Command Surface
Generated from cargo run -q -p ayx-rs -- catalog list --format full --scope all -o json on 2026-09-15 21:25:06 UTC.
This is the full, flattened catalog index — every visible node in the live clap command tree, one row per command, plus every registered capability. Command identity (name, path) and summary are derived live from the clap tree at generation time, so a command can never be silently missing here. Safety/Mutating reflect catalog metadata: commands with a curated metadata entry show that classification; every other command is honestly marked unclassified (blank Mutating) rather than borrowing a value that would misrepresent it — see ayx catalog list --scope curated for the fully annotated compatibility view.
For flags, positional arguments, aliases, payload schemas, and nested tree traversal, use ayx --help, ayx <group> --help, or ayx discover --deep.
This file is generated. Refresh it with:
cargo run -q -p xtask -- refresh-command-surfaceSummary
Section titled “Summary”- Commands: 364
- Capabilities: 6
Commands
Section titled “Commands”actions
Section titled “actions”| Name | Path | Safety | Mutating | Summary |
|---|---|---|---|---|
| actions | actions |
unclassified | Action registry — named playbooks with safety, validation, and rollback notes | |
| actions describe | actions/describe |
unclassified | Describe a single action: steps, validations, rollback, plus its effective input_schema (declared or inferred, tagged by input_schema_source) and declared output_schema, if any — the agent-facing source of truth for what this action requires/returns |
|
| actions export | actions/export |
unclassified | Print an action’s full YAML so an operator can fork it into their config home (${AYX_CONFIG_HOME}/registry/) to override the bundled stdlib version |
|
| actions list | actions/list |
unclassified | List every action, with title, safety classification, and tags. Compact index only — no input/output schema. Call describe on a candidate id for its full contract before constructing --params |
|
| actions resolve | actions/resolve |
unclassified | Resolve a free-text task description to a ranked list of candidate actions. Ranking/lookup only — no schema. Call describe on the chosen id for its full contract before constructing --params |
|
| actions run | actions/run |
unclassified | Execute an action. Without --apply, mutating/destructive actions emit a structured plan and never invoke a subprocess. Read-only actions always run |
|
| actions validate | actions/validate |
unclassified | Cross-check every step in every loaded action against the catalog. Emits warnings for unknown command paths, capability ids, and dangling workflow → action references. Read-only | |
| actions workflows | actions/workflows |
unclassified | Workflow registry — higher-order skills composing actions | |
| actions workflows explain | actions/workflows/explain |
unclassified | Explain a workflow: title, safety, ordered action ids with summaries, resolved/missing action detail, plus its effective input_schema (declared or inferred, tagged by input_schema_source) and declared output_schema, if any — the agent-facing source of truth for what this workflow requires/returns |
|
| actions workflows list | actions/workflows/list |
unclassified | List every workflow with its title, safety, and action count. Compact index only — no input/output schema. Call explain on a candidate id for its full contract before constructing --params |
|
| actions workflows run | actions/workflows/run |
unclassified | Execute a workflow as an ordered chain of actions. Honors the same --apply semantics as actions run |
| Name | Path | Safety | Mutating | Summary |
|---|---|---|---|---|
| audit | audit |
unclassified | Audit artifact management — list, sweep, retention. Audit files live under ${AYX_CONFIG_HOME}/audits/ by default. | |
| audit status | audit/status |
unclassified | Show the resolved audit directory and a quick file count / size summary | |
| audit sweep | audit/sweep |
unclassified | Delete audit artifacts older than --retain-days. Dry-run by default |
catalog
Section titled “catalog”| Name | Path | Safety | Mutating | Summary |
|---|---|---|---|---|
| catalog | catalog |
unclassified | Machine-readable command registry | |
| catalog describe | catalog/describe |
read-only | no | Describe a single command in the catalog. |
| catalog list | catalog/list |
read-only | no | List machine-readable command metadata. |
| catalog run | catalog/run |
unclassified | Run a registered capability with JSON input |
completions
Section titled “completions”| Name | Path | Safety | Mutating | Summary |
|---|---|---|---|---|
| completions | completions |
unclassified | Generate shell completion scripts (bash, zsh, fish, powershell, elvish) |
designer
Section titled “designer”| Name | Path | Safety | Mutating | Summary |
|---|---|---|---|---|
| designer | designer |
unclassified | Alteryx Designer / Server artifact tooling — .yxmd/.yxmc/.yxzp/.yxdb | |
| designer workflow | designer/workflow |
unclassified | Workflow package and XML tooling for .yxmd, .yxmc, .yxzp, and .yxdb | |
| designer workflow convert-cloud | designer/workflow/convert-cloud |
unclassified | Convert a desktop workflow into cloud JSON | |
| designer workflow inspect | designer/workflow/inspect |
read-only | no | Inspect Alteryx workflow, macro, package, or data artifacts. |
| designer workflow migrate | designer/workflow/migrate |
mutating | yes | Perform an end-to-end workflow XML migration pass. |
| designer workflow publish | designer/workflow/publish |
mutating | yes | Republish a workflow package through the Server API. |
| designer workflow recurse | designer/workflow/recurse |
mutating | yes | Recursively apply XML replacement rules across workflow artifacts. |
