) |
| `AISYNC_CONFIG_DIR` | Where aisync keeps its settings (default `~/.config/aisync`) |
| `VAULT_ADDR`, `VAULT_TOKEN` | Used instead of the stored Vault settings when set |
