CLI reference¶
The plugin CLI lives under two command groups: tovio plugin (install, trust, inspect, validate,
test, bind, run) and tovio policy hook (policy-integrated enforcing bindings).
All commands that produce machine-readable results support --json (REQ-PLUGIN-062).
Implemented
The tovio plugin command group, contracts, validation, and sandbox execution are shipped in the
Team/Advanced CLI (REQ-PLUGIN-061), and so are Ed25519 publisher signatures, the local trust
store, and bounded HTTPS installation. Execution needs a build with the sandbox compiled in — the
default build has it; a --no-default-features build reports "built without plugin execution"
rather than a false pass.
tovio plugin¶
tovio plugin install <source>¶
Install a plugin package into this repository's store (.tovio/plugins/<id>/), from either a local
path or an HTTPS URL. Validates the manifest before anything is written, so a bad package stores
nothing.
A local package is a directory holding manifest.toml plus at most one runtime artifact — or a
bare manifest.toml on its own, which installs a manifest-only local-development package.
An HTTPS package URL must end in / or /manifest.toml and serve a sibling plugin.wasm. It
must clear bounded retrieval (system-root TLS, connect/read time limits, response-size limits
enforced while reading), the artifact SHA-256, the publisher signature, the trust store, and the
revocation list before the local store changes (REQ-PLUGIN-089). URL credentials, fragments,
queries, redirects, non-success responses, other schemes, and archive extraction are all refused, as
are remote local_dev and hash-only packages.
$ tovio plugin install ./license-check # a package directory
$ tovio plugin install https://plugins.example.com/license-check/1.2.0/
tovio plugin trust <add|revoke|list>¶
Manage the repository-local trust store of Ed25519 publisher identities (REQ-PLUGIN-087/088).
Trust is granted per publisher, not per plugin, and revocation is enforced both at install and
before every execution.
$ tovio plugin trust add did:key:<64 hex digits> --label "Example Corp"
$ tovio plugin trust revoke did:key:<64 hex digits> --reason "key compromise"
$ tovio plugin trust list --json
A revocation is permanent in this store and is never silently reversed — it may even be recorded before the trust it revokes.
tovio plugin uninstall <plugin-id>¶
Remove an installed plugin: its store directory goes, and any local binding that referenced it is dropped with it.
tovio plugin list¶
Show installed plugins — id, name, version, type, and declared events. --json yields the full
inventory.
tovio plugin show <plugin-id>¶
Show one plugin's full validated manifest, its integrity status, and the local bindings that reference it, each with the capabilities that binding grants.
tovio plugin verify <plugin-id>¶
Re-verify an installed plugin's artifact hash, publisher signature, trust, and revocation state.
Emits TVO-PLUGIN-003 on any failure, fail-closed. Local hash-only and explicit local_dev
packages are reported as development-policy installs — never as publisher-verified.
tovio plugin validate <path>¶
Validate a manifest or package without installing it, and report the reason on failure. The CLI only
reads the file; the check itself is the pure tovio-core PluginManifest::validate
(REQ-PLUGIN-063). Writes nothing.
$ tovio plugin validate ./license-check # a package directory
$ tovio plugin validate ./manifest.toml # or the manifest alone
tovio plugin test <path> --event <event>¶
Run a plugin package over a sample event without installing it — the author's inner loop. It
resolves the package the way install does (a directory with manifest.toml plus a runtime
artifact), runs it in the sandbox under the manifest's own declared capabilities with no binding
involved, and prints the result. A dev run never gates.
Flags:
| Flag | Meaning |
|---|---|
--event <event> |
Which lifecycle event to run for (required). |
--json |
Emit the full result envelope for programmatic use. |
tovio plugin bind <plugin-id> --event <event> --mode advisory|enforcing¶
Create a local binding — not a repo/org/Forge policy gate (REQ-PLUGIN-025). It is refused if
the plugin's manifest does not declare the event, or the event is unknown. The binding is written
pinned to the exact version installed right now; the at_least version floor exists in the on-disk
format but has no flag, so it is hand-authored. See Bindings for the precedence rules.