| designer workflow repackage | designer/workflow/repackage |
mutating | yes | Rebuild a .yxzp package from a directory tree. |
| designer workflow replace | designer/workflow/replace |
mutating | yes | Find and replace text in workflow XML or packages. |
| designer workflow scan | designer/workflow/scan |
read-only | no | Preflight scan workflow artifacts for rule matches without rewriting. |
| designer workflow unpack | designer/workflow/unpack |
read-only | no | Unpack a .yxzp workflow package. |
| designer workflow validate | designer/workflow/validate |
read-only | no | Validate workflow and macro XML structures. |
| designer workflow yxdb | designer/workflow/yxdb |
unclassified | Read and export .yxdb data; use –csv for export and top-level -o json for machine-readable envelopes |
discover
Section titled “discover”| Name | Path | Safety | Mutating | Summary |
|---|---|---|---|---|
| discover | discover |
read-only | no | Progressive live discovery of the CLI tree |
doctor
Section titled “doctor”| Name | Path | Safety | Mutating | Summary |
|---|---|---|---|---|
| doctor | doctor |
read-only-or-safe-local-fix | no | Run configuration, auth, network, and product health diagnostics |
| doctor all | doctor/all |
unclassified | Run every applicable diagnostic in sequence and return one merged envelope with per-check status/summary fields plus an overall rollup | |
| doctor auth | doctor/auth |
unclassified | Check One and Server credential posture | |
| doctor config | doctor/config |
read-only-or-safe-local-fix | no | Validate config home, active profile resolution, and inline secret posture. |
| doctor mongo | doctor/mongo |
unclassified | Check Mongo mode and managed connection posture | |
| doctor network | doctor/network |
unclassified | Check configured One and Server network targets | |
| doctor one | doctor/one |
unclassified | Check One auth and workspace probe posture | |
| doctor server | doctor/server |
unclassified | Check Server configuration posture and next-step guidance |
headless
Section titled “headless”| Name | Path | Safety | Mutating | Summary |
|---|---|---|---|---|
| headless | headless |
unclassified | Local product MCP server diagnostics | |
| headless doctor | headless/doctor |
unclassified | Check the local product MCP server, protocol handshake, and tool inventory |
license
Section titled “license”| Name | Path | Safety | Mutating | Summary |
|---|---|---|---|---|
| license | license |
unclassified | Licensing portal branch and API surface | |
| license api | license/api |
unclassified | Licensing portal API status and diagnostics | |
| license api diagnose | license/api/diagnose |
read-only | no | Validate Licensing API reachability and auth posture. |
| license api status | license/api/status |
read-only | no | Summarize the Licensing portal API posture. |
| license inventory | license/inventory |
read-only | no | Summarize Licensing branch inventory candidates. |
| license status | license/status |
read-only | no | Summarize the Licensing branch posture. |
| Name | Path | Safety | Mutating | Summary |
|---|---|---|---|---|
| mcp | mcp |
unclassified | Product-owned Model Context Protocol tools | |
| mcp call | mcp/call |
unclassified | Invoke one product MCP tool. Execution is dry-run unless –apply is set | |
| mcp gateway | mcp/gateway |
unclassified | Use an authenticated Streamable HTTP MCP Gateway endpoint | |
| mcp gateway abilities | mcp/gateway/abilities |
unclassified | Show negotiated protocol abilities and workflow/dataset tool families | |
| mcp gateway call | mcp/gateway/call |
unclassified | Invoke one Gateway MCP tool. Execution is dry-run unless –apply is set | |
| mcp gateway tools | mcp/gateway/tools |
unclassified | Discover the Gateway’s published MCP tools | |
| mcp gateway tools describe | mcp/gateway/tools/describe |
unclassified | Show one published Gateway tool schema | |
| mcp gateway tools list | mcp/gateway/tools/list |
unclassified | List all tools published by the Gateway | |
| mcp tools | mcp/tools |
unclassified | Discover the published product MCP tool contract | |
| mcp tools describe | mcp/tools/describe |
unclassified | Show one published product MCP tool schema | |
| mcp tools list | mcp/tools/list |
unclassified | List all published product MCP tools |
| Name | Path | Safety | Mutating | Summary |
|---|---|---|---|---|
| mongo | mongo |
unclassified | Mongo inventory, backup, restore, query, and doctor helpers | |
| mongo backup | mongo/backup |
mutating | yes | Back up the Gallery and Service Mongo databases. |
| mongo doctor | mongo/doctor |
read-only | no | Run the default support query suite across critical Mongo collections. |
| mongo inventory | mongo/inventory |
read-only | no | Generate an inventory plan for the Mongo-backed databases. |
| mongo mutate | mongo/mutate |
destructive | yes | Apply a guarded, template-based Mongo mutation with mandatory preview approval. |
| mongo query | mongo/query |
read-only | no | Run a read-only Mongo query against a Server collection. |
| mongo restore | mongo/restore |
mutating | yes | Restore Mongo data from a backup input path. |
| mongo status | mongo/status |
read-only | no | Resolve the configured Mongo connection and database names. |
| mongo undo | mongo/undo |
destructive | yes | Reverse a prior guarded Mongo mutation from its execution audit artifact. |
onboard
Section titled “onboard”| Name | Path | Safety | Mutating | Summary |
|---|---|---|---|---|
| onboard | onboard |
unclassified | Interactive first-run setup for config.yaml or environments.yaml with validation and secret reuse |
| Name | Path | Safety | Mutating | Summary |
|---|---|---|---|---|
| one | one |
unclassified | Alteryx One command surface | |
| one api | one/api |
unclassified | Alteryx One API introspection (spec + coverage) | |
