# @bpmnkit/cli

Command-line interface for Camunda 8 — deploy, manage, and monitor processes from the terminal

- **Type:** MCP server
- **Trust:** 85/100 (A), scored on the package rubric
- **Verification:** verified (build provenance)
- **Version:** 1.1.0
- **Author:** Unknown
- **License:** MIT
- **npm:** @bpmnkit/cli
- **Source:** https://github.com/bpmnkit/monorepo
- **Compatible clients:** claude-code, cursor, copilot, gemini (basis: transport)

## Trust

85/100 (A), scored on the package rubric
- Publisher verified: no
- Build provenance: verified attestation
- npm trusted publishing (OIDC): yes
- Install scripts: nothing suspicious found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 0 days

## Security scan

- **Status:** warnings
- **Scanned:** 2026-09-30T23:01:28.100Z
- **Version scanned:** 1.1.0
- **CVEs:** none found by OSV at scan time

## Tools

40 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `sort-by` — Sort field
- `sort-order` — Sort order: asc|desc
- `ask` — Natural language search using a local AI (claude/copilot/gemini)
- `query` — Ask in plain language; the AI translates it to a Camunda API search
- `get-xml` — Get process definition XML and render as ASCII art
- `processDefinitionKey` — Process definition key
- `render` — Render process definition as ASCII art in the terminal
- `decisionDefinitionKey` — Decision definition key
- `decisionRequirementsKey` — Decision requirements key
- `get-start-form` — Get process start form and render as ASCII art
- `get-form` — Get user task form and render as ASCII art
- `userTaskKey` — User task key
- `completion` — Generate shell completion scripts
- `bash` — Generate bash completion script
- `zsh` — Generate zsh completion script
- `fish` — Generate fish completion script
- `workspace` — Project root to search for .camunda/element-templates (default: current directory)
- `config-folder` — Config folder name searched at each level (default: .camunda)
- `search` — Search the bundled Camunda 8 out-of-the-box connector catalog (Slack, HTTP, AWS, AI Agent, …)
- `list` — List every connector template — the bundled Camunda 8 catalog plus the project's own
- `show` — Show a connector template's required/optional input keys
- `templateId` — Template id, e.g. io.camunda.connectors.Slack.v1
- `validate` — Validate element templates against the Camunda schema — a .json file, or every template a project holds
- `path` — A template .json file, or a project directory (default: the current directory)
- `format` — Output format: text (default) or json
- `connector` — Connector element templates — generate from OpenAPI, browse the catalog, validate a project's own
- `generate` — Generate connector templates from a local OpenAPI spec or catalog entry
- `api` — Catalog API id (e.g. github, stripe). Use 'connector catalog' to list.
- `base-url` — Override the base URL from the spec
- `id-prefix` — Reverse-DNS id prefix (default: io.generated)
- `filter` — Regex filter on operationId/summary (case-insensitive)
- `expand-body` — Decompose top-level request body properties into individual fields
- `auth` — Default auth type: noAuth, apiKey, basic, bearer, oauth-client-credentials-flow
- `dry-run` — Print templates to stdout without writing files
- `catalog` — List available API catalog entries
- `deploy` — Deploy a BPMN (or DMN/form) file to local Reebe or the active Camunda 8 profile
- `file` — Path to the resource file
- `target` — Deployment target: "local" (Reebe, via ZEEBE_ADDRESS) or "camunda8" (active profile)
- `dev` — Local development loop — edit, simulate, lint and test every process in a folder in the browser
- `dir` — Project directory (default: current directory)

## Install

**Verdict: install** — No blocking findings and no open coverage gaps — safe to install as configured.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"cli\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"@bpmnkit/cli\"\n      ],\n      \"env\": {\n        \"ZEEBE_CLIENT_SECRET\": \"<YOUR_ZEEBE_CLIENT_SECRET>\"\n      }\n    }\n  }\n}"
```
**Credentials it will ask for** (names only — Forge never holds a value):
- `ZEEBE_CLIENT_SECRET` — Zeebe Client Secret (optional)
Placeholders only. Forge never holds, brokers, or transmits a credential value — replace each <YOUR_NAME> in your own config file. Do not send a value back to Forge; no Forge endpoint accepts one.
- This entry needs 1 credential (0 required). The generated config carries placeholders, so it will fail in the editor rather than at runtime if they are left unset.

## Blast radius

Moderate blast radius — holds an oauth grant; runs on your machine.
- Floor 28, ceiling 28 (tier: moderate)
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/%40bpmnkit%2Fcli
- Install plan: https://forgeregistry.com/api/v1/packages/%40bpmnkit%2Fcli/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/%40bpmnkit%2Fcli
- HTML page: https://forgeregistry.com/registry/%40bpmnkit%2Fcli
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
