Skip to main content

CLI Commands Reference

This page covers the terminal commands you run from your shell.

For in-chat slash commands, see Slash Commands Reference.

Global entrypoint

digit [global-options] <command> [subcommand/options]

Global options

OptionDescription
--version, -VShow version and exit.
--profile <name>, -p <name>Select which Digit profile to use for this invocation. Overrides the sticky default set by digit profile use.
--resume <session>, -r <session>Resume a previous session by ID or title.
--continue [name], -c [name]Resume the most recent session, or the most recent session matching a title.
--worktree, -wStart in an isolated git worktree for parallel-agent workflows.
--yoloBypass dangerous-command approval prompts.
--pass-session-idInclude the session ID in the agent's system prompt.
--ignore-user-configIgnore ~/.digit/config.yaml and fall back to built-in defaults. Credentials in .env are still loaded.
--ignore-rulesSkip auto-injection of AGENTS.md, SOUL.md, .cursorrules, memory, and preloaded skills.
--tuiLaunch the TUI instead of the classic CLI. Equivalent to DIGIT_TUI=1. Always wins over display.interface.
--cliForce the classic prompt_toolkit REPL. Use this to override display.interface: tui for a single invocation.
--devWith --tui: run the TypeScript sources directly via tsx instead of the prebuilt bundle (for TUI contributors).

Top-level commands

CommandPurpose
digit chatInteractive or one-shot chat with the agent.
digit modelInteractively choose the default provider and model.
digit moaConfigure named Mixture of Agents presets selectable from the model picker.
digit fallbackManage fallback providers tried when the primary model errors.
digit gatewayRun or manage the messaging gateway service.
digit proxyLocal OpenAI-compatible proxy that attaches OAuth provider credentials. See Subscription Proxy.
digit egressOutbound credential-injection firewall for remote terminal sandboxes (iron-proxy). Disabled by default. See Egress proxy.
digit lspManage Language Server Protocol integration (semantic diagnostics for write_file/patch).
digit setupInteractive setup wizard for all or part of the configuration.
digit whatsappConfigure and pair the WhatsApp bridge.
digit whatsapp-cloudConfigure the official Meta WhatsApp Business Cloud API adapter (Business account + public webhook required). Distinct from digit whatsapp (Baileys personal-account bridge).
digit slackSlack helpers (currently: generate the app manifest with every command as a native slash).
digit authManage credentials — add, list, remove, reset, status, logout. Handles OAuth flows for Codex/Nous/Anthropic.
digit login / logoutDeprecated — use digit auth instead.
digit sendSend a one-shot message to a configured messaging platform (Telegram, Discord, Slack, Signal, SMS, …). Useful from shell scripts, cron jobs, CI hooks, and monitoring daemons — no agent loop, no LLM.
digit secretsManage external secret sources (currently Bitwarden Secrets Manager) for pulling API keys at process startup instead of from ~/.digit/.env.
digit migrateDiagnose and (optionally) rewrite config.yaml to replace references to retired models or deprecated settings (e.g. migrate xai).
digit statusShow agent, auth, and platform status.
digit cronInspect and tick the cron scheduler.
digit kanbanMulti-profile collaboration board (tasks, links, dispatcher).
digit projectManage named, multi-folder workspaces (projects). Anchors desktop session grouping and, when bound to a kanban board, gives tasks a deterministic worktree + branch convention. State is per-profile.
digit webhookManage dynamic webhook subscriptions for event-driven activation.
digit hooksInspect, approve, or remove shell-script hooks declared in config.yaml.
digit doctorDiagnose config and dependency issues.
digit security auditOn-demand supply-chain audit (OSV.dev) for the venv, plugin requirements, and pinned MCP servers.
digit approvalsApproval-prompt tools — mine approval history into allowlist proposals.
digit dumpCopy-pasteable setup summary for support/debugging.
digit prompt-sizeShow a byte breakdown of the system prompt + tool schemas (skills index, memory, profile). Runs offline.
digit rule-checkAdd a business rule to an existing FTS specification by writing it in Russian. Prints how the statement was read, then a verdict from the real compiler and fts-gate. No model involved.
digit debugDebug tools — upload logs and system info for support.
digit backupBack up Digit home directory to a zip file.
digit checkpointsInspect / prune / clear ~/.digit/checkpoints/ (the shadow store used by /rollback). Run with no args for a status overview.
digit importRestore a Digit backup from a zip file.
digit logsView, tail, and filter agent/gateway/error log files.
digit configShow, edit, migrate, and query configuration files.
digit skinList, switch, and tweak display skins.
digit consoleOpen the safe Digit command console.
digit pairingApprove or revoke messaging pairing codes.
digit skillsBrowse, install, publish, audit, and configure skills.
digit bundlesGroup several skills under a single /<name> slash command. See Skill Bundles.
digit curatorBackground skill maintenance — status, run, pause, pin. See Curator.
digit journey (aliases learning, memory-graph)Timeline of learned skills + memories over time. digit journey sectors shows the same graph grouped by area of knowledge instead of by date.
digit memoryConfigure external memory provider. Plugin-specific subcommands (e.g. digit honcho) register automatically when their provider is active.
digit acpRun Digit as an ACP server for editor integration.
digit mcpManage MCP server configurations and run Digit as an MCP server.
digit pluginsManage Digit plugins (install, enable, disable, remove).
digit portalNous Portal status, subscription link, and Tool Gateway routing. See Tool Gateway.
digit toolsConfigure enabled tools per platform.
digit computer-useInstall or check the Computer Use (cua-driver) backend (macOS/Windows/Linux).
digit petsBrowse, install, and select petdex animated pets shown across the CLI, TUI, and desktop app. Subcommands: list, install, select, show, off, scale, remove, doctor.
digit sessionsBrowse, export, prune, rename, and delete sessions.
digit insightsShow token/cost/activity analytics.
digit clawOpenClaw migration helpers.
digit import-agentImport a Claude Code (~/.claude) or Codex CLI (~/.codex) setup.
digit dashboardLaunch the web dashboard for managing config, API keys, and sessions.
digit serveStart the Digit backend server (headless; powers the desktop app and remote backends).
digit desktop (alias gui)Build and launch the native Electron desktop app.
digit profileManage profiles — multiple isolated Digit instances.
digit completionPrint shell completion scripts (bash/zsh/fish).
digit versionShow version information.
digit updatePull latest code and reinstall dependencies. --check previews without installing; --backup takes a pre-pull DIGIT_HOME snapshot.
digit uninstallRemove Digit from the system.

digit chat

digit chat [options]

Common options:

OptionDescription
-q, --query "..."One-shot, non-interactive prompt.
-m, --model <model>Override the model for this run.
-t, --toolsets <csv>Enable a comma-separated set of toolsets.
--provider <provider>Force a provider: auto, openrouter, nous, openai-codex, copilot-acp, copilot, anthropic, gemini, huggingface, novita (aliases novita-ai, novitaai), openai-api, zai, kimi-coding, kimi-coding-cn, minimax, minimax-cn, minimax-oauth, kilocode, xiaomi, arcee, gmi, upstage (alias solar), alibaba, alibaba-coding-plan (alias alibaba_coding), deepseek, nvidia, ollama-cloud, xai (alias grok), xai-oauth (alias grok-oauth), qwen-oauth, bedrock, opencode-zen, opencode-go, ai-gateway, azure-foundry, lmstudio, stepfun, tencent-tokenhub (alias tencent, tokenhub).
-s, --skills <name>Preload one or more skills for the session (can be repeated or comma-separated).
-v, --verboseVerbose output.
-Q, --quietProgrammatic mode: suppress banner/spinner/tool previews.
--image <path>Attach a local image to a single query.
--resume <session> / --continue [name]Resume a session directly from chat.
--worktreeCreate an isolated git worktree for this run.
--checkpointsEnable filesystem checkpoints before destructive file changes.
--yoloSkip approval prompts.
--pass-session-idPass the session ID into the system prompt.
--ignore-user-configIgnore ~/.digit/config.yaml and use built-in defaults. Credentials in .env are still loaded. Useful for isolated CI runs, reproducible bug reports, and third-party integrations.
--ignore-rulesSkip auto-injection of AGENTS.md, SOUL.md, .cursorrules, persistent memory, and preloaded skills. Combine with --ignore-user-config for a fully isolated run.
--safe-modeTroubleshooting mode: disable ALL customizations — user config, rules/memory injection, plugins, shell hooks, and MCP servers (implies --ignore-user-config and --ignore-rules). Use to isolate whether a problem comes from your setup or from Digit itself.
--source <tag>Session source tag for filtering (default: cli). Use tool for third-party integrations that should not appear in user session lists.
--max-turns <N>Maximum tool-calling iterations per conversation turn (default: 500, or agent.max_turns in config).

Examples:

digit
digit chat -q "Summarize the latest PRs"
digit chat --provider openrouter --model anthropic/claude-sonnet-4.6
digit chat --toolsets web,terminal,skills
digit chat --quiet -q "Return only JSON"
digit chat --worktree -q "Review this repo and open a PR"
digit chat --ignore-user-config --ignore-rules -q "Repro without my personal setup"
digit chat --safe-mode -q "Is this bug mine or Digit'?"

digit -z <prompt> — scripted one-shot

For programmatic callers (shell scripts, CI, cron, parent processes piping in a prompt), digit -z is the purest one-shot entry point: single prompt in, final response text out, nothing else on stdout or stderr. No banner, no spinner, no tool previews, no Session: line — just the agent's final reply as plain text.

digit -z "What's the capital of France?"
# → Paris.