| one api coverage | one/api/coverage |
read-only | no | Diff the live One OpenAPI spec against wired commands (covered / missing / stale) |
| one api diagnose | one/api/diagnose |
read-only | no | Validate Alteryx One API reachability and auth posture |
| one api open-api-spec | one/api/open-api-spec |
read-only | no | Fetch the Alteryx One OpenAPI specification |
| one api status | one/api/status |
read-only | no | Summarize the Alteryx One API posture |
| one auth | one/auth |
unclassified | Summarize One API token posture for managed IAM | |
| one auth diagnose | one/auth/diagnose |
read-only | no | Validate One API token reachability and workspace scope |
| one auth protocol | one/auth/protocol |
unclassified | Validate a versioned, secret-free agent authentication request | |
| one auth status | one/auth/status |
read-only | no | Summarize One API token posture for managed IAM |
| one connections | one/connections |
unclassified | Alteryx One connections — list, create, and manage credentials | |
| one connections connector-metadata | one/connections/connector-metadata |
unclassified | Inspect connector metadata — defaults, detail, publish info, and overrides | |
| one connections connector-metadata defaults | one/connections/connector-metadata/defaults |
read-only | no | Inspect connector defaults |
| one connections connector-metadata detail | one/connections/connector-metadata/detail |
read-only | no | Inspect current connector metadata |
| one connections connector-metadata overrides | one/connections/connector-metadata/overrides |
unclassified | Manage connector metadata overrides | |
| one connections connector-metadata overrides create | one/connections/connector-metadata/overrides/create |
mutating | yes | Create connector metadata overrides from JSON payload |
| one connections connector-metadata overrides delete | one/connections/connector-metadata/overrides/delete |
mutating | yes | Delete connector metadata overrides |
| one connections connector-metadata overrides list | one/connections/connector-metadata/overrides/list |
read-only | no | Inspect connector metadata overrides |
| one connections connector-metadata publish-info | one/connections/connector-metadata/publish-info |
read-only | no | Inspect connector publish information |
| one connections connector-metadata template | one/connections/connector-metadata/template |
unclassified | Fetch connector metadata defaults and emit a fillable JSON template for use with connections create --body <file> |
|
| one connections count | one/connections/count |
read-only | no | Count One connections |
| one connections create | one/connections/create |
mutating | yes | Create a One connection from JSON payload |
| one connections delete | one/connections/delete |
mutating | yes | Delete a One connection |
| one connections detail | one/connections/detail |
read-only | no | Inspect a One connection |
| one connections dry-run | one/connections/dry-run |
read-only | no | Dry-run creation of a One connection |
| one connections list | one/connections/list |
read-only | no | List One connections |
| one connections permissions | one/connections/permissions |
unclassified | Manage permissions for a One connection | |
| one connections permissions create | one/connections/permissions/create |
mutating | yes | Share a One connection with people or groups |
| one connections permissions delete | one/connections/permissions/delete |
mutating | yes | Revoke a subject’s access to a One connection |
| one connections permissions detail | one/connections/permissions/detail |
read-only | no | Inspect one subject’s access to a One connection |
| one connections permissions list | one/connections/permissions/list |
read-only | no | List the people and groups a One connection is shared with |
| one connections status | one/connections/status |
read-only | no | Inspect connection status |
| one connections update | one/connections/update |
mutating | yes | Update a One connection from JSON payload |
| one datasets | one/datasets |
unclassified | Create and read datasets from the Alteryx One dataset APIs | |
| one datasets count | one/datasets/count |
read-only | no | Count datasets in the user-facing One dataset library |
| one datasets create | one/datasets/create |
unclassified | Create an imported dataset reference from a JSON payload | |
| one datasets imported | one/datasets/imported |
unclassified | Read imported-dataset resources | |
| one datasets imported detail | one/datasets/imported/detail |
read-only | no | Inspect an imported dataset by id |
| one datasets list | one/datasets/list |
read-only | no | List datasets in the user-facing One dataset library |
| one datasets wrangled | one/datasets/wrangled |
unclassified | Read wrangled-dataset resources | |
| one datasets wrangled count | one/datasets/wrangled/count |
read-only | no | Count wrangled datasets |
| one datasets wrangled detail | one/datasets/wrangled/detail |
read-only | no | Inspect a wrangled dataset by id |
| one datasets wrangled list | one/datasets/wrangled/list |
read-only | no | List wrangled datasets |
| one doctor | one/doctor |
unclassified | Alteryx One configuration, auth, and product health diagnostics | |
| one doctor auth | one/doctor/auth |
read-only | no | Run the One auth doctor workflow |
| one doctor discover | one/doctor/discover |
read-only | no | Run the One discovery doctor workflow |
| one doctor identity | one/doctor/identity |
read-only | no | Run the One identity doctor workflow |
| one doctor plans | one/doctor/plans |
read-only | no | Run the One plans doctor workflow |
| one doctor scheduling | one/doctor/scheduling |
read-only | no | Run the One scheduling doctor workflow |
| one inventory | one/inventory |
