onecli run wraps a coding agent process with OneCLI gateway access. Your agent’s HTTPS traffic routes through the gateway, which injects stored credentials automatically. The agent never sees raw API keys or OAuth tokens.
Supported agents
Any command works after
--. The agents listed above also get an auto-installed skill file that teaches them how to use the gateway.
Setup
1
Start OneCLI
2
Install the CLI
3
Launch your agent
onecli: gateway connected. Starting claude... and your agent starts with the gateway configured.What onecli run does
When you run onecli run -- claude, the CLI:
- Fetches gateway configuration from the OneCLI server
- Writes the gateway CA certificate to
~/.onecli/gateway-ca.pem - Fetches your configured secrets and generates a dynamic skill file at
~/.claude/skills/onecli-gateway/SKILL.mdlisting your actual services - Injects
HTTPS_PROXY, CA trust variables,ONECLI_AGENT_NAME, andONECLI_URLinto the child process - Hands over terminal control to the agent
How agents connect to services
The skill file teaches supported agents a simple workflow:-
Make the request directly. The agent calls the real API URL (e.g.
https://gmail.googleapis.com/...). No auth headers needed. If credentials are configured, the gateway injects them and the request succeeds. -
If it fails, help the user connect. The gateway returns a structured error with a
connect_url. The agent appends&source=agent&agent_name=(from$ONECLI_AGENT_NAME) and presents the link to the user. - Poll and retry. The agent polls the connection status and retries automatically once the user connects the service. No manual “try now” needed.
onecli secrets create.
Flags
Dry run
Use--dry-run to inspect what onecli run would do without side effects:
Compared to the SDK path
onecli run is for coding agents running directly on your machine. If your agents run in Docker containers (e.g. via NanoClaw), use the Node.js SDK instead. Both paths use the same gateway, the same secrets, and the same policy rules.