helixordevelopers

CLI

helixor-pack inspects your license, compiles playbooks into packs, downloads catalog packs, and runs or serves a pack. helixor is the same program under a second name.

Runtime 0.2.1
helixor-pack <command> [options]
helixor-pack --help
helixor-pack <command> --help

Both commands are installed with the runtime. See Installation.

Commands#

CommandDoesNetwork
inspect-licenseVerify and print a license file.none
compileCompile a playbook into a sealed .hxpack.none, or the authority with --remote
catalogList the pre-built packs.authority
download-packDownload a catalog pack sealed for your license.authority
runUnseal a pack and evaluate one text.none
serveUnseal a pack and start the HTTP, SSE and WebSocket service.listens only

"Authority" is the Helixor licensing and compiler service at the URL in Environment.

License resolution#

Every command finds the license the same way. For inspect-license, the optional positional argument takes the place of --license.

  1. --license <path>, if given. If that file does not exist, the command exits 1 without trying the others.
  2. $HELIXOR_LICENSE_FILE.
  3. ./helixor.lic in the working directory.
  4. ~/.helixor/helixor.lic.

If nothing is found, it prints Error: No license file provided and default '…' not found. and exits 1. catalog and download-pack need a license too.

inspect-license#

helixor-pack inspect-license [LICENSE_FILE]

Verifies the signature and validity window, then prints a report. The report shows the license ID, organization, contact, tier and plan, status (ACTIVE (N days remaining) or IN GRACE PERIOD), expiry, grace period, licensed packs and solvers, and features. It does not print the content key. A tampered, not-yet-valid or expired file exits 1 with the reason. See License file.

compile#

helixor-pack compile --playbook PLAYBOOK --out OUT [--license LICENSE] [--remote] [--url URL]
FlagRequiredMeaning
--playbookyesPath to the YAML playbook.
--outyesPath of the .hxpack to write. Parent directories are created.
--licensenoLicense file; see License resolution.
--remotenoCompile on the authority instead of locally.
--urlnoAuthority URL override for --remote.

A local compile validates the playbook, rejects declarations a compiled pack would not execute (UnsupportedPackDeclarationError, listing each problem), checks that your license allows the pack_id and any solvers, and encrypts with your license's content key. See Playbook schema for the checks and for what the pack will execute.

Compiling playbook 'internal_code_guard.yaml' locally...
Successfully compiled sealed binary pack (654 bytes): internal_code_guard.hxpack

What --remote sends

--remote posts your playbook and your full license JSON, including its content key, to <authority>/api/v1/pack/compile. Use it only with the Helixor authority over HTTPS.

catalog#

helixor-pack catalog [--license LICENSE] [--url URL]

Lists the pre-built packs on the authority. For each one it shows the pack ID, version, name, kind, description and invariants, and whether your license is entitled to it (✓ Entitled or ✗ Upgrade Required). Your license JSON is sent in a request header, so use only the HTTPS authority URL.

download-pack#

helixor-pack download-pack --pack-id PACK_ID [--license LICENSE] [--out OUT] [--url URL]
FlagRequiredMeaning
--pack-idyesA pack ID from catalog, for example compliance.regulatory_pii_guard.v1.
--outnoOutput path. Default <pack_id>.hxpack in the working directory.
--license, --urlnoAs above.

The authority seals the pack for your license. Re-download it after you renew; see Packs and manifest.

run#

helixor-pack run --pack PACK --text TEXT [--license LICENSE]

Unseals the pack in memory, evaluates TEXT once and prints the result as JSON. It makes no network calls.

helixor-pack run --pack internal_code_guard.hxpack --text "Release PROJ-ZEUS-9 today"
{
  "pack_id": "custom.internal_code_guard.v1",
  "action": "block_project_code",
  "invariants_passed": false,
  "reason": "Pack rule 'project_code' triggered (block)",
  "triggers": [
    {"rule_id": "project_code", "law": "compliance", "severity": "FATAL", "matched_items": ["PROJ-ZEUS-9"]}
  ],
  "remedy": {"clean_text": "[BLOCKED: Prohibited Content]", "redactions_count": 0, "redacted_categories": []},
  "…": "…",
  "license_status": "ACTIVE",
  "active_key_id": "ep1_2026",
  "active_epoch": 1,
  "edition": "DEVELOPER",
  "upgrade_notice": null
}

The output includes matched_items, so don't paste it into tickets or logs. edition, license_status, active_key_id and active_epoch come from the license the pack was unsealed with.

serve#

helixor-pack serve --pack PACK [--license LICENSE] [--host HOST] [--port PORT] [--token TOKEN]
FlagDefaultMeaning
--packrequiredThe .hxpack to serve.
--host127.0.0.1Bind address. Any non-loopback address requires a token; without one the command exits 1 with Server error: Refusing to bind '…' without authentication.
--port18734Bind port.
--token$HELIXOR_SERVICE_TOKENBearer token every endpoint except GET /v1/health requires. Prefer the environment variable, so the token does not appear in the process list.
--licensesee aboveLicense file.

Unseals the pack, prints Unsealed pack '<pack_id>' in RAM. Starting server on http://<host>:<port>, and serves the HTTP API in the foreground until stopped.

GET /v1/health reports the served pack_id and license tier; use it as the health check. The HTTP API page covers authentication, CORS and the remaining known issue.

Exit codes#

CodeMeaning
0Success.
1The command failed. One line goes to standard error, prefixed by the command: Error inspecting license file:, Compilation error:, Error querying catalog:, Download error:, Execution error: or Server error:. The rest of the line is the underlying error, for example a license signature or pack unseal failure.
2Usage error: an unknown command, a missing required flag or no command at all.

The messages behind code 1 are listed in Errors.

Environment#

VariableUsed byMeaning
HELIXOR_LICENSE_FILEallDefault license path.
HELIXOR_SERVICE_TOKENserveBearer token for the service when --token is not given.
HELIXOR_CORS_ORIGINSserveComma-separated browser origins allowed to call the service. Unset: none. A wildcard is rejected.
HELIXOR_AUTHORITY_URLcompile --remote, catalog, download-packAuthority base URL. --url overrides it.
HELIXOR_ENVIRONMENTsameWhen HELIXOR_AUTHORITY_URL is unset, prod or production selects https://license.helixor.dev; anything else selects https://license-dev.helixor.dev. The default is the development authority.

The CLI also loads a .env file at start-up. See Configuration.