read-only | no | Summarize the current One API surface registry |
| one jobs | one/jobs |
read-only | no | Alteryx One Job Library — inspect jobs, their runs, and results |
| one jobs cancel | one/jobs/cancel |
mutating | yes | Cancel a Job Library entry |
| one jobs count | one/jobs/count |
read-only | no | Count Job Library entries |
| one jobs execute | one/jobs/execute |
mutating | yes | Submit a Job Group from a JSON request body |
| one jobs inputs | one/jobs/inputs |
read-only | no | List aggregate job inputs |
| one jobs list | one/jobs/list |
read-only | no | List Job Library entries |
| one jobs outputs | one/jobs/outputs |
read-only | no | List aggregate job outputs |
| one jobs pdf-results | one/jobs/pdf-results |
read-only | no | Inspect aggregate job PDF results |
| one jobs profile | one/jobs/profile |
read-only | no | Inspect aggregate job profiling metadata |
| one jobs profile-results | one/jobs/profile-results |
read-only | no | Inspect aggregate job profiling results |
| one jobs publications | one/jobs/publications |
read-only | no | List publications for an aggregate job |
| one jobs publish | one/jobs/publish |
mutating | yes | Publish job results to a target |
| one jobs runs | one/jobs/runs |
read-only | no | List every child run record for an Alteryx One Job Group execution |
| one jobs status | one/jobs/status |
read-only | no | Inspect aggregate job status |
| one login | one/login |
mutating | yes | Authenticate with Alteryx One and store credentials |
| one logout | one/logout |
mutating | yes | Clear stored Alteryx One credentials from the active profile |
| one open | one/open |
read-only | no | Open a One resource in the web console. Launches a browser only on a terminal, without –no-input or –print, and when no agent host is detected; otherwise prints the URL |
| one output-objects | one/output-objects |
unclassified | Alteryx One output objects — list, create, and manage | |
| one output-objects count | one/output-objects/count |
read-only | no | Count One output objects |
| one output-objects create | one/output-objects/create |
mutating | yes | Create a One output object from JSON payload |
| one output-objects delete | one/output-objects/delete |
mutating | yes | Delete a One output object |
| one output-objects detail | one/output-objects/detail |
read-only | no | Inspect a One output object |
| one output-objects inputs | one/output-objects/inputs |
read-only | no | List inputs for a One output object |
| one output-objects list | one/output-objects/list |
read-only | no | List One output objects |
| one output-objects update | one/output-objects/update |
mutating | yes | Update a One output object from JSON payload |
| one output-objects wrangle-to-python | one/output-objects/wrangle-to-python |
mutating | yes | Generate Python from a One output object |
| one person | one/person |
unclassified | Alteryx One person (user) management | |
| one person create | one/person/create |
mutating | yes | Create a One person from JSON payload |
| one person current | one/person/current |
read-only | no | Inspect the current One person record |
| one person delete | one/person/delete |
mutating | yes | Delete a One person record |
| one person detail | one/person/detail |
read-only | no | Inspect a One person record by id |
| one person list | one/person/list |
read-only | no | List One people |
| one person password-reset-request | one/person/password-reset-request |
mutating | yes | Request a One password reset from JSON payload |
| one person patch | one/person/patch |
mutating | yes | Patch a One person record from JSON payload |
| one person update | one/person/update |
mutating | yes | Replace a One person record from JSON payload |
| one person update-password | one/person/update-password |
mutating | yes | Update the current One person’s password from JSON payload |
| one plans | one/plans |
unclassified | Alteryx One plans — list, run, share, and manage | |
| one plans count | one/plans/count |
read-only | no | Count One plans |
| one plans create | one/plans/create |
mutating | yes | Create a One plan |
| one plans delete | one/plans/delete |
mutating | yes | Delete a One plan |
| one plans detail | one/plans/detail |
read-only | no | Inspect a One plan |
| one plans export | one/plans/export |
read-only | no | Fetch a One plan package |
| one plans full | one/plans/full |
read-only | no | Inspect a One plan with the full documented payload |
| one plans import | one/plans/import |
read-only | no | Import a One plan package (provider contract pending) |
| one plans list | one/plans/list |
read-only | no | List One plans |
| one plans permissions | one/plans/permissions |
mutating | yes | List plan permissions, or delete one when --subject-id is provided |
| one plans run | one/plans/run |
mutating | yes | Run a One plan |
| one plans run-parameters | one/plans/run-parameters |
read-only | no | Inspect run parameters for a One plan |
| one plans schedules | one/plans/schedules |
read-only | no | List schedules for a One plan |
| one plans share | one/plans/share |
mutating | yes | Share a One plan from JSON payload |
| one plans update | one/plans/update |
mutating | yes | Update a One plan from JSON payload |
| one role | one/role |
unclassified | Alteryx One managed-IAM role assignments | |
| one role assign | one/role/assign |
mutating | yes | Assign a subject to a One managed IAM role |
| one role detail | one/role/detail |
read-only | no | Inspect a managed IAM role |
| one role list | one/role/list |
read-only | no | List managed IAM roles |
| one role list-assignments | one/role/list-assignments |
read-only | no | Inspect role assignments for One managed IAM |
| one role unassign | one/role/unassign |
mutating | yes | Unassign a subject from a One managed IAM role |
| one scheduling | one/scheduling |
