Skip to content

Operations ​

Run make for the complete command list. Commands that call a provider consume real usage; account, quota, and log output can contain private identifiers.

Start, stop, and inspect ​

bash
make up
make status
make logs proxy
make logs tailscale
make logs quota
make down

make up also applies template changes. make status checks the containers, loopback endpoint, LAN endpoint, tailnet, panel, client key, and provider accounts. Follow its suggested fix for a failing link. make down keeps provider credentials and the Tailscale identity.

Accounts, quota, and model availability ​

bash
make ops accounts
make ops models
make ops quota
make ops logs LINES=500

make ops quota reports usage windows, reset times, and weekly capacity expiring unused within 24 hours. The quota container applies this information to account priorities automatically. To stop automatic priority updates, use the same state directory as startup:

bash
LOCAL_DIR="$HOME/.cli-proxy-api" docker compose -f local/compose.yaml stop quota

To resume, run make up. Stopping quota does not disable proxy routing; it leaves the last priorities in place, so adjust them in the panel if necessary.

Check a request and its transport ​

bash
make ops smoke
make ops ws-smoke IDLE=2m
make codex smoke

The WebSocket smoke command checks handshakes, ping/pong, optional idle time, closing, and rejection without a client key. It requires no connected provider. make codex smoke performs a real Codex turn and rejects an HTTP fallback.

Measure first-token latency ​

bash
make ops bench N=5
make ops bench N=3 CODEX_MODEL=

The benchmark sends real requests, roughly 5,000 prompt tokens per request. The first in a series is cold; later requests should reuse the prompt cache. Set MODEL and CODEX_MODEL to available models. An empty CODEX_MODEL skips that API. Treat measured results as local observations that depend on your accounts and network.

Rotate keys ​

Change the appropriate field in 1Password, then refresh the Keychain cache and restart with the new template values:

bash
make ops keys
make up

Update any clients with a manually stored key. Command-based clients read the cache, but a running client may retain an earlier value until its auth refresh or restart. If switching vaults or items, export the new names before refreshing.

Back up private state ​

make claude backup and make codex backup save private client settings outside the repository, under ~/.cli-proxy-api/backups/ by default. The files are owner-only and may contain credentials, workspace names, or instructions. Do not commit or share them.

These commands do not back up proxy OAuth credentials or Tailscale state. For disaster recovery, back up your runtime state directory separately into encrypted private storage. Stop the stack before taking a consistent copy. A backup contains secrets even when every tracked file is safe.

Rebuild the panel ​

Install Bun, then run make code panel. The script clones the tagged upstream Management Center, applies panel/ledger.patch, and rebuilds panel/management.html. Review the generated file and run make up to use it. When upgrading the panel tag, the patch may need to be rebased on that version.

hara · built on CLIProxyAPI