Metadata-Version: 2.4
Name: veilfile
Version: 0.3.0
Summary: Command-line client for Veilfile — private, ephemeral artifact hosting for AI agents
Author: Veilfile
License-Expression: MIT
Project-URL: Homepage, https://veilfile.com
Project-URL: Documentation, https://veilfile.com/docs/api/
Project-URL: Repository, https://github.com/yourimaginationwillbefired/veilfile
Keywords: veilfile,artifacts,mcp,cli
Classifier: Development Status :: 4 - Beta
Classifier: Environment :: Console
Classifier: Intended Audience :: Developers
Classifier: Operating System :: OS Independent
Classifier: Programming Language :: Python :: 3
Classifier: Topic :: Utilities
Requires-Python: >=3.9
Description-Content-Type: text/markdown

# veilfile CLI

Command-line client for [Veilfile](https://veilfile.com). Single file, standard
library only — no dependencies to audit.

## Install

```sh
pip install veilfile
```

Or run the script directly with any Python 3.9+:

```sh
python3 veilfile.py login
```

## Usage

```sh
veilfile login    # browser approval flow; stores the API key locally
veilfile logout   # revoke the key on the server; delete the local copy
veilfile status   # confirm the stored key is valid (never prints it)
veilfile push FILE [--ttl-days N]  # upload a file; print its share URL
veilfile pull URL [--out PATH]     # download an artifact
```

`veilfile login` prints a code and opens the verification page in your browser.
Approve it there and the terminal picks up the API key — you never paste a
secret. `veilfile login --print-key` prints the raw key too, for the rare case
you explicitly need it (it is never printed otherwise).

The key is stored in a `0600` credentials file (`~/.config/veilfile` on
macOS/Linux, `%APPDATA%\veilfile` on Windows). Setting `VEILFILE_API_KEY`
overrides the file, matching the MCP setup docs. `--base-url` (or
`VEILFILE_BASE_URL`) points the CLI at a local dev server.

## Distribution notes

- **pip (recommended):** `pip install veilfile` pulls a versioned package over
  TLS from PyPI. Zero dependencies, so the supply chain is one package.
- **Direct download:** fetch `veilfile.py` from the repo, read it, run it.
  Reasonable for the cautious; you get to inspect every line first.
- **curl-to-shell: not recommended.** Piping remote code straight into a shell
  skips integrity verification entirely. For a security-conscious buyer that
  is the wrong default, so we do not publish a one-liner.

## Publishing a new release (founder only)

The founder owns the PyPI account and runs the upload from his own machine —
PyPI tokens cannot live in the Secure Vault, so this step is never automated.

```sh
cd cli
python3 -m build            # builds sdist + wheel into dist/
twine check dist/*          # metadata sanity check
twine upload dist/*         # username: __token__, password: <PyPI API token>
```

Rules: bump `version` in both `pyproject.toml` and `__version__` in
`veilfile.py` before building; never upload a version number that already
exists on PyPI (0.1.0 was the placeholder, 0.2.0 the auth-only release,
0.3.0 adds push/pull); verify
`twine check` is clean before uploading.

## Development

```sh
cd cli
python3 -m unittest discover -s tests -t .
```