unclassified | Alteryx One schedules — create, inspect, and manage | |
| one scheduling count | one/scheduling/count |
read-only | no | Count One schedules |
| one scheduling create | one/scheduling/create |
mutating | yes | Create a One schedule from a JSON payload |
| one scheduling delete | one/scheduling/delete |
destructive | yes | Delete a One schedule |
| one scheduling detail | one/scheduling/detail |
read-only | no | Inspect a One schedule by id |
| one scheduling disable | one/scheduling/disable |
mutating | yes | Disable a One schedule |
| one scheduling enable | one/scheduling/enable |
mutating | yes | Enable a One schedule |
| one scheduling list | one/scheduling/list |
read-only | no | List One schedules |
| one scheduling update | one/scheduling/update |
mutating | yes | Update a One schedule from a JSON payload |
| one token | one/token |
unclassified | Alteryx One API access token management | |
| one token create | one/token/create |
mutating | yes | Create a One API access token from JSON payload |
| one token delete | one/token/delete |
mutating | yes | Delete a One API access token by id |
| one token detail | one/token/detail |
read-only | no | Inspect a One API access token by id |
| one token list | one/token/list |
read-only | no | List One API access tokens |
| one webhook-flow-tasks | one/webhook-flow-tasks |
unclassified | Alteryx One webhook flow tasks — create, inspect, and test | |
| one webhook-flow-tasks create | one/webhook-flow-tasks/create |
mutating | yes | Create a webhook flow task from JSON payload |
| one webhook-flow-tasks delete | one/webhook-flow-tasks/delete |
mutating | yes | Delete a webhook flow task |
| one webhook-flow-tasks detail | one/webhook-flow-tasks/detail |
read-only | no | Inspect a webhook flow task |
| one webhook-flow-tasks test | one/webhook-flow-tasks/test |
mutating | yes | Send a test webhook from JSON payload |
| one whoami | one/whoami |
read-only | no | Show the current One user profile |
| one workflows | one/workflows |
read-only | no | Alteryx One cloud-native workflows — inspect, run, cancel, copy, share, and delete |
| one workflows assets | one/workflows/assets |
read-only | no | List workflow assets with the richer svc-workflow projection |
| one workflows cancel | one/workflows/cancel |
mutating | yes | Cancel a queued or running cloud-native workflow run |
| one workflows copy | one/workflows/copy |
mutating | yes | Duplicate a cloud-native workflow |
| one workflows count | one/workflows/count |
read-only | no | Count cloud-native workflows in the workspace |
| one workflows delete | one/workflows/delete |
mutating | yes | Delete a cloud-native workflow. Irreversible — no known restore/trash endpoint exists |
| one workflows dependencies | one/workflows/dependencies |
read-only | no | List the connections, datasets, and macros a workflow depends on |
| one workflows detail | one/workflows/detail |
read-only | no | Inspect one cloud-native workflow |
| one workflows engines | one/workflows/engines |
read-only | no | Show which execution engines a workflow can run on |
| one workflows graph | one/workflows/graph |
read-only | no | Inspect the workflow graph when the asset response provides it. Raw provider data is retained under the normal response field |
| one workflows list | one/workflows/list |
read-only | no | List Alteryx One cloud-native workflows |
| one workflows run | one/workflows/run |
mutating | yes | Queue a cloud-native workflow run |
| one workflows share | one/workflows/share |
mutating | yes | Share a cloud-native workflow with people or groups |
| one workflows tools | one/workflows/tools |
read-only | no | List the tools available to cloud-native workflows |
| one workflows upload | one/workflows/upload |
unclassified | Upload a cloud-native workflow JSON file to Alteryx One | |
| one workspace | one/workspace |
unclassified | Alteryx One workspace inspection and administration | |
| one workspace cloud-configs | one/workspace/cloud-configs |
unclassified | Manage cloud configuration records in the active workspace | |
| one workspace cloud-configs create | one/workspace/cloud-configs/create |
mutating | yes | Create a cloud configuration from a JSON payload |
| one workspace cloud-configs list | one/workspace/cloud-configs/list |
read-only | no | List cloud configuration records |
| one workspace cloud-configs update | one/workspace/cloud-configs/update |
mutating | yes | Update a cloud configuration from a JSON payload |
| one workspace config | one/workspace/config |
unclassified | Read or change the active workspace configuration | |
| one workspace config get | one/workspace/config/get |
read-only | no | Read the active workspace configuration |
| one workspace config reset | one/workspace/config/reset |
mutating | yes | Reset the active workspace configuration |
| one workspace config schema | one/workspace/config/schema |
read-only | no | Read the active workspace configuration schema |
| one workspace config set | one/workspace/config/set |
mutating | yes | Update the active workspace configuration from JSON payload |
| one workspace create | one/workspace/create |
mutating | yes | Create a One workspace from a JSON payload |
| one workspace current | one/workspace/current |
read-only | no | Inspect the current One workspace posture |
| one workspace delete | one/workspace/delete |
mutating | yes | Delete a One workspace by numeric id |
| one workspace detail | one/workspace/detail |
read-only | no | Inspect a One workspace by numeric id |
| one workspace groups | one/workspace/groups |
unclassified | Manage groups in the active workspace | |
| one workspace groups create | one/workspace/groups/create |
mutating | yes | Create a group from a JSON payload |
