refinery on your PATH, authenticated to the right workspace, and the habit of reading refinery info before assuming anything.
0.1 · Install
On TextQL cloud:Prompt
refinery on your PATH. Full instructions (including a section written for coding agents): docs.textql.com/core/admin/cli.
The CLI always matches its deployment —
refinery self-updates from the deployment it points at — it can never be newer than your server, and it changes version only when your deployment upgrades. refinery update --check reports without changing anything.0.2 · Authenticate
Prompt
You’ll see: a device-flow URL + code (approve in the browser), or use
refinery auth login --api-key KEY with a workspace API key for headless setups. Then check who you are: refinery auth status.0.3 · Orient with refinery info — always first
Prompt
You’ll see: the deployment you’re pointed at, your identity and roles, the grant’s scopes, which execution tools the org allows (python/bash/sql), and your existing sandboxes. Check it before assuming a capability exists — a tool that exits 4 is disabled for the org, not broken.
refinery auth upgrade when the hint says insufficient_scope) · 4 tool unavailable. Every command prints exactly one JSON document on stdout — pipe it, parse it, script it. Use --pretty only for human eyes.
✅ Checkpoint
-
refinery infoshows the workspace you intended, and you can name your enabled tools - You know what exit codes 3 and 4 mean and which one
auth upgradecan fix