Install on macOS, Windows, or Linux
Download only a signed archive from the official channel. Every public release must include SHA-256 checksums.
Download channel not configured
Choose the archive for your operating system and architecture, extract it, then place the binary in a directory on PATH.
macOS
# After downloading the macOS archive
chmod +x ./naquada
sudo install -m 0755 ./naquada /usr/local/bin/naquadaLinux
# After downloading the Linux archive
chmod +x ./naquada
sudo install -m 0755 ./naquada /usr/local/bin/naquadaWindows PowerShell
$destination = "$env:LOCALAPPDATA\Naquada\bin"
New-Item -ItemType Directory -Force $destination
Copy-Item .\naquada.exe "$destination\naquada.exe"
[Environment]::SetEnvironmentVariable(
"Path",
[Environment]::GetEnvironmentVariable("Path", "User") + ";$destination",
"User"
)naquada --version
naquada --helpCheck
Install from source
For contributors who already have the monorepo and stable Rust.
cargo install --locked --path apps/naquada-cliSign in without copying a secret key
The interactive CLI uses a device code, like modern AI tools. Your password never passes through the terminal.
naquada login
naquada whoami- The CLI opens the Naquada Production page.
- You verify the code and approve the device in your account.
- The short session and refresh token are stored in the OS credential vault.
naquada logoutrevokes the remote session and removes the local copy.
Do not create a global key for the CLI
Link the current directory
Linking creates a Naquada project context and local receipt files. It does not crawl the repository.
naquada project link \
--name "My project" \
--tag my-project
naquada project statusConcrete result
.naquada/project.jsoncontains the project ID and tag..naquada/config.jsoncontains local rules only..naquada/runs/and.naquada/assets/exist.naquada project statusresolves the same production context.
Register the MCP server with Codex
This registers the current binary as an stdio MCP server for the workspace through the official codex mcp add command.
naquada setup codex --applyCheck
naquada is enabled.Command reference
Place --json before the subcommand for stable output intended for extensions and scripts.
naquada login / logout / whoamiManage the user session.naquada project linkCreate or attach the project context.naquada project statusCompare local and remote linkage.naquada run listList local receipts.naquada run status <id>Read remote status and the local receipt.naquada run resume <id>Resume an approved delivery.naquada run cancel <id>Request run cancellation.naquada mcp serveStart the stdio MCP server.naquada setup codex --applyRegister the server with Codex.naquada docsOpen this public documentation.naquada doctorCheck session, project, API, and directories.Asset delivery and recovery
Remote execution and local delivery are separate steps. The receipt makes delivery idempotent.
- Local references are hashed and uploaded only when the plan names them.
- An asset is staged in
.naquada/assets/, checked for size and SHA-256, then moved. - The final path must remain inside the workspace root.
- Without explicit overwrite, duplicate names become
-02,-03, and so on. - After restart,
run resumecontinues from the receipt. - No Git operation is ever performed.
naquada run list
naquada run status <run-id>
naquada run resume <run-id>Sessions, global keys, and publication keys
Naquada deliberately separates three credential types so an overly powerful key is not reused everywhere.
CLI / extension session
Device authorization, short renewable tokens, OS credential storage, and remote revocation on logout.
Global account key — nqk_acc_ prefix
For unattended automation. Select granular account, Board, and publication permissions. The secret is shown once; the key has expiration and rate limits and can be revoked immediately.
curl https://api.naquada.tech/api/account/v1/capabilities \
-H "Authorization: Bearer $NAQUADA_ACCOUNT_KEY"Publication key — ctr_prd_ or ctr_sbx_ prefix
Existing Sandbox/Production behavior is unchanged. A global key can use one only with externalizations:invoke, a matching Production-key delegation policy, and X-Naquada-Externalization-Key-Id. The publication key secret is never exposed.
curl "https://api.naquada.tech/api/v1/generate/my-slug?version=1" \
-H "Authorization: Bearer $NAQUADA_ACCOUNT_KEY" \
-H "X-Naquada-Externalization-Key-Id: <production-key-id>" \
-H "Content-Type: application/json" \
-d '{"inputs":{"prompt":"Hello"}}'Recommended rotation
Diagnostics and expected result
The JSON report lets an extension or a person verify every prerequisite.
naquada --json doctorResult
ok, authenticated, projectLinked, and apiReachable are true, paths point into the current project, and gitTouched is false.