| one workspace groups delete | one/workspace/groups/delete |
mutating | yes | Delete a group |
| one workspace groups list | one/workspace/groups/list |
read-only | no | List groups in the active workspace |
| one workspace groups members | one/workspace/groups/members |
unclassified | Manage group members | |
| one workspace groups members add | one/workspace/groups/members/add |
mutating | yes | Add members to a group |
| one workspace groups members remove | one/workspace/groups/members/remove |
mutating | yes | Remove members from a group |
| one workspace groups roles | one/workspace/groups/roles |
unclassified | Set group roles from a JSON payload | |
| one workspace groups roles set | one/workspace/groups/roles/set |
mutating | yes | Set roles for a group from a JSON payload |
| one workspace groups update | one/workspace/groups/update |
mutating | yes | Update a group from a JSON payload |
| one workspace list | one/workspace/list |
read-only | no | List accessible One workspaces |
| one workspace members | one/workspace/members |
unclassified | Manage members of the active workspace | |
| one workspace members admins | one/workspace/members/admins |
read-only | no | List administrators of the active workspace |
| one workspace members invitation-link | one/workspace/members/invitation-link |
read-only | no | Get an invitation link for a member |
| one workspace members invite | one/workspace/members/invite |
mutating | yes | Invite a member with –email, or use –body for the batch/advanced API shape |
| one workspace members list | one/workspace/members/list |
read-only | no | List members of the active workspace |
| one workspace members reinvite | one/workspace/members/reinvite |
mutating | yes | Reinvite member(s) using a JSON payload |
| one workspace members remove | one/workspace/members/remove |
mutating | yes | Remove a member from the active workspace |
| one workspace members suspend | one/workspace/members/suspend |
mutating | yes | Suspend one member of the active workspace |
| one workspace members unsuspend | one/workspace/members/unsuspend |
mutating | yes | Unsuspend members in the active workspace |
| one workspace members update | one/workspace/members/update |
mutating | yes | Update one member from a JSON payload |
| one workspace transfer | one/workspace/transfer |
unclassified | Transfer the active workspace or its assets | |
| one workspace transfer assets | one/workspace/transfer/assets |
mutating | yes | Transfer active-workspace assets from a JSON payload |
| one workspace transfer start | one/workspace/transfer/start |
mutating | yes | Start an active-workspace transfer |
| one workspace use | one/workspace/use |
mutating | yes | Select an already-authenticated workspace as active |
| one write-settings | one/write-settings |
unclassified | Alteryx One write settings — list, create, and manage | |
| one write-settings count | one/write-settings/count |
read-only | no | Count One write settings |
| one write-settings create | one/write-settings/create |
mutating | yes | Create a One write setting from JSON payload |
| one write-settings delete | one/write-settings/delete |
mutating | yes | Delete a One write setting |
| one write-settings detail | one/write-settings/detail |
read-only | no | Inspect a One write setting |
| one write-settings list | one/write-settings/list |
read-only | no | List One write settings |
| one write-settings update | one/write-settings/update |
mutating | yes | Update a One write setting from JSON payload |
profile
Section titled “profile”| Name | Path | Safety | Mutating | Summary |
|---|---|---|---|---|
| profile | profile |
unclassified | Central profile registry and active profile management | |
| profile current | profile/current |
read-only | no | Show the active central profile pointer. |
| profile list | profile/list |
read-only | no | List centrally managed profiles and show the active profile. |
| profile migrate | profile/migrate |
unclassified | Migrate a legacy profile into the central registry | |
| profile path | profile/path |
unclassified | Show central profile storage paths | |
| profile show | profile/show |
unclassified | Show the resolved central profile and configured sections | |
| profile use | profile/use |
mutating-local | yes | Set the active central profile. |
secret
Section titled “secret”| Name | Path | Safety | Mutating | Summary |
|---|---|---|---|---|
| secret | secret |
unclassified | Keyring secret inspection and maintenance | |
| secret env-template | secret/env-template |
unclassified | Print a non-secret environment-variable template for automation | |
| secret migrate | secret/migrate |
unclassified | Move supported plaintext profile secrets into the OS keyring | |
| secret prune | secret/prune |
unclassified | Remove orphaned keyring accounts from the pre-v0.11.0 profile_name-scoped naming scheme | |
| secret set | secret/set |
unclassified | Store a named secret in the OS keyring, or attach an environment reference | |
| secret status | secret/status |
unclassified | Show secret source and resolution posture without returning secret values | |
| secret unset | secret/unset |
unclassified | Detach a named secret and safely remove its private keyring entry | |
| secret validate | secret/validate |
unclassified | Validate configured secret references without making network requests |
server
Section titled “server”| Name | Path | Safety | Mutating | Summary |
|---|---|---|---|---|
| server | server |
unclassified | Server discovery, logs, auth, diagnose, doctor, upgrade, and low-level API calls | |
| server api | server/api |
unclassified | Server API status, diagnostics, and OpenAPI-driven calls | |
| server api call | server/api/call |
mutating-or-read-only | no | Invoke a Server API operation by operationId. |
