CLI reference¶
The complete, information-oriented lookup surface for TOVIO. Every tovio command, every global flag,
every configuration file, every TVO-* error code, the public read API, and the developer-facing
glossary.
If you want to learn TOVIO, start with the tutorials. If you want to do a task, read the guides. This section is for looking things up.
Pages¶
| Page | What it covers |
|---|---|
| Command reference | Every command: synopsis, flags, examples, exit codes. |
| Global flags | --json, -q/--quiet, --format, NO_COLOR, short and git-compat aliases. |
| Configuration | The .tovio/ directory, config files, and .tovioignore. |
| Public Forge web API | The read-only /public/v1 routes the explorer reads. |
| Error reference | The three-part standard, exit-code classes, and the TVO-* catalog. |
| Glossary | Every term, defined once. |
Command index¶
Commands are grouped by interaction tier, which controls discovery (whether a command shows in
default tovio help), never capability — every command is always runnable by name. Tiers are distinct
from the cryptographic permission tiers (Solo / Team / Enterprise). See
tovio help for how the default help gates by tier.
Phase labels in the command reference identify roadmap ownership, not availability. Every command below
is present in the CLI today, with one exception that is marked as such in place. tovio help --all
prints the same three groups from the binary itself, so it is the fastest way to confirm the surface
your build actually carries.
Everyday — the daily loop¶
For all developers. These are the commands shown by a bare tovio help — the daily loop, and nothing
that is not part of it.
| Command | Purpose |
|---|---|
init |
Create a new repository. |
quickstart |
Interactive first-run tutorial. |
status |
Show current repository state — the source of truth. |
commit |
Finalize the current change; start the next. |
sync |
Share and receive changes (push + pull in one). (Phase 3) |
log |
Browse history. |
diff |
Compare versions. |
conflicts |
List every open conflict and how to resolve each. |
resolve |
Resolve a materialized conflict at a path. |
mv |
Rename or move a tracked file, recorded as one undoable move. |
lane |
Create, list, and delete lanes. |
switch |
Move to another lane or change. |
land |
Land a change onto a lane; auto-rebases the stack. |
change |
Manage work in progress. |
clone |
Clone a repository, sparse by default. (Phase 3) |
undo |
Undo the latest supported local op-log mutation. |
health |
Diagnose whether the current lane is clean, landable, and how stale. |
Team — collaboration & protection¶
For team leads and senior developers. Invisible in a Simple-Mode repository until reached for. (Phase 1 / Phase 3.)
| Command | Purpose |
|---|---|
policy |
Declare per-path read/write access policies. |
access |
Diagnose, request, and grant access. |
review |
Review a change proposal on the Forge. |
identity |
Manage cryptographic identities and attributes. |
key |
Back up, recover, and rotate the identity key. |
device |
Manage the per-device keys of one identity. |
agent |
Register AI agents and issue capability tokens. |
audit |
The append-only access log. |
forge |
Administer a Forge you operate. |
issue |
Open, browse, and close issues on a Forge. |
release |
Publish releases and their downloadable assets. |
fetch / push / pull |
One-direction sync primitives behind sync. |
serve |
Serve this repository to other machines over TLS. |
lock / locks |
Locks for unmergeable binary paths (locks is a deprecated alias for lock list). |
Advanced — power & maintenance¶
For security, DevOps, and architects. Gated out of default help.
| Command | Purpose |
|---|---|
restore |
Discard working-copy edits to a file, resetting it to its committed version. |
rebase |
Re-parent the current change onto another lane, keeping every Change ID. |
cherry-pick / revert |
Port a change onto another lane; mint a forward change that inverts a landed one. |
bisect |
Binary-search history for the change that introduced a regression. |
change split / change absorb |
Recover granularity without a staging index. |
redo |
Replay an undone operation. |
show |
Not implemented. Inspect an object with cat or audit show --object instead. |
cat / grep |
Print or search committed file contents, decrypting where you hold the key. |
blame |
Attribution by change, not commit. |
tag |
Create, list, or force-move an immutable tag. |
build-check |
Verify a target is conflict-free (buildable). |
explain |
Debug how a subsystem reached its state (merge, op-log, …). |
obliterate |
Permanently remove an object's payload. Destructive. |
behavioral |
Version an AI system's behavioral surface. |
semantic |
Query the optional symbol graph. |
git |
Git import / export / bridge. |
remote |
Manage named remotes for push / pull / land. |
meta |
Cross-repository (meta-) changes. |
sparse / materialize |
Declare a directory cone; check a commit's tree into the working copy. |
fsmonitor / autosync |
The filesystem-monitor daemon and the automatic-sync plumbing. |
fsck / gc |
Integrity check and garbage collection. (tovio --version prints the version.) |
config / completions |
Your local preferences; a shell completion script. |
plugin |
Manage sandboxed lifecycle plugins. |
ci |
Compile config-as-code pipelines and inspect imported CI. |
mcp serve |
Run the MCP server for agents. |
web-bridge / web-session |
Sign web-dashboard requests locally; authorize a browser's session key. |
Governed surface
TOVIO caps its command surface deliberately: "to add a command, remove or merge one." A new
top-level command must justify itself by removing or merging another. This is why the default
tovio help stays a short daily loop while the full surface remains one flag away.
Last reviewed September 9, 2026
Suggest an improvement to this page Not for security reports — see disclosure