CLI
Install and use the Kiket CLI for config validation, scans, evidence, and audit reports.
The Kiket CLI is a non-interactive, machine-readable client for the platform API. Use it in CI pipelines, local .kiket/ workflows, and one-off operational tasks.
Install
npm install -g @kiket/cli
# or
pnpm add -g @kiket/cliRequires Node.js 24+.
Configure
Set credentials once (shell profile, CI secret store, or .env):
| Variable | Purpose |
|---|---|
KIKET_API_KEY | Long-lived API key from Settings → API Keys |
KIKET_API_URL | API base (default https://api.kiket.dev) |
KIKET_ORGANIZATION_ID | Organization UUID for tenant-scoped commands |
You can override per invocation with global flags: --api-key, --api-url, --organization-id, --format json|text.
export KIKET_API_KEY="kik_..."
export KIKET_API_URL="https://api.kiket.dev"
export KIKET_ORGANIZATION_ID="org_..."Local .kiket/ workflow
These commands work on YAML in your repo without calling the API (unless noted):
kiket init # scaffold .kiket/ starter layout
kiket validate --file .kiket/workflows/privacy-request.yaml --local
kiket migrate-config --file .kiket/workflows/privacy-request.yaml --write
kiket simulate \
--original baseline.yaml \
--modified proposed.yaml \
--instances '[]'Drop --local on validate to run server-side validation against the live API.
Platform operations
Commands below require KIKET_API_KEY (or --api-key):
# Trigger a compliance scanner run
kiket scan \
--workspace-id "$WORKSPACE_ID" \
--process-id "$PROCESS_ID" \
--trigger manual
# List open findings
kiket findings list --status open --workspace-id "$WORKSPACE_ID"
# Import normalized evidence from a JSON fixture
kiket evidence import --file evidence-record.json
# Generate and verify an audit report snapshot
kiket report generate \
--report-key privacy-dsar-summary \
--title "Q2 DSAR summary" \
--workspace-id "$WORKSPACE_ID"
kiket report verify --id "$REPORT_ID"
# Optional: anchor proof create/verify for audit trails
kiket anchor create \
--subject-type audit_report \
--subject-id "$REPORT_ID" \
--subject-hash "$SHA256"
kiket anchor verify --id "$ANCHOR_ID"Extension authoring
For evidence adapter development:
kiket extension init --template webhook
kiket extension validate --file kiket-extension.yaml
kiket extension test --file fixtures/raw-event.json
kiket extension install --key my-adapter --display-name "My adapter" --version 0.1.0
kiket extension publish --visibility org --file kiket-extension.yamlSee Build your first evidence adapter for the full walkthrough.
Output
Default output is JSON on stdout; errors go to stderr with exit code 1. Use --format text for human-readable summaries in ad hoc shells.