Metadata-Version: 2.5
Name: radmah-cli
Version: 1.4.0
Summary: Command-line interface for RadMah AI — synthetic data, simulation, and Agentic Data Scientist
Project-URL: Documentation, https://docs.radmah.ai/cli/installation
Project-URL: Homepage, https://radmah.ai
Project-URL: Issues, https://radmah.ai/contact
Author-email: ITLOX <sales@radmah.ai>
License-Expression: LicenseRef-Proprietary
License-File: LICENSE
Keywords: cli,ics,radmah,scada,synthetic-data
Classifier: Development Status :: 3 - Alpha
Classifier: Intended Audience :: Developers
Classifier: Operating System :: OS Independent
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3 :: Only
Classifier: Programming Language :: Python :: 3.10
Classifier: Programming Language :: Python :: 3.11
Classifier: Programming Language :: Python :: 3.12
Classifier: Programming Language :: Python :: 3.13
Classifier: Topic :: Software Development :: Libraries :: Python Modules
Requires-Python: >=3.10
Requires-Dist: keyring>=24.0
Requires-Dist: prompt-toolkit>=3.0
Requires-Dist: radmah-sdk~=1.4.0
Requires-Dist: rich>=13.7
Requires-Dist: typer>=0.12
Description-Content-Type: text/markdown

# radmah-cli

The `rady` command-line interface for the RadMah AI platform.
(``radmah`` is registered as an alias for operators who prefer the
full brand — both resolve to the same binary.)

Requires Python 3.10 or newer. Versions in lockstep with `radmah-sdk`
(`rady --version` reports the installed version).

## What it does

```bash
rady auth login                                    # persistent OS-keyring credential
rady fabricate preview "200 account records"       # create a reviewed draft
rady fabricate approve <preview-id>                 # generate after approval
rady chat                                          # interactive AI assistant REPL
rady jobs list                                     # see your recent platform jobs
rady jobs wait <id>                                # block on a running job
rady jobs evidence <id>                            # sealed evidence bundle summary
rady fhir synth --seed 7 -o bundle.json            # FHIR R4 bundle (metered job)
rady contract hash --file contract.json            # canonical Contract-K hash
rady plan list                                     # ADS campaign templates
rady plan campaign <id>                            # a campaign's draft plan
rady ics mitre-coverage                            # ATT&CK for ICS depth by status
```

`rady --help` lists every command group. Every listed command calls the
public API through the SDK.

`rady fhir synth`, `rady contract hash`, `rady plan` and `rady ics
mitre-coverage` were restored in 1.4.0 (they need `radmah-sdk` 1.4.0). They
now use the CLI-wide exit codes, which differ from the in-process versions
removed in 1.3.0: an unknown campaign id exits 4 (was 1), a contract the API
rejects exits 2 (was 3), a failed FHIR job exits 1 (was 4). `rady ics
mitre-coverage --json` prints the API's view grouped by status
(`by_status`, `technique_ids_by_status`), a different schema from the
in-process report; the static-catalogue, benchmark-export and label-only
sample figures are not served by the API. These commands have no public
API route yet, so they print a "moved" notice and exit 2: `arrow`,
`benchmark`, `cctp`, `hash`, `lift`, `sandbox`, `fhir observation`, `mitre
coverage` and `scada verify-causal`.

## Architecture

- **One package**, same commands across Free, Sovereign, and
  Enterprise tiers — the only difference is the `--base-url` (or
  `RADMAH_API_URL`) the user points it at. Free + Sovereign default
  to `https://api.radmah.ai`; Enterprise customers point it at
  their own deployment's API URL (e.g. `https://radmah.example.com`).
  An `https://` deployment on your private network (an RFC 1918 address
  or a name under `.internal`) needs an explicit opt-in:
  `rady --allow-private-base-url <command>` (the flag goes before the
  command) or `export RADMAH_ALLOW_PRIVATE_BASE_URL=1`, the same setting
  the SDK reads; export `RADMAH_CA_BUNDLE` when its certificate comes from
  your own CA. `http://localhost` (this machine) needs neither. An
  `http://` URL to any other host is refused, because the key would cross
  the network unencrypted, unless you opt in by name for that command with
  `rady --allow-insecure-http <command>` (the flag also accepts that typed
  URL as a private-network endpoint) or for every command with
  `export RADMAH_ALLOW_INSECURE_HTTP=1` (the same setting the SDK reads; it
  lifts only the cleartext refusal, so a private `http://` endpoint also
  needs `RADMAH_ALLOW_PRIVATE_BASE_URL=1`); even then `rady` prints a one-line warning on stderr. Use the
  deployment's `https://` URL instead.
  `RADMAH_ALLOW_PRIVATE_BASE_URL=0` refuses private endpoints outright.
  Every command, `rady ics techniques` and `rady jobs error` included,
  goes through the SDK's transport and these rules. Cloud metadata
  endpoints are always refused, and a server's region redirect never
  carries the key from a public host, or from an `http://` endpoint, to a
  host on your network.
- **Credentials** are stored in the OS-native credential store (macOS
  Keychain, Windows Credential Manager, Linux Secret Service) via the
  [`keyring`](https://pypi.org/project/keyring/) library. No plaintext
  API keys on disk.
- **All engine execution happens server-side** — the CLI is a thin
  wrapper around the SDK which is a thin wrapper around the REST API.
  No engine code ever reaches the user's machine through this package,
  and every command works from this package alone.
- **Rich output everywhere** — progress spinners, colored outcome
  markers, tables, hints. The CLI is chatty by design.

## Install

```bash
python3 -m pip install radmah-cli
rady --version
```

The install pulls `radmah-sdk` as a dependency. `rady` (and its
`radmah` alias) appear on `$PATH` via the `[project.scripts]` entry
in `pyproject.toml`.

## Licence

Proprietary (`LicenseRef-Proprietary`); see the `LICENSE` file shipped with
the package. You may read the source and use the unmodified package to access
the RadMah AI platform under your account agreement; you may not copy, modify,
redistribute or reuse it.