| server api diagnose | server/api/diagnose |
read-only | no | Validate token acquisition and API reachability for Server. |
| server api import-swagger | server/api/import-swagger |
read-only | no | Download and cache the Server OpenAPI document. |
| server api status | server/api/status |
read-only | no | Summarize Server API credentials and base URL posture. |
| server auth | server/auth |
unclassified | Server SSO/SAML auth diagnosis and simulation | |
| server auth diagnose | server/auth/diagnose |
unclassified | Inspect Server auth configuration and failure signals | |
| server auth diagnose ad-legacy | server/auth/diagnose/ad-legacy |
read-only | no | Inspect legacy Active Directory auth support signals. |
| server auth diagnose certificate | server/auth/diagnose/certificate |
read-only | no | Inspect certificate posture for SAML auth. |
| server auth diagnose saml | server/auth/diagnose/saml |
read-only | no | Inspect SAML configuration, metadata, and callback alignment. |
| server auth diagnose saml-logs | server/auth/diagnose/saml-logs |
read-only | no | Collect and summarize SAML login logs. |
| server auth simulate | server/auth/simulate |
unclassified | Simulate Server SAML authentication flows | |
| server auth simulate saml | server/auth/simulate/saml |
read-only | no | Simulate a SAML auth flow using metadata and expected endpoints. |
| server auth status | server/auth/status |
read-only | no | Summarize Server authentication configuration. |
| server ayx-paths | server/ayx-paths |
unclassified | Show common Alteryx Server filesystem paths | |
| server backup | server/backup |
unclassified | Run or simulate a full Server backup | |
| server backup-plan | server/backup-plan |
unclassified | Generate a Server backup file plan | |
| server diagnose | server/diagnose |
unclassified | Run targeted Server diagnostics | |
| server diagnose logs | server/diagnose/logs |
unclassified | Inspect Server log sources and triage targets | |
| server diagnose network | server/diagnose/network |
unclassified | Inspect Server network and connectivity checks | |
| server diagnose runtime-settings | server/diagnose/runtime-settings |
unclassified | Inspect Server runtime settings and Mongo config | |
| server diagnose startup | server/diagnose/startup |
read-only | no | Run a guided startup failure diagnosis. |
| server diagnose tls | server/diagnose/tls |
read-only | no | Inspect TLS, certificate, and proxy-related Server checks. |
| server doctor | server/doctor |
unclassified | Guided Server troubleshooting workflows | |
| server doctor logs | server/doctor/logs |
unclassified | Guide Server log-family triage and next steps | |
| server doctor network | server/doctor/network |
unclassified | Guide Server network troubleshooting checks | |
| server doctor runtime-settings | server/doctor/runtime-settings |
unclassified | Guide Server runtime settings validation | |
| server doctor startup | server/doctor/startup |
read-only | no | Run a guided startup doctor workflow. |
| server runtime-settings | server/runtime-settings |
unclassified | Summarize RuntimeSettings.xml and export JSON | |
| server server-logs | server/server-logs |
unclassified | Discover, summarize, and parse Server logs | |
| server server-logs context | server/server-logs/context |
read-only | no | Extract matching context from a Server log file |
| server server-logs discover | server/server-logs/discover |
read-only | no | Discover Server log locations from the active profile |
| server server-logs gallery-events | server/server-logs/gallery-events |
unclassified | Parse Gallery log events from a log file | |
| server server-logs inventory | server/server-logs/inventory |
read-only | no | Inventory known Server log files and metadata |
| server server-logs parse-csv | server/server-logs/parse-csv |
unclassified | Parse a Gallery log CSV export | |
| server server-logs recent | server/server-logs/recent |
unclassified | List recent Server log candidates | |
| server server-logs service-events | server/server-logs/service-events |
unclassified | Parse Service log events from a log file | |
| server server-logs summary | server/server-logs/summary |
read-only | no | Summarize a Server log file |
| server server-logs tail | server/server-logs/tail |
unclassified | Read the tail of a Server log file | |
| server system-info | server/system-info |
unclassified | Capture host system information to JSON | |
| server upgrade | server/upgrade |
unclassified | Server upgrade planning, backup, apply simulation, and postcheck helpers | |
| server upgrade apply | server/upgrade/apply |
unclassified | (preview) Simulate an upgrade apply — no changes are made | |
| server upgrade backup | server/upgrade/backup |
unclassified | Run a Server upgrade backup | |
| server upgrade bundle | server/upgrade/bundle |
unclassified | Bundle upgrade artifacts into a package | |
| server upgrade path | server/upgrade/path |
unclassified | Compute a supported Server upgrade path | |
| server upgrade plan | server/upgrade/plan |
read-only | no | Compute an upgrade path between versions. |
| server upgrade postcheck | server/upgrade/postcheck |
unclassified | Run a Server upgrade postcheck | |
| server upgrade precheck | server/upgrade/precheck |
unclassified | Run a Server upgrade precheck |
sqlserver
Section titled “sqlserver”| Name | Path | Safety | Mutating | Summary |
|---|---|---|---|---|
| sqlserver | sqlserver |
unclassified | SQL Server status, prechecks, connection helpers, and migration planning | |
| sqlserver connection-string | sqlserver/connection-string |
unclassified | Generate a SQL Server connection string | |
| sqlserver inventory | sqlserver/inventory |
unclassified | Summarize SQL Server inventory and database posture | |
| sqlserver migrate | sqlserver/migrate |