# Parent scripts can cleanly capture the response:
answer=$(digit -z "summarize this" < /path/to/file.txt)

Per-run overrides (no mutation to ~/.digit/config.yaml):

FlagEquivalent env varPurpose
-m / --model <model>DIGIT_INFERENCE_MODELOverride the model for this run
--provider <provider>(none)Override the provider for this run
--usage-file <path>(none)Write a JSON usage report after the run (see below)
digit -z "…" --provider openrouter --model openai/gpt-5.5
# or:
DIGIT_INFERENCE_MODEL=anthropic/claude-sonnet-4.6 digit -z "…"

Same agent, same tools, same skills — just strips every interactive / cosmetic layer. If you need tool output in the transcript too, use digit chat -q instead; -z is explicitly for "I only want the final answer".

--usage-file — JSON usage report for pipelines

digit -z "…" --usage-file /path/report.json writes a machine-readable usage report after the run: estimated_cost_usd, input_tokens / output_tokens / cache_read_tokens / cache_write_tokens / reasoning_tokens / total_tokens, api_calls, model, provider, session_id, service_tier, and completed / failed flags. The report is written even when the run fails, so batch pipelines can always account for spend. It has no effect outside -z/--oneshot, and a broken usage write never masks the run's own outcome.

digit -z "summarize this repo" --usage-file /tmp/usage.json
jq .estimated_cost_usd /tmp/usage.json

digit model

Interactive provider + model selector. This is the command for adding new providers, setting up API keys, and running OAuth flows. Run it from your terminal — not from inside an active Digit chat session.

digit model

Use this when you want to:

  • add a new provider (OpenRouter, Anthropic, Copilot, DeepSeek, custom, etc.)
  • log into OAuth-backed providers (Anthropic, Copilot, Codex, Nous Portal)
  • enter or update API keys
  • pick from provider-specific model lists
  • configure a custom/self-hosted endpoint
  • save the new default into config
digit model vs /model — know the difference

digit model (run from your terminal, outside any Digit session) is the full provider setup wizard. It can add new providers, run OAuth flows, prompt for API keys, and configure endpoints.

/model (typed inside an active Digit chat session) can only switch between providers and models you've already set up. It cannot add new providers, run OAuth, or prompt for API keys.

If you need to add a new provider: Exit your Digit session first (Ctrl+C or /quit), then run digit model from your terminal prompt.

/model slash command (mid-session)

Switch between already-configured models without leaving a session:

/model # Show current model and available options
/model claude-sonnet-4 # Switch model (auto-detects provider)
/model zai:glm-5 # Switch provider and model
/model custom:qwen-2.5 # Use model on your custom endpoint
/model custom # Auto-detect model from custom endpoint
/model custom:local:qwen-2.5 # Use a named custom provider
/model openrouter:anthropic/claude-sonnet-4 # Switch back to cloud

By default, /model changes apply to the current session only. Add --global to persist the change to config.yaml (or set model.persist_switch_by_default: true to make every switch persist):

/model claude-sonnet-4 --global # Switch and save as new default
What if I only see OpenRouter models?

If you've only configured OpenRouter, /model will only show OpenRouter models. To add another provider (Anthropic, DeepSeek, Copilot, etc.), exit your session and run digit model from the terminal.

On a --global switch, provider and base URL changes are persisted to config.yaml alongside the model. When switching away from a custom endpoint, the stale base URL is cleared to prevent it leaking into other providers.

digit gateway

digit gateway <subcommand>

Subcommands:

SubcommandDescription
runRun the gateway in the foreground. Recommended for WSL, Docker, and Termux.
startStart the installed systemd/launchd background service.
stopStop the service (or foreground process).
restartRestart the service.
statusShow service status.
listList all profiles and whether each profile's gateway is currently running (with PID where available). Handy when you run multiple profiles side-by-side and want a single overview.
installInstall as a systemd (Linux) or launchd (macOS) background service.
uninstallRemove the installed service.
setupInteractive messaging-platform setup.
migrate-legacyRemove legacy digit.service units left over from pre-rename installs. Profile units (digit-gateway-<profile>.service) and unrelated services are never touched. Flags: --dry-run, -y/--yes.
enrollExperimental: enroll this gateway with a relay connector and save relay credentials for connector-backed platforms. See Digit Relay.

Options:

OptionDescription
--allOn start / restart / stop: act on every profile's gateway, not just the active DIGIT_HOME. Useful if you run multiple profiles side-by-side and want to restart them all after digit update.
--no-superviseOn run: inside the s6-overlay Docker image, opt out of auto-supervision and use pre-s6 foreground semantics — gateway runs as the container's main process with no auto-restart. No-op outside the s6 image. Equivalent to setting DIGIT_GATEWAY_NO_SUPERVISE=1.
--external-supervisorOn run: declare that a wrapper-provided process manager owns the foreground gateway. Use this when sudo, env -i, or another wrapper strips launchd/systemd's native environment marker. In-chat restarts and updates exit back to that manager instead of spawning a detached replacement.

--external-supervisor is a restart-policy contract: an in-chat restart or service-restart update exits with status 75, so the wrapper's supervisor must relaunch the gateway after that nonzero exit. For systemd, use Restart=on-failure or Restart=always and do not include 75 in RestartPreventExitStatus; for launchd, configure KeepAlive to relaunch after unsuccessful exits. Without that policy, a requested restart leaves the gateway stopped.

digit gateway enroll accepts --token, --connector-url, --gateway-id, and --wake-url. It exchanges the enrollment token with the connector and writes the resulting GATEWAY_RELAY_ID, GATEWAY_RELAY_SECRET, GATEWAY_RELAY_DELIVERY_KEY, optional GATEWAY_RELAY_URL, and (when --wake-url is given) GATEWAY_RELAY_WAKE_URL values to the active profile's .env.

WSL users

Use digit gateway run instead of digit gateway start — WSL's systemd support is unreliable. Wrap it in tmux for persistence: tmux new -s digit 'digit gateway run'. See WSL FAQ for details.

digit lsp

digit lsp <subcommand>

Manage the Language Server Protocol integration. LSP runs real language servers (pyright, gopls, rust-analyzer, …) in the background and feeds their diagnostics into the post-write check used by write_file and patch. Gated on git workspace detection — LSP only runs when the cwd or edited file is inside a git worktree.

Subcommands:

SubcommandDescription
statusShow service state, configured servers, install status.
listPrint the registry of supported servers. Pass --installed-only to skip missing ones.
install <id>Eagerly install one server's binary.
install-allInstall every server with a known auto-install recipe.
restartTear down running clients so the next edit re-spawns.
which <id>Print the resolved binary path for one server.

See LSP — Semantic Diagnostics for the full guide, supported languages, and configuration knobs.

digit setup

digit setup [model|tts|terminal|gateway|tools|agent] [--non-interactive] [--reset] [--quick] [--reconfigure] [--portal]

Easiest path: digit setup --portal — OAuth into Nous Portal and opt into the Tool Gateway in one shot.

First run: launches the first-time wizard.

Returning user (already configured): drops straight into the full reconfigure wizard — every prompt shows your current value as its default, press Enter to keep or type a new value. No menu.

Jump into one section instead of the full wizard:

SectionDescription
modelProvider and model setup.
terminalTerminal backend and sandbox setup.
gatewayMessaging platform setup.
toolsEnable/disable tools per platform.
agentAgent behavior settings.

Options:

OptionDescription
--quickOn returning-user runs: only prompt for items that are missing or unset. Skip items you already have configured.
--non-interactiveUse defaults / environment values without prompts.
--resetReset configuration to defaults before setup.
--reconfigureBackwards-compat alias — bare digit setup on an existing install now does this by default.
--portalOne-shot Nous Portal setup: log in via OAuth, set Nous as the inference provider, and opt into the Tool Gateway. Skips the rest of the wizard.

digit portal

digit portal [status|open|tools]

Inspect Nous Portal auth, Tool Gateway routing, and reach the subscription page. Subcommand-less invocation runs status.

SubcommandDescription
status (default)Portal auth state + per-tool Tool Gateway routing summary. Also shown when no subcommand is given.
openOpen portal.nousresearch.com/manage-subscription in your default browser.
toolsList every Tool Gateway partner (Firecrawl, FAL, OpenAI TTS, Browser Use, Modal) and which are routed via Nous.

For configuration of the gateway itself, see Tool Gateway. For the one-shot setup path, see digit setup --portal above.

digit whatsapp

digit whatsapp

Runs the WhatsApp pairing/setup flow, including mode selection and QR-code pairing.

digit slack

digit slack manifest # print manifest to stdout
digit slack manifest --write # write to ~/.digit/slack-manifest.json
digit slack manifest --long-description-file AGENTS.md --write
digit slack manifest --slashes-only # just the features.slash_commands array

Generates a Slack app manifest that registers every gateway command in COMMAND_REGISTRY (/btw, /stop, /model, …) as a first-class Slack slash command — matching Discord and Telegram parity. Paste the output into your Slack app config at https://api.slack.com/apps → your app → Features → App Manifest → Edit, then Save. Slack prompts for reinstall if scopes or slash commands changed.

FlagDefaultPurpose
--write [PATH]stdoutWrite to a file instead of stdout. Bare --write writes $DIGIT_HOME/slack-manifest.json.
--name NAMEDigitBot display name in Slack.
--description DESCdefault blurbBot description shown in the Slack app directory.
--long-description TEXTunsetSet display_information.long_description inline (175–4,000 characters). Incompatible with --slashes-only.
--long-description-file PATHunsetRead the long description from a UTF-8 text file, preserving its contents exactly. Mutually exclusive with --long-description and incompatible with --slashes-only.
--slashes-onlyoffEmit only features.slash_commands for merging into a manually-maintained manifest.

Run digit slack manifest --write again after digit update to pick up any new commands.

digit send

digit send --to <target> "message text"
digit send --to <target> --file <path>
echo "message" | digit send --to <target>
digit send --list [platform]

Send a one-shot message to a configured messaging platform without spinning up an agent or gateway loop. Reuses the gateway's already-configured credentials (~/.digit/.env + ~/.digit/config.yaml) so ops scripts, cron jobs, CI hooks, and monitoring daemons can post status updates without reimplementing each platform's REST client.

For bot-token platforms (Telegram, Discord, Slack, Signal, SMS, WhatsApp-CloudAPI) no running gateway is required — digit send talks directly to the platform's REST endpoint. Plugin platforms that need a persistent adapter still require a live gateway.

OptionDescription
-t, --to <TARGET>Delivery target. Formats: platform (uses home channel), platform:chat_id, platform:chat_id:thread_id, or platform:#channel-name. Examples: telegram, telegram:-1001234567890, discord:#ops, slack:C0123ABCD, signal:+15551234567.
-f, --file <PATH>Read the message body from PATH (text files only — logs, reports, markdown). Pass - to force reading from stdin. To send an image or other binary file, use MEDIA:<path> (see below).
-s, --subject <LINE>Prepend a subject/header line before the message body.
-l, --list [platform]List configured targets across all platforms (or only the given platform).
-q, --quietSuppress stdout on success — useful in scripts (rely on exit code only).
--jsonEmit raw JSON result instead of human-readable output.

If neither a positional message argument nor --file is provided, digit send reads from stdin when it is not a TTY. Exit codes: 0 on success, 1 on delivery/backend failure, 2 on usage errors.

Sending images and other media

--file is for text bodies only. To deliver an image, document, video, or audio file as a native platform attachment, reference it inside the message text with the MEDIA:<local_path> directive:

digit send --to telegram "MEDIA:/tmp/screenshot.png"
digit send --to telegram "Build chart for today MEDIA:/tmp/chart.png" # with caption
digit send --to discord:#ops "MEDIA:/tmp/report.pdf"

By default, image files are sent as photos (platforms like Telegram recompress these). Add [[as_document]] to the message to deliver them as uncompressed file attachments instead:

digit send --to telegram "[[as_document]] MEDIA:/tmp/screenshot.png"

Examples:

digit send --to telegram "deploy finished"
echo "RAM 92%" | digit send --to telegram:-1001234567890
digit send --to discord:#ops --file /tmp/report.md
digit send --to slack:#eng --subject "[CI]" --file build.log
digit send --list # all platforms
digit send --list telegram # filter by platform

digit secrets

digit secrets bitwarden <subcommand>
digit secrets bw <subcommand> # short alias

Pull API keys from an external secret manager at process startup instead of storing them in ~/.digit/.env. Currently supports Bitwarden Secrets Manager. See the full guide: Bitwarden integration.

bitwarden (alias bw) subcommands:

SubcommandDescription
setupInteractive wizard: install the pinned bws binary, store an access token, and pick a project. Accepts --project-id, --access-token, and --server-url for non-interactive use.
statusShow current config, binary path/version, and token validation status.
tokenRotate the access token: validates the new token against Bitwarden before storing it in .env (a rejected token changes nothing). Accepts --access-token for non-interactive use and --no-verify to skip the probe.
syncFetch secrets now and report what changed. Add --apply to actually export the secrets into the current shell's environment (default is dry-run).
installDownload and verify the pinned bws binary. --force re-downloads even if a managed copy already exists.
disableTurn off the Bitwarden integration.

digit migrate

digit migrate <type>

Diagnose and (optionally) rewrite the active config.yaml to replace references to retired models or deprecated settings. A timestamped backup of the original config.yaml is taken before any rewrite (skip with --no-backup).

SubcommandDescription
xaiScan config.yaml for references to xAI models scheduled for retirement on May 15, 2026 and (with --apply) rewrite them in-place to the official replacements per the xAI migration guide. Defaults to dry-run.

Common flags for migration subcommands:

FlagDescription
--applyRewrite config.yaml in-place (default: dry-run, no writes).
--no-backupSkip the timestamped backup of config.yaml when applying.

Not to be confused with digit claw migrate (one-shot import of OpenClaw configuration into Digit) — digit migrate is the top-level config-rewrite command.

digit proxy

digit proxy <subcommand>

Run a local OpenAI-compatible HTTP server that forwards requests to an OAuth-authenticated upstream provider (e.g. Nous Portal, xAI). External apps can point at the proxy with any bearer token; the proxy attaches your real OAuth credentials on the way out. See Subscription Proxy for the full guide.

SubcommandDescription
startRun the proxy in the foreground. Flags: --provider <nous|xai> (default nous), --host <addr> (default 127.0.0.1; use 0.0.0.0 to expose on LAN), --port <int> (default 8645).
statusShow which proxy upstreams are ready (credentials present, OAuth valid).
providersList available proxy upstream providers.

digit security

digit security <subcommand>

On-demand vulnerability scan against OSV.dev. Covers the Digit venv (installed PyPI distributions), Python dependencies declared by plugins under ~/.digit/plugins/, and pinned npx/uvx MCP servers in config.yaml. Does NOT scan globally-installed packages or editor/browser extensions.

SubcommandDescription
auditRun a one-shot supply-chain audit.

audit flags:

FlagDefaultDescription
--jsonoffEmit machine-readable JSON instead of human-readable text.
--fail-on <level>criticalExit non-zero when any finding meets this severity (low, moderate, high, critical).
--skip-venvoffSkip scanning the Digit Python venv.
--skip-pluginsoffSkip scanning plugin requirements files.
--skip-mcpoffSkip scanning pinned MCP servers in config.yaml.

digit login / digit logout (Deprecated)

caution

digit login has been removed. Use digit auth to manage OAuth credentials, digit model to select a provider, or digit setup for full interactive setup.

digit auth

Manage credential pools for same-provider key rotation. See Credential Pools for full documentation.

digit auth # Interactive wizard
digit auth list # Show all pools
digit auth list openrouter # Show specific provider
digit auth add openrouter --api-key sk-or-v1-xxx # Add API key
digit auth add anthropic --type oauth # Add OAuth credential
digit auth remove openrouter 2 # Remove by index
digit auth reset openrouter # Clear cooldowns
digit auth status anthropic # Show auth status for a provider
digit auth logout anthropic # Log out and clear stored auth state
digit auth spotify # Authenticate Digit with Spotify via PKCE

Subcommands: add, list, remove, reset, status, logout, spotify. When called with no subcommand, launches the interactive management wizard.

digit status

digit status [--all] [--deep]
OptionDescription
--allShow all details in a shareable redacted format.
--deepRun deeper checks that may take longer.

digit cron

digit cron <list|create|edit|pause|resume|run|remove|status|tick>
SubcommandDescription
listShow scheduled jobs.
create / addCreate a scheduled job from a prompt, optionally attaching one or more skills via repeated --skill.
editUpdate a job's schedule, prompt, name, delivery, repeat count, or attached skills. Supports --clear-skills, --add-skill, and --remove-skill.
pausePause a job without deleting it.
resumeResume a paused job and compute its next future run.
runTrigger a job on the next scheduler tick.
removeDelete a scheduled job.
statusCheck whether the cron scheduler is running.
tickRun due jobs once and exit.

The cron trigger is pluggable via the cron.provider config key. Empty (the default) uses the built-in in-process ticker. Set it to chronos (the NAS-managed provider for scale-to-zero hosted gateways) — configured via the cron.chronos.* keys (portal_url, callback_url, expected_audience, nas_jwks_url) — or name a custom provider under plugins/cron/<name>/ or $DIGIT_HOME/plugins/<name>/. An unknown or unavailable provider falls back to the built-in, so cron is never left without a trigger. See the cron internals doc.

digit kanban

digit kanban [--board <slug>] <action> [options]

Multi-profile, multi-project collaboration board. Each install can host many boards (one per project, repo, or domain); each board is a standalone queue with its own SQLite DB and dispatcher scope. New installs start with one board called default, whose DB is ~/.digit/kanban.db for back-compat; additional boards live at ~/.digit/kanban/boards/<slug>/kanban.db. The gateway-embedded dispatcher sweeps every board per tick.

Global flags (apply to every action below):

FlagPurpose
--board <slug>Operate on a specific board. Defaults to the current board (set via digit kanban boards switch, the DIGIT_KANBAN_BOARD env var, or default).

This is the human / scripting surface. Agent workers spawned by the dispatcher drive the board through a dedicated kanban_* toolset (kanban_show, kanban_complete, kanban_block, kanban_create, kanban_link, kanban_comment, kanban_heartbeat; orchestrator profiles also get kanban_list and kanban_unblock) instead of shelling to digit kanban. Workers have DIGIT_KANBAN_BOARD pinned in their env so they physically cannot see other boards.

ActionPurpose
initCreate kanban.db if missing. Idempotent.
boards list / boards lsList all boards with task counts. --json, --all (include archived).
boards create <slug>Create a new board. Flags: --name, --description, --icon, --color, --switch (make active). Slug is kebab-case, auto-downcased.
boards switch <slug> / boards usePersist <slug> as the active board (writes ~/.digit/kanban/current).
boards show / boards currentPrint the currently-active board's name, DB path, and task counts.
boards rename <slug> "<name>"Change a board's display name. Slug is immutable.
boards rm <slug>Archive (default) or hard-delete a board. --delete skips the archive step. Archived boards move to boards/_archived/<slug>-<ts>/. Refused for default.
create "<title>"Create a new task on the active board. Flags: --body, --assignee, --parent (repeatable), --workspace scratch|worktree|dir:<path>, --tenant, --priority, --triage, --idempotency-key, --max-runtime, --max-retries, --skill (repeatable).
list / lsList tasks on the active board. Filter with --mine, --assignee, --status, --tenant, --archived, --json.
show <id>Show a task with comments and events. --json for machine output.
assign <id> <profile>Assign or reassign. Use none to unassign. Refused while task is running.
link <parent> <child>Add a dependency. Cycle-detected. Both tasks must be on the same board.
unlink <parent> <child>Remove a dependency.
claim <id>Atomically claim a ready task. Prints resolved workspace path.
comment <id> "<text>"Append a comment. The next worker that claims the task reads it as part of its kanban_show() response.
complete <id>Mark task done. Flags: --result, --summary, --metadata.
block <id> "<reason>"Mark task blocked for human input. Also appends the reason as a comment.
schedule <id> "<reason>"Park time-delay/follow-up work in scheduled so it is not shown as a human blocker.
unblock <id>Return a blocked or scheduled task to ready (or todo if dependencies are still open).
archive <id>Hide from default list. gc will remove scratch workspaces.
tail <id>Follow a task's event stream.
dispatchOne dispatcher pass on the active board. Flags: --dry-run, --max N, --failure-limit N, --json.
context <id>Print the full context a worker would see (title + body + parent results + comments).
specify <id> / specify --allFlesh out a triage-column task into a concrete spec (title + body with goal, approach, acceptance criteria) via the auxiliary LLM, then promote it to todo. Flags: --tenant (scope --all to one tenant), --author, --json. Configure the model under auxiliary.triage_specifier in config.yaml.
decompose <id> / decompose --allFan a triage-column task out into a graph of child tasks routed to specialist profiles by description. Falls back to specify-style single-task promotion when the LLM decides the task doesn't benefit from fan-out. Same flags as specify. Configure the decomposer model under auxiliary.kanban_decomposer in config.yaml; kanban.orchestrator_profile only controls who owns the root/orchestration task after fan-out. Also runs automatically every dispatcher tick when kanban.auto_decompose: true (the default). See Auto vs Manual orchestration.
gcRemove scratch workspaces for archived tasks.

Examples:

# Create a second board and put a task on it without switching away.
digit kanban boards create atm10-server --name "ATM10 Server" --icon 🎮
digit kanban --board atm10-server create "Restart server" --assignee ops

# Switch the active board for subsequent calls.
digit kanban boards switch atm10-server
digit kanban list # shows atm10-server tasks

# Archive a board (recoverable) or hard-delete it.
digit kanban boards rm atm10-server
digit kanban boards rm atm10-server --delete

Board resolution order (highest precedence first): --board <slug> flag → DIGIT_KANBAN_BOARD env var → ~/.digit/kanban/current file → default.

All actions are also available as a slash command in the gateway (/kanban …), with the same argument surface — including boards subcommands and the --board flag.

For the full design — comparison with Cline Kanban / Paperclip / NanoClaw / Gemini Enterprise, eight collaboration patterns, four user stories, concurrency correctness proof — see docs/digit-kanban-v1-spec.pdf in the repository or the Kanban user guide.

digit egress

Outbound credential-injection firewall for remote terminal sandboxes. Wraps the iron-proxy daemon — a TLS-intercepting proxy that swaps opaque proxy tokens for real upstream API credentials at the network boundary, so sandboxes never hold real keys. Disabled by default; see the full Egress proxy page for setup + architecture.

digit egress install # download the pinned iron-proxy binary
digit egress install --force # re-download even if already installed

digit egress setup # interactive wizard: CA, mappings, config
digit egress setup --tunnel-port N # override the tunnel listener port (default 9090)
digit egress setup --from-bitwarden # use Bitwarden Secrets Manager as credential source
digit egress setup --no-bitwarden # explicitly switch back to env-based credentials
digit egress setup --rotate-tokens # mint fresh proxy tokens (default preserves existing)

digit egress start # spawn the managed proxy daemon
digit egress stop # SIGTERM (then SIGKILL after 5s grace)
digit egress restart # stop (if running) then start — needed for secret changes
digit egress reload # hot-reload the ruleset in-place (no restart, no dropped
# connections) via the loopback management API

digit egress status # binary + config + pid + listening + mappings
digit egress status --show-tokens # print proxy tokens in full (default: redacted)

digit egress disable # flip proxy.enabled = false (does not stop a running proxy)
digit egress config # print the path to proxy.yaml for inspection

Common flows

# First-time setup
export OPENROUTER_API_KEY=
digit egress setup && digit egress start
digit config set terminal.backend docker # if not already

# Switching credential source after the fact
digit egress setup --from-bitwarden # env → bitwarden
digit egress setup --no-bitwarden # bitwarden → env
# (just `setup` without either flag preserves the existing mode)

# Rotating all tokens (e.g. after a suspected token leak)
digit egress setup --rotate-tokens # setup offers to restart the running daemon for you
# (running sandboxes still hold old tokens; restart them too)

# Adding a new upstream
# Edit ~/.digit/config.yaml proxy.extra_allowed_hosts: [api.example.com]
digit egress setup
digit egress restart # one-command apply (stop + start)

Diagnostic shortcuts

digit egress status # current state in one view
cat ~/.digit/proxy/proxy.yaml # the rendered iron-proxy config
tail -20 ~/.digit/proxy/iron-proxy.log # daemon-level diagnostics
tail -f ~/.digit/proxy/iron-proxy.log | jq # daemon + per-request log (line-delimited JSON; v0.39 combines both streams)

Common failure modes + recovery are covered in Egress proxy → Troubleshooting.

digit project

digit project <create|list|show|add-folder|remove-folder|rename|set-primary|use|archive|restore|bind-board>

Projects are human-named workspaces that can span multiple folders / repos. They anchor desktop session grouping and, when bound to a kanban board, give tasks a deterministic worktree + branch convention. State is per-profile.

SubcommandDescription
createCreate a new project.
list (alias ls)List projects.
showShow a project's details.
add-folderAdd a folder / repo to a project.
remove-folderRemove a folder from a project.
renameRename a project.
set-primarySet the primary folder.
useSet the active project.
archiveArchive a project (recoverable).
restoreRestore an archived project.
bind-boardBind a kanban board to this project.

digit webhook

digit webhook <subscribe|list|remove|test>

Manage dynamic webhook subscriptions for event-driven agent activation. Requires the webhook platform to be enabled in config — if not configured, prints setup instructions.

SubcommandDescription
subscribe / addCreate a webhook route. Returns the URL and HMAC secret to configure on your service.
list / lsShow all agent-created subscriptions.
remove / rmDelete a dynamic subscription. Static routes from config.yaml are not affected.
testSend a test POST to verify a subscription is working.

digit webhook subscribe

digit webhook subscribe <name> [options]
OptionDescription
--promptPrompt template with {dot.notation} payload references.
--eventsComma-separated event types to accept (e.g. issues,pull_request). Empty = all.
--descriptionHuman-readable description.
--skillsComma-separated skill names to load for the agent run.
--deliverDelivery target: log (default), telegram, discord, slack, github_comment.
--deliver-chat-idTarget chat/channel ID for cross-platform delivery.
--secretCustom HMAC secret. Auto-generated if omitted.
--deliver-onlySkip the agent — deliver the rendered --prompt as the literal message. Zero LLM cost, sub-second delivery. Requires --deliver to be a real target (not log).
--scriptFilter/transform script under ~/.digit/scripts/. The webhook payload is passed as JSON on stdin; JSON stdout replaces the payload, and empty stdout, [SILENT], or a nonzero exit code ignores the webhook. See Script Filters and Transforms.

Subscriptions persist to ~/.digit/webhook_subscriptions.json and are hot-reloaded by the webhook adapter without a gateway restart.

digit doctor

digit doctor [--fix]
OptionDescription
--fixAttempt automatic repairs where possible.

digit dump

digit dump [--show-keys]

Outputs a compact, plain-text summary of your entire Digit setup. Designed to be copy-pasted into Discord, GitHub issues, or Telegram when asking for support — no ANSI colors, no special formatting, just data.

OptionDescription
--show-keysShow redacted API key prefixes (first and last 4 characters) instead of just set/not set.

What it includes

SectionDetails
HeaderDigit version, release date, git commit hash
EnvironmentOS, Python version, OpenAI SDK version
IdentityActive profile name, DIGIT_HOME path
ModelConfigured default model and provider
TerminalBackend type (local, docker, ssh, etc.)
API keysPresence check for all 22 provider/tool API keys
FeaturesEnabled toolsets, MCP server count, memory provider
ServicesGateway status, configured messaging platforms
WorkloadCron job counts, installed skill count
Config overridesAny config values that differ from defaults

Example output

--- digit dump ---
version: 0.8.0 (2026.4.8) [af4abd2f]
os: Linux 6.14.0-37-generic x86_64
python: 3.11.14
openai_sdk: 2.24.0
profile: default
digit_home: ~/.digit
model: anthropic/claude-opus-4.6
provider: openrouter
terminal: local

api_keys:
openrouter set
openai not set
anthropic set
nous not set
firecrawl set
...

features:
toolsets: all
mcp_servers: 0
memory_provider: built-in
gateway: running (systemd)
platforms: telegram, discord
cron_jobs: 3 active / 5 total
skills: 42

config_overrides:
agent.max_turns: 250
compression.threshold: 0.85
display.streaming: True
--- end dump ---

When to use

  • Reporting a bug on GitHub — paste the dump into your issue
  • Asking for help in Discord — share it in a code block
  • Comparing your setup to someone else's
  • Quick sanity check when something isn't working
tip

digit dump is specifically designed for sharing. For interactive diagnostics, use digit doctor. For a visual overview, use digit status.

digit debug

digit debug share [options]

Upload a debug report (system info + recent logs) to a paste service and get a shareable URL. Useful for quick support requests — includes everything a helper needs to diagnose your issue.

OptionDescription
--lines <N>Number of log lines to include per log file (default: 200).
--expire <days>Paste expiry in days (default: 7).
--nousUpload to Nous-internal diagnostics storage instead of a public paste service. Use this when Nous support asks for a private diagnostic bundle.
--localPrint the report locally instead of uploading.
--no-redactDisable upload-time secret redaction. By default, uploads are redacted.

The report includes system info (OS, Python version, Digit version), recent agent, gateway, GUI/dashboard, and desktop logs (512 KB limit per file), and redacted API key status. By default, uploads are redacted so secrets are not included.

Default uploads use public paste services tried in order: paste.rs, dpaste.com. --nous uploads the same debug bundle to private Nous diagnostics storage instead; the returned viewer link is for the Nous team and auto-deletes after 14 days.

Examples

digit debug share # Upload debug report, print URL
digit debug share --lines 500 # Include more log lines
digit debug share --expire 30 # Keep paste for 30 days
digit debug share --nous # Upload a private diagnostics bundle for Nous support
digit debug share --local # Print report to terminal (no upload)

digit backup

digit backup [options]

Create a zip archive of your Digit configuration, skills, sessions, and data. The backup excludes the digit codebase itself.

OptionDescription
-o, --output <path>Output path for the zip file (default: ~/digit-backup-<timestamp>.zip).
-q, --quickQuick snapshot: only critical state files (config.yaml, state.db, .env, auth, cron jobs). Much faster than a full backup.
-l, --label <name>Label for the snapshot (only used with --quick).

The backup uses SQLite's backup() API for safe copying, so it works correctly even when Digit is running (WAL-mode safe).

What's excluded from the zip:

  • *.db-wal, *.db-shm, *.db-journal — SQLite's WAL / shared-memory / journal sidecars. The *.db file already got a consistent snapshot via sqlite3.backup(); shipping the live sidecars alongside it would let a restore see a half-committed state.
  • checkpoints/ — per-session trajectory caches. Hash-keyed and regenerated per session; wouldn't port cleanly to another install anyway.
  • The digit code itself (this is a user-data backup, not a repo snapshot).

Examples

digit backup # Full backup to ~/digit-backup-*.zip
digit backup -o /tmp/digit.zip # Full backup to specific path
digit backup --quick # Quick state-only snapshot
digit backup --quick --label "pre-upgrade" # Quick snapshot with label

digit checkpoints

digit checkpoints [COMMAND]

Inspect and manage the shadow git store at ~/.digit/checkpoints/ — the storage layer behind the in-session /rollback command. Safe to run any time; does not require the agent to be running.

SubcommandDescription
status (default)Show total size, project count, and per-project breakdown. Bare digit checkpoints is equivalent.
listAlias for status.
pruneForce a cleanup sweep — delete orphan and stale projects, GC the store, enforce the size cap. Ignores the 24h idempotency marker.
clearDelete the entire checkpoint base. Irreversible; asks for confirmation unless -f.
clear-legacyDelete only the legacy-<timestamp>/ archives produced by the v1→v2 migration.

Options

OptionSubcommandDescription
--limit Nstatus, listMax projects to list (default 20).
--retention-days NpruneDrop projects whose last_touch is older than N days (default 7).
--max-size-mb NpruneAfter the orphan/stale pass, drop the oldest commit per project until total store size ≤ N MB (default 500).
--keep-orphanspruneSkip deleting projects whose working directory no longer exists.
-f, --forceclear, clear-legacySkip the confirmation prompt.

Examples

digit checkpoints # status overview
digit checkpoints prune --retention-days 3 # aggressive cleanup
digit checkpoints prune --max-size-mb 200 # tighten size cap once
digit checkpoints clear-legacy -f # drop v1 archive dirs
digit checkpoints clear -f # wipe everything

See Checkpoints and /rollback for the full architecture and the in-session commands.

digit import

digit import <zipfile> [options]

Restore a previously created Digit backup into your Digit home directory. All files in the archive overwrite existing files in your Digit home; --force only skips the confirmation prompt that fires when the target already has a Digit installation.

OptionDescription
-f, --forceSkip the existing-installation confirmation prompt.
warning

Stop the gateway before importing to avoid conflicts with running processes.

Examples

digit import ~/digit-backup-20260423.zip # Prompts before overwriting existing config
digit import ~/digit-backup-20260423.zip --force # Overwrite without prompting

digit logs

digit logs [log_name] [options]

View, tail, and filter Digit log files. All logs are stored in ~/.digit/logs/ (or <profile>/logs/ for non-default profiles).

Log files

NameFileWhat it captures
agent (default)agent.logAll agent activity — API calls, tool dispatch, session lifecycle (INFO and above)
errorserrors.logWarnings and errors only — a filtered subset of agent.log
gatewaygateway.logMessaging gateway activity — platform connections, message dispatch, webhook events
guigui.logDashboard / TUI-gateway / PTY-bridge / websocket events
desktopdesktop.logElectron desktop app — boot, backend spawn output, and recent Python tracebacks

Options

OptionDescription
log_nameWhich log to view: agent (default), errors, gateway, or list to show available files with sizes.
-n, --lines <N>Number of lines to show (default: 50).
-f, --followFollow the log in real time, like tail -f. Press Ctrl+C to stop.
--level <LEVEL>Minimum log level to show: DEBUG, INFO, WARNING, ERROR, CRITICAL.
--session <ID>Filter lines containing a session ID substring.
--since <TIME>Show lines from a relative time ago: 30m, 1h, 2d, etc. Supports s (seconds), m (minutes), h (hours), d (days).
--component <NAME>Filter by component: gateway, agent, tools, cli, cron.

Examples

# View the last 50 lines of agent.log (default)
digit logs

# Follow agent.log in real time
digit logs -f

# View the last 100 lines of gateway.log
digit logs gateway -n 100

# Show only warnings and errors from the last hour
digit logs --level WARNING --since 1h

# Filter by a specific session
digit logs --session abc123

# Follow errors.log, starting from 30 minutes ago
digit logs errors --since 30m -f

# List all log files with their sizes
digit logs list

Filtering

Filters can be combined. When multiple filters are active, a log line must pass all of them to be shown:

# WARNING+ lines from the last 2 hours containing session "tg-12345"
digit logs --level WARNING --since 2h --session tg-12345

Lines without a parseable timestamp are included when --since is active (they may be continuation lines from a multi-line log entry). Lines without a detectable level are included when --level is active.

Log rotation

Digit uses Python's RotatingFileHandler. Old logs are rotated automatically — look for agent.log.1, agent.log.2, etc. The digit logs list subcommand shows all log files including rotated ones.

digit prompt-size

digit prompt-size [--platform <name>] [--json]

Reports the fixed prompt budget for a fresh session — what gets sent on every API call before any conversation content. Useful when a downstream adapter or proxy has a tighter prompt budget than the model's context window, or when you want to see which block (skills index, memory, profile) dominates.

It builds the same system prompt the agent would, then breaks it down:

  • System prompt total — full assembled prompt (identity, guidance, skills index, context files, memory, profile, timestamp).
  • Skills index — the <available_skills> block. This is often the largest single block when many skills are installed.
  • Memory and user profile — your MEMORY.md / USER.md snapshots.
  • Prompt tiers — stable / context / volatile, matching how Digit layers the prompt for cache-friendliness.
  • Tool schemas — the JSON for all enabled tools (the other half of the fixed per-call payload).

Runs entirely offline — no API call, works with no credentials configured.

# Human-readable breakdown for the CLI platform (default)
digit prompt-size

# Simulate a messaging platform's prompt (different platform hint)
digit prompt-size --platform telegram

# Machine-readable output for scripts
digit prompt-size --json
tip

The skills index and tool schemas scale with how many skills and tools you have enabled. To shrink the prompt, disable unused toolsets (digit tools) or uninstall skills you don't need (digit skills). Context files (AGENTS.md, .cursorrules) in your current directory also count toward the total.

digit rule-check

digit rule-check <SPEC.fts> "<statement>" ["<statement>" ...] [--utility <name>] [--fts] [--json]

Write a business rule in plain Russian and find out whether it actually holds in an existing FTS calculation. The statement is parsed by rules — no model — emitted as an FTS specification, compiled and executed by the real compiler, and screened by fts-gate for structural fallacies.

The specification argument is mandatory and comes first, because that is the whole contract: the rule is added to a declared schema, it is not reconstructed from the sentence. A bare "если сумма больше 1000, скидка 10%" with no declared fields is rejected — without a declared сумма there is nothing to check the rule against, only a guess about what сумма means.

The declared rules, properties and examples of the target utility are carried into the check, so the verdict is about the rule in the calculation, not the rule in isolation. That is what catches an uncovered gap between the new threshold and an old one, a rule fully shadowed by its neighbour, a violated property, and an example whose declared result the new rule changes.

Output, in this order:

  1. Прочитано так — the parsed rule translated back into Russian. This is the line that matters most: it is a reading of what will actually reach the compiler, so a mismatch with what you meant is visible before you trust a green verdict.
  2. The verdict — verified, refuted (naming the failed check and, where possible, a counterexample), or "не удалось формализовать".
  3. The boundary — printed in every answer, including green ones.
# The rule holds in this calculation
digit rule-check order.fts "если постоянный клиент равен да, то прибавить 5 процентов от суммы заказа"

# Check a rule together with a property it must not break
digit rule-check order.fts "если сумма заказа больше 1000, то прибавить 2000" "результат не больше 500"

# Show the specification that was compiled, or emit everything as JSON
digit rule-check order.fts "..." --fts
digit rule-check order.fts "..." --json

Exit codes: 0 verified, 1 refuted, 3 could not formalize, 4 the check did not happen at all (no compiler, unreadable spec, ambiguous utility). Three outcomes get three codes on purpose — "I did not understand" and "I understood, and it is wrong" are different statements, and merging them lies in both directions.

What this does not check

It checks that the conclusion follows from the premise, never that the premise is true — the system has no world model. "На экспорт начислять НДС 20 %" is factually wrong (exports are zero-rated) and will pass every check and come back green. That is why the boundary is printed in every answer rather than filed away in documentation.

Prerequisite

The compiler and the fallacy detector are an external process, not a copy in the Digit tree — a second copy of the compiler would be a second implementation of FTS semantics, and the whole point is that there is only one. Install it with digit mcp install fts-gate (the compiler ships with it), or point DIGIT_FTS_GATE_HOME at your own build. Without it the command refuses with exit code 4; it never degrades into an unverified answer.

digit config

digit config <subcommand>

Subcommands:

SubcommandDescription
showShow current config values.
editOpen config.yaml in your editor.
get <key> [--json]Print a single config value by dotted key (e.g. digit config get model.default). --json emits machine-readable output.
set <key> <value>Set a config value.
unset <key>Remove a config key, reverting it to the built-in default.
pathPrint the config file path.
env-pathPrint the .env file path.
checkCheck for missing or stale config.
migrateAdd newly introduced options interactively.

digit pairing

digit pairing <list|approve|revoke|clear-pending>
SubcommandDescription
listShow pending and approved users.
approve <platform> <code>Approve a pairing code.
revoke <platform> <user-id>Revoke a user's access.
clear-pendingClear pending pairing codes.

digit skills

digit skills <subcommand>

Subcommands:

SubcommandDescription
browsePaginated browser for skill registries.
searchSearch skill registries.
installInstall a skill.
inspectPreview a skill without installing it.
listList installed skills.
checkCheck installed hub skills for upstream updates.
updateReinstall hub skills with upstream changes when available.
auditRe-scan installed hub skills.
uninstallRemove a hub-installed skill.
resetUn-stick a bundled skill flagged as user_modified by clearing its manifest entry. With --restore, also replaces the user copy with the bundled version.
opt-outStop bundled skills from being seeded into the active profile. Writes a .no-bundled-skills marker so the installer, digit update, and any sync skip bundled-skill seeding. Safe by default — nothing on disk is touched. With --remove, also deletes already-present bundled skills that are unmodified (user-edited, hub-installed, and hand-written skills are never removed; previews and confirms first, --yes to skip).
opt-inUndo opt-out by removing the .no-bundled-skills marker so bundled skills are seeded again on the next digit update. With --sync, re-seed immediately.
publishPublish a skill to a registry.
snapshotExport/import skill configurations.
tapManage custom skill sources.
configInteractive enable/disable configuration for skills by platform.

Common examples:

digit skills browse
digit skills browse --source official
digit skills search react --source skills-sh
digit skills search https://mintlify.com/docs --source well-known
digit skills inspect official/security/1password
digit skills inspect skills-sh/vercel-labs/json-render/json-render-react
digit skills install official/migration/openclaw-migration
digit skills install skills-sh/anthropics/skills/pdf --force
digit skills install https://sharethis.chat/SKILL.md # Direct URL (+ referenced support files)
digit skills install https://example.com/SKILL.md --name my-skill # Override name when frontmatter has none
digit skills check
digit skills update
digit skills config
digit skills reset google-workspace
digit skills reset google-workspace --restore --yes
digit skills opt-out # stop future bundled-skill seeding (nothing deleted)
digit skills opt-out --remove --yes # also delete UNMODIFIED bundled skills
digit skills opt-in --sync # undo: remove marker and re-seed now

Notes:

  • --force can override non-dangerous policy blocks for third-party/community skills.
  • --force does not override a dangerous scan verdict.
  • --source skills-sh searches the public skills.sh directory.
  • --source well-known lets you point Digit at a site exposing /.well-known/skills/index.json.
  • --source browse-sh searches browse.sh's catalog of 200+ site-specific browser-automation skills. Identifiers look like browse-sh/airbnb.com/search-listings-ddgioa.
  • Passing an http(s)://…/*.md URL installs SKILL.md plus explicitly referenced files under references/, templates/, scripts/, assets/, and examples/. When frontmatter has no name: and the URL slug isn't a valid identifier, an interactive terminal prompts for a name; non-interactive surfaces (/skills install inside the TUI, gateway platforms) require --name <x> instead.

digit bundles

digit bundles <subcommand>

Skill bundles group several skills under one /<bundle-name> slash command. Invoking the bundle loads every referenced skill into a single combined user message. Storage: ~/.digit/skill-bundles/<slug>.yaml. See Skill Bundles for the YAML schema and behavior.

Subcommands:

SubcommandDescription
listList installed bundles (default when no subcommand given)
show <name>Show one bundle's name, description, skills, and file path
create <name>Create a new bundle. Pass --skill <id> (repeat) or omit for interactive entry. --description, --instruction, --force available.
delete <name>Remove a bundle file
reloadRe-scan ~/.digit/skill-bundles/ and report added/removed bundles

Examples:

digit bundles create backend-dev \
--skill github-code-review \
--skill test-driven-development \
--skill github-pr-workflow \
-d "Backend feature work"

digit bundles list
digit bundles show backend-dev
digit bundles delete backend-dev

In a chat session, /bundles lists installed bundles and /<bundle-name> loads one.

digit curator

digit curator <subcommand>

The curator is an auxiliary-model background task that periodically reviews agent-created skills, prunes stale ones, consolidates overlaps, and archives obsolete skills. Bundled and hub-installed skills are never touched. Archives are recoverable; auto-deletion never happens.

SubcommandDescription
statusShow curator status and skill stats
runTrigger a curator review now (blocks until the LLM pass finishes)
run --backgroundStart the LLM pass in a background thread and return immediately
run --dry-runPreview only — produce the review report with no mutations
backupTake a manual tar.gz snapshot of ~/.digit/skills/ (curator also snapshots automatically before every real run)
rollbackRestore ~/.digit/skills/ from a snapshot (defaults to newest)
rollback --listList available snapshots
rollback --id <ts>Restore a specific snapshot by id
rollback -ySkip the confirmation prompt
pausePause the curator until resumed
resumeResume a paused curator
pin <skill>Pin a skill so the curator never auto-transitions it
unpin <skill>Unpin a skill
restore <skill>Restore an archived skill
archive <skill>Archive a skill manually
pruneManually prune skills the curator would normally clean up
list-archivedList archived skills (recoverable via restore)

On a fresh install the first scheduled pass is deferred by one full interval_hours (7 days by default) — the gateway will not curate immediately on the first tick after digit update. Use digit curator run --dry-run to preview before that happens.

See Curator for behavior and config.

digit moa

Configure named Mixture of Agents presets. Presets appear as selectable models under a Mixture of Agents provider in every model picker; /moa <prompt> runs one prompt through the default preset.

digit moa list
digit moa configure [name]
digit moa delete <name>

digit moa configure reuses Digit' provider → model picker for each reference model and the aggregator. A preset is an execution-mode configuration, not a primary model or provider.

digit fallback

digit fallback <subcommand>

Manage the fallback provider chain. Fallback providers are tried in order when the primary model fails with rate-limit, overload, or connection errors.

SubcommandDescription
list (alias: ls)Show the current fallback chain (default when no subcommand)
addPick a provider + model (same picker as digit model) and append to the chain
remove (alias: rm)Pick an entry to delete from the chain
clearRemove all fallback entries

See Fallback Providers.

digit hooks

digit hooks <subcommand>

Inspect shell-script hooks declared in ~/.digit/config.yaml, test them against synthetic payloads, and manage the first-use consent allowlist at ~/.digit/shell-hooks-allowlist.json.

SubcommandDescription
list (alias: ls)List configured hooks with matcher, timeout, and consent status
test <event>Fire every hook matching <event> against a synthetic payload
revoke (aliases: remove, rm)Remove a command's allowlist entries (takes effect on next restart)
doctorCheck each configured hook: exec bit, allowlist, mtime drift, JSON validity, and synthetic run timing

See Hooks for event signatures and payload shapes.

digit memory

digit memory <subcommand>

Set up and manage external memory provider plugins. Available providers: honcho, openviking, mem0, hindsight, holographic, retaindb, byterover, supermemory. Only one external provider can be active at a time. Built-in memory (MEMORY.md/USER.md) is always active.

Subcommands:

SubcommandDescription
setupInteractive provider selection and configuration.
statusShow current memory provider config.
offDisable external provider (built-in only).
Provider-specific subcommands

When an external memory provider is active, it may register its own top-level digit <provider> command for provider-specific management (e.g. digit honcho when Honcho is active). Inactive providers do not expose their subcommands. Run digit --help to see what's currently wired in.

digit acp

digit acp

Starts Digit as an ACP (Agent Client Protocol) stdio server for editor integration.

Related entrypoints:

digit-acp
python -m acp_adapter

Install support first:

cd ~/.digit/digit && uv pip install -e '.[acp]'

See ACP Editor Integration and ACP Internals.

digit mcp

digit mcp <subcommand>

Manage MCP (Model Context Protocol) server configurations and run Digit as an MCP server.

SubcommandDescription
(none) or pickerInteractive catalog picker — browse Nous-approved MCPs and install/enable/disable.
catalogList Nous-approved MCPs (plain text, scriptable).
install <name>Install a catalog entry (e.g. digit mcp install n8n).
serve [-v|--verbose]Run Digit as an MCP server — expose conversations to other agents.
add <name> [--url URL] [--command CMD] [--auth oauth|header] [--args ...]Add a custom MCP server with automatic tool discovery. --args passes the remaining argv to the stdio command, so put it last.
remove <name> (alias: rm)Remove an MCP server from config.
list (alias: ls)List configured MCP servers.
test <name>Test connection to an MCP server.
configure <name> (alias: config)Toggle tool selection for a server.
login <name>Force re-authentication for an OAuth-based MCP server.

See MCP Config Reference, Use MCP with Digit, and MCP Server Mode.

digit plugins

digit plugins [subcommand]

Unified plugin management — general plugins, memory providers, and context engines in one place. Running digit plugins with no subcommand opens a composite interactive screen with two sections:

  • General Plugins — multi-select checkboxes to enable/disable installed plugins
  • Provider Plugins — single-select configuration for Memory Provider and Context Engine. Press ENTER on a category to open a radio picker.
SubcommandDescription
(none)Composite interactive UI — general plugin toggles + provider plugin configuration.
install <identifier> [--force]Install a plugin from a Git URL or owner/repo.
update <name>Pull latest changes for an installed plugin.
remove <name> (aliases: rm, uninstall)Remove an installed plugin.
enable <name>Enable a disabled plugin.
disable <name>Disable a plugin without removing it.
list (alias: ls)List installed plugins with enabled/disabled status.

Provider plugin selections are saved to config.yaml:

  • memory.provider — active memory provider (empty = built-in only)
  • context.engine — active context engine ("compressor" = built-in default)

General plugin disabled list is stored in config.yaml under plugins.disabled.

See Plugins and Build a Digit Plugin.

digit tools

digit tools [--summary]
OptionDescription
--summaryPrint the current enabled-tools summary and exit.

Without --summary, this launches the interactive per-platform tool configuration UI.

digit computer-use

digit computer-use <subcommand>

Subcommands:

SubcommandDescription
installRun the upstream cua-driver installer (macOS, Windows, and Linux).
install --upgradeRe-run the installer even if cua-driver is already on PATH. The upstream script always pulls the latest release, so this performs an in-place upgrade.
statusPrint whether cua-driver is on $PATH and which version is installed.

digit computer-use install is the stable entry point for installing the cua-driver binary used by the computer_use toolset. It runs the same upstream installer that digit tools invokes when you first enable Computer Use, so it's safe to use for re-running the install if the toolset toggle didn't trigger it (for example, on returning-user setups).

digit update automatically re-runs the upstream installer at the end of the update if cua-driver is on PATH, so most users will not need to call --upgrade manually. Use it when upstream ships a fix you want right now without waiting for the next Digit update.

digit pets

digit pets <list|install|select|show|off|scale|remove|doctor>

Petdex is a public gallery of animated sprite pets for coding agents. Install one and Digit shows it reacting to agent activity across the CLI, TUI, and desktop app.

SubcommandDescription
listBrowse the petdex gallery.
installInstall a pet from the gallery.
selectSet the active pet (writes display.pet.*).
showAnimate the active pet in the terminal.
offDisable the pet display.
scaleResize the pet everywhere (display.pet.scale).
removeDelete an installed pet.
doctorCheck pet setup + terminal graphics support.

You can also generate a brand-new pet from a text description with the /hatch slash command. See Pets.

digit sessions

digit sessions <subcommand>

Subcommands:

SubcommandDescription
listList recent sessions.
browseInteractive session picker with search and resume.
export <output> [--session-id ID]Export sessions to JSONL.
delete <session-id>Delete one session.
pruneDelete sessions matching filters: time bounds --older-than/--newer-than/--before/--after (durations like 5h/2d, bare days, or ISO timestamps); attributes --source, --title, --model, --provider, --branch, --end-reason, --user, --chat-id, --chat-type, --cwd; numeric bounds --min/--max-messages, --min/--max-tokens, --min/--max-cost, --min/--max-tool-calls; plus --include-archived, --dry-run, --yes. Default: older than 90 days.
archiveBulk-archive (soft-hide, no deletion) sessions matching the same filters as prune. Requires at least one filter.
statsShow session-store statistics.
rename <session-id> <title>Set or change a session title.

digit insights

digit insights [--days N] [--source platform]
OptionDescription
--days <n>Analyze the last n days (default: 30).
--source <platform>Filter by source such as cli, telegram, or discord.

digit claw

digit claw migrate [options]

Migrate your OpenClaw setup to Digit. Reads from ~/.openclaw (or a custom path) and writes to ~/.digit. Automatically detects legacy directory names (~/.clawdbot, ~/.moltbot) and config filenames (clawdbot.json, moltbot.json).

OptionDescription
--dry-runPreview what would be migrated without writing anything.
--preset <name>Migration preset: full (all compatible settings) or user-data (excludes infrastructure config). Neither preset imports secrets — pass --migrate-secrets explicitly.
--overwriteOverwrite existing Digit files on conflicts (default: refuse to apply when the plan has conflicts).
--migrate-secretsInclude API keys in migration. Required even under --preset full.
--no-backupSkip the pre-migration zip snapshot of ~/.digit/ (by default a single restore-point archive is written to ~/.digit/backups/pre-migration-*.zip before apply; restorable with digit import).
--source <path>Custom OpenClaw directory (default: ~/.openclaw).
--workspace-target <path>Target directory for workspace instructions (AGENTS.md).
--skill-conflict <mode>Handle skill name collisions: skip (default), overwrite, or rename.
--yesSkip the confirmation prompt.

What gets migrated

The migration covers 30+ categories across persona, memory, skills, model providers, messaging platforms, agent behavior, session policies, MCP servers, TTS, and more. Items are either directly imported into Digit equivalents or archived for manual review.

Directly imported: SOUL.md, MEMORY.md, USER.md, AGENTS.md, skills (4 source directories), default model, custom providers, MCP servers, messaging platform tokens and allowlists (Telegram, Discord, Slack, WhatsApp, Signal, Matrix, Mattermost), agent defaults (reasoning effort, compression, human delay, timezone, sandbox), session reset policies, approval rules, TTS config, browser settings, tool settings, exec timeout, command allowlist, gateway config, and API keys from 3 sources.

Archived for manual review: Cron jobs, plugins, hooks/webhooks, memory backend (QMD), skills registry config, UI/identity, logging, multi-agent setup, channel bindings, IDENTITY.md, TOOLS.md, HEARTBEAT.md, BOOTSTRAP.md.

API key resolution checks three sources in priority order: config values → ~/.openclaw/.envauth-profiles.json. All token fields handle plain strings, env templates (${VAR}), and SecretRef objects.

For the complete config key mapping, SecretRef handling details, and post-migration checklist, see the full migration guide.

Examples

# Preview what would be migrated
digit claw migrate --dry-run

# Full migration (all compatible settings, no secrets)
digit claw migrate --preset full

# Full migration including API keys
digit claw migrate --preset full --migrate-secrets

# Migrate user data only (no secrets), overwrite conflicts
digit claw migrate --preset user-data --overwrite

# Migrate from a custom OpenClaw path
digit claw migrate --source /home/user/old-openclaw

digit import-agent

digit import-agent [claude-code|codex] [options]

Import a Claude Code (~/.claude) or OpenAI Codex CLI (~/.codex) setup into Digit. Maps CLAUDE.md/AGENTS.md instructions to memory entries, Bash(...) permission allow/deny rules to command_allowlist/approvals.deny, MCP servers to mcp_servers in config.yaml, and skill directories into ~/.digit/skills/. Always previews before applying; API keys and credentials are never imported.

OptionDescription
agentclaude-code or codex (default: auto-detect).
--source <path>Custom source directory (default: ~/.claude or ~/.codex).
--dry-runPreview only — write nothing.
--overwriteReplace conflicting MCP servers / skills (default: skip).
--yes, -ySkip confirmation prompts.

See the import guide for the full mapping tables.

digit serve

digit serve [options]

Start the Digit backend server — the JSON-RPC/WebSocket gateway the desktop app and remote clients connect to. It is the same server digit dashboard runs, but headless: it never opens a browser UI. The desktop app launches its own digit serve backend; use this command directly when you want a headless backend on a remote host. Accepts the same --host / --port / --insecure / --skip-build / --stop / --status options as digit dashboard below (a non-loopback bind engages the same auth gate). Requires the [web] extra; the embedded Chat socket additionally needs [pty] on a POSIX host.

digit dashboard

digit dashboard [options]

Launch the web dashboard — a browser-based UI for managing configuration, API keys, and monitoring sessions. (For a headless backend with no browser UI — e.g. what the desktop app spawns — use digit serve above.) Requires cd ~/.digit/digit && uv pip install -e ".[web]" (FastAPI + Uvicorn). The embedded browser Chat tab is always available and additionally needs the pty extra (cd ~/.digit/digit && uv pip install -e ".[web,pty]") plus a POSIX PTY environment such as Linux, macOS, or WSL2. See Web Dashboard for full documentation.

OptionDefaultDescription
--port9119Port to run the web server on
--host127.0.0.1Bind address
--no-openDon't auto-open the browser
--insecureoffDeprecated / no-op. Formerly bypassed auth on a non-loopback bind. Since the June 2026 hardening a public bind always requires an auth provider (password or OAuth). Bind 127.0.0.1 and tunnel to keep it local.
--skip-buildoffSkip the web UI build step and serve the existing dist directly. Useful for non-interactive contexts (Windows Scheduled Tasks, CI) where npm isn't available. Pre-build with cd web && npm run build.
--isolatedoffWhen launched from a named profile (worker dashboard), run a dedicated per-profile server instead of routing to the machine dashboard.
--stopStop running digit dashboard processes and exit.
--statusList running digit dashboard processes and exit.

digit dashboard register

Register this install as a self-hosted dashboard with your Nous Portal account. Creates an OAuth client, writes DIGIT_DASHBOARD_OAUTH_CLIENT_ID into ~/.digit/.env, and prints how to engage the login gate. Requires being logged in (digit setup).

OptionDescription
--nameHuman-readable label for the dashboard (default: auto-generated).
--redirect-uriPublic HTTPS OAuth redirect URI (e.g. https://digit.example.com/auth/callback). Omit for localhost-only use.
--portal-urlOverride the Nous Portal base URL for registration (default: the portal you logged into). Also settable via DIGIT_DASHBOARD_PORTAL_URL.
# Default — opens browser to http://127.0.0.1:9119
digit dashboard

# Custom port, no browser
digit dashboard --port 8080 --no-open

# From a profile alias — routes to the machine dashboard with the
# profile preselected in the sidebar switcher (attach if running)
worker dashboard

digit profile

digit profile <subcommand>

Manage profiles — multiple isolated Digit instances, each with its own config, sessions, skills, and home directory.

SubcommandDescription
listList all profiles.
use <name>Set a sticky default profile.
create <name> [--clone] [--clone-all] [--clone-from <source>] [--no-alias]Create a new profile. --clone copies config, .env, SOUL.md, and skills from the active profile. --clone-all copies all state. --clone-from specifies a source profile and implies config clone unless paired with --clone-all.
delete <name> [-y]Delete a profile.
show <name>Show profile details (home directory, config, etc.).
alias <name> [--remove] [--name NAME]Manage wrapper scripts for quick profile access.
rename <old> <new>Rename a profile.
export <name> [-o FILE]Export a profile to a .tar.gz archive (local backup).
import <archive> [--name NAME]Import a profile from a .tar.gz archive (local restore).
install <source> [--name N] [--alias] [--force] [-y]Install a profile distribution from a git URL or local directory.
update <name> [--force-config] [-y]Re-pull a distribution; preserves user data (memories, sessions, auth).
info <name>Show a profile's distribution manifest (version, requirements, source).

Examples:

digit profile list
digit profile create work --clone
digit profile use work
digit profile alias work --name h-work
digit profile export work -o work-backup.tar.gz
digit profile import work-backup.tar.gz --name restored
digit profile install github.com/user/my-distro --alias
digit profile update work
digit -p work chat -q "Hello from work profile"

digit completion

digit completion [bash|zsh|fish]

Print a shell completion script to stdout. Source the output in your shell profile for tab-completion of Digit commands, subcommands, and profile names.

Examples:

# Bash
digit completion bash >> ~/.bashrc

# Zsh
digit completion zsh >> ~/.zshrc

# Fish
digit completion fish > ~/.config/fish/completions/digit.fish

digit update

digit update [--gateway] [--check] [--no-backup] [--backup] [--yes]

Pulls the latest digit code and reinstalls dependencies in the managed venv, then re-runs the post-install hooks (MCP servers, skills sync, completion install). Safe to run on a live install. Use --check to see whether your checkout is behind origin/main without installing.

digit update pulls the configured update branch (default: main). If your checkout is on another branch, Digit may check out the update branch before pulling. Commit branch work before updating when you want to keep it outside the update autostash flow.

OptionDescription
--gatewayInternal mode used by the messaging /update command. Uses file-based IPC for prompts and progress streaming instead of reading from terminal stdin. Not a gateway restart flag.
--checkCheck whether an update is available without pulling, installing dependencies, or restarting anything.
--no-backupSkip all pre-update backups for this run (both the quick state snapshot and the full zip), regardless of updates.pre_update_backup.
--backupForce a full pre-update backup for this run: the quick state snapshot plus a complete zip of DIGIT_HOME (config, auth, sessions, skills, pairing data). The default mode is quick — a lightweight state snapshot only. Set the permanent mode via `updates.pre_update_backup: quick
--yes, -yAssume yes for interactive prompts such as config migration and stash restore. API-key entry is skipped; run digit config migrate separately for those.

Additional behavior:

  • Gateway restart. After a successful update, Digit attempts to restart all running gateway profiles automatically so they pick up the new code. Use digit gateway restart when you want to restart a gateway without applying an update.
  • Local source changes. For git installs, dirty tracked files and untracked files are auto-stashed before branch checkout or pull (git stash push --include-untracked). Interactive terminal updates ask before restoring the stash. Non-interactive updates restore it by default; set updates.non_interactive_local_changes: discard only on managed installs where local source edits should be thrown away after a successful pull. If stash restore conflicts or the pull fails, the stash is left in place for manual recovery.
  • npm lockfile churn. Before stashing or switching branches, Digit makes a best-effort cleanup of tracked package-lock.json diffs produced by npm install/build steps. Commit or manually stash intentional lockfile edits before running digit update.
  • Pairing data snapshot. Even when --backup is off, digit update takes a lightweight snapshot of ~/.digit/pairing/ and the Feishu comment rules before git pull. You can roll it back with digit backup restore --state pre-update if a pull rewrites a file you were editing.
  • Legacy digit.service warning. If Digit detects a pre-rename digit.service systemd unit (instead of the current digit-gateway.service), it prints a one-time migration hint so you can avoid flap-loop issues.
  • Exit codes. 0 on success, 1 on pull/install/post-install errors, 2 on unexpected working-tree changes that block git pull.

Maintenance commands

CommandDescription
digit versionPrint version information.
digit updatePull latest changes and reinstall dependencies.

| digit uninstall [--full] [--gui] [--dry-run] [--yes] | Remove Digit, optionally deleting all config/data. --gui removes only the desktop Chat GUI, leaving the agent intact; --full also deletes config/data; --dry-run prints what would be removed without changing anything; --yes skips prompts. |

See also