Flags:
| Flag | Meaning |
|---|---|
--event <event> |
Which lifecycle event to bind (required). |
--mode advisory\|enforcing |
Binding mode (required). |
--required |
Add error/skipped/unsupported/unavailable to the blocking set. An enforcing binding already blocks on fail without this. An advisory binding marked required is recorded but never blocks. |
--paths <globs> |
Restrict by path (repeatable; empty ⇒ all). |
--branches <globs> |
Restrict by target lane/ref (repeatable; empty ⇒ all). |
--grant <cap> |
Grant one capability on this binding (repeatable). Deny-by-default, and the effective grant is always manifest ∩ binding, so this can never widen the manifest. |
--grant-read-path <glob> |
Grant one read_clear_paths glob (repeatable). |
--grant takes any of read_protected_metadata, write_working_copy, write_plugin_cache,
network_access, emit_audit, invoke_tovio_command, propose_resolution, propose_transform,
block_operation. read_protected_plaintext is deliberately not flag-grantable: passing it is
refused with TVO-PLUGIN-013 rather than silently dropped or silently honored.
tovio plugin unbind <plugin-id> --event <event>¶
Remove the local binding of that plugin to that event. --event is required; naming a pair with no
existing binding is TVO-PLUGIN-004.
tovio plugin bindings¶
List every local binding, with plugin id, version requirement, mode, required, filters, and the
granted capabilities. Supports --json.
tovio plugin run <plugin-id> --event <event> [--dry-run]¶
Run an installed, bound plugin over the current state in the capability-bounded sandbox. Its
effective capabilities are the manifest ∩ binding intersection. An enforcing binding that reports
fail makes the command exit non-zero, whether or not it is required.
--dry-run reports the result and what would block without gating the operation.
tovio plugin doctor¶
Config-and-health sweep over the whole plugin store — no execution. Every manifest parses and validates, every artifact's integrity is checked, and every binding resolves to an installed plugin and a declared event. Reports healthy vs. broken and exits non-zero on any problem, so CI can gate on it.
tovio policy hook¶
The policy-integrated hook surface (REQ-PLUGIN-066..068): it attaches a plugin to a lifecycle
event as an enforcing binding, whereas tovio plugin bind lets you choose the mode.
tovio policy hook add <event> <plugin-id> [--required] [--paths <globs>] [--branches <branches>]
[--grant <cap>] [--grant-read-path <glob>]
tovio policy hook remove <event> <plugin-id>
tovio policy hook list
tovio policy hook addcreates or updates an enforcing binding (REQ-PLUGIN-067); the plugin must be installed and declare the event. Being enforcing, it already blocks onfail;--requiredaddserror/skipped/unsupported/unavailable to that set.tovio policy hook listmakes every hook, including its granted capabilities, inspectable by humans and agents (REQ-PLUGIN-068).- The grant surface is the same deny-by-default one as
plugin bind— including the refusal ofread_protected_plaintext.
Hooks are local today
policy hook add writes into the same .tovio/plugins/bindings.toml store as plugin bind,
with scope = "local". It is not yet a signed org-policy artifact, and a local result is not a
Forge-side gate (REQ-PLUGIN-070). What the Forge enforces is an org allow/deny policy over
plugin ids plus attested, revision-stamped plugin:<id> checks.
Related commands¶
tovio explain pluginshows which plugins are bound to which events, advisory vs. enforcing, and their filters — without initializing or executing anything.tovio statussurfaces blocking plugin state when relevant (REQ-PLUGIN-064).tovio landsurfaces required plugin blockers (REQ-PLUGIN-065).tovio audit verifycovers plugin audit fields as part of the signed audit body.tovio resolve --aiuses the plugin framework for configured resolver plugins (REQ-PLUGIN-078).
Global flags¶
Plugin commands honor the standard global flags — see Global flags. The ones that matter here:
--json— machine-readable output on every command that produces a result (REQ-PLUGIN-062).-q/--quiet— suppress success and progress output; errors still print.
--justification is accepted here because it is a global flag, but no tovio plugin or
tovio policy hook command writes an audit entry today, so it has no effect on this surface. What
is audited is plugin execution: an enforcing run produces signed audit metadata
(REQ-PLUGIN-058..060) that tovio audit verify covers.
Related¶
Last reviewed September 9, 2026
Suggest an improvement to this page Not for security reports — see disclosure