unclassified | Generate a SQL Server migration plan | |
| sqlserver precheck | sqlserver/precheck |
unclassified | Run SQL Server migration prechecks | |
| sqlserver prepare | sqlserver/prepare |
unclassified | Generate SQL Server migration preparation guidance | |
| sqlserver status | sqlserver/status |
unclassified | Summarize configured SQL Server connection posture | |
| sqlserver validate-strings | sqlserver/validate-strings |
unclassified | Validate configured SQL Server connection strings |
telemetry
Section titled “telemetry”| Name | Path | Safety | Mutating | Summary |
|---|---|---|---|---|
| telemetry | telemetry |
unclassified | Operational telemetry: running jobs, run history, top workflows/plans, errors, weekly run-counts | |
| telemetry errors | telemetry/errors |
unclassified | Recent failed-job messages with timestamps | |
| telemetry errors recent | telemetry/errors/recent |
unclassified | Recent failed job groups with error messages | |
| telemetry jobs | telemetry/jobs |
unclassified | Job-group telemetry: running, history, top | |
| telemetry jobs history | telemetry/jobs/history |
unclassified | Recent job-group history (succeeded + failed + cancelled) in –since window | |
| telemetry jobs running | telemetry/jobs/running |
unclassified | List job groups currently in Running or Queued state | |
| telemetry jobs top | telemetry/jobs/top |
unclassified | Top flows by run count over –since window | |
| telemetry permissions | telemetry/permissions |
unclassified | Who has access to which connections, workflows, and collections | |
| telemetry permissions collections | telemetry/permissions/collections |
unclassified | Collections / Gallery item-membership ACLs (Server only) | |
| telemetry permissions connections | telemetry/permissions/connections |
unclassified | DCM connections and the subjects with access to each | |
| telemetry permissions summary | telemetry/permissions/summary |
unclassified | Roll up access counts: connections per subject, people per workspace | |
| telemetry permissions workflows | telemetry/permissions/workflows |
unclassified | Who has workflow access. On One that’s workspace people (no per-flow ACL endpoint); on Server it’s the collections.appinfos surface | |
| telemetry plans | telemetry/plans |
unclassified | Plan telemetry: top by run-count, performance percentiles | |
| telemetry plans performance | telemetry/plans/performance |
unclassified | Per-plan duration percentiles | |
| telemetry plans top | telemetry/plans/top |
unclassified | Top plans by run count over –since window | |
| telemetry queue | telemetry/queue |
unclassified | Queue depth and wait-time stats (Server source only in Phase 2) | |
| telemetry queue status | telemetry/queue/status |
unclassified | Currently running + queued jobs (Server side) | |
| telemetry queue wait-time | telemetry/queue/wait-time |
unclassified | Wait-time stats over recent queue entries | |
| telemetry summary | telemetry/summary |
unclassified | One-shot overview composing the above into a single envelope | |
| telemetry weekly | telemetry/weekly |
unclassified | Weekly run-count matrix (7×24 buckets) — data feed for the deferred heatmap phase | |
| telemetry weekly run-counts | telemetry/weekly/run-counts |
unclassified | Emit a stable 168-bucket run-count matrix (day_of_week × hour) | |
| telemetry workflows | telemetry/workflows |
unclassified | Workflow telemetry: top by run-count / failure-rate / duration, errors | |
| telemetry workflows errors | telemetry/workflows/errors |
unclassified | Flows ordered by failure count over –since window | |
| telemetry workflows performance | telemetry/workflows/performance |
unclassified | Per-flow duration percentiles (p50/p95/p99) over –since window | |
| telemetry workflows top | telemetry/workflows/top |
unclassified | Top flows by run count, failure rate, or duration over –since window |
| Name | Path | Safety | Mutating | Summary |
|---|---|---|---|---|
| tools | tools |
unclassified | Cross-environment tools for environments.yaml source/target workflows | |
| tools workspace | tools/workspace |
unclassified | Cross-environment workspace scaffolding and comparison | |
| tools workspace check-dcm-connections | tools/workspace/check-dcm-connections |
unclassified | (preview) Resolve and summarize both workspace profiles — DCM connection checks not yet implemented | |
| tools workspace compare | tools/workspace/compare |
unclassified | (preview) Resolve and summarize both workspace profiles — comparison not yet implemented | |
| tools workspace init | tools/workspace/init |
unclassified | Write an environments.yaml workspace template | |
| tools workspace migrate-workflows | tools/workspace/migrate-workflows |
unclassified | (preview) Resolve and summarize both workspace profiles — workflow migration not yet implemented | |
| tools workspace resolve | tools/workspace/resolve |
unclassified | Resolve source and target environments from a workspace |
update
Section titled “update”| Name | Path | Safety | Mutating | Summary |
|---|---|---|---|---|
| update | update |
unclassified | Self-update from GitHub releases |
whoami
Section titled “whoami”| Name | Path | Safety | Mutating | Summary |
|---|---|---|---|---|
| whoami | whoami |
unclassified | Show active profile, account email, workspace, and environment in one shot. |
Capabilities
Section titled “Capabilities”| Id | Provider | Safety | Available | Tags | Summary |
|---|---|---|---|---|---|
designer.tool.add |
designer_local | mutating | yes | designer tool mutating local |
Add a tool node to a local workflow XML document. |
designer.tool.edit |
designer_local | mutating | yes | designer tool mutating local |
Replace a tool node in a local workflow XML document. |
designer.tool.remove |
designer_local | mutating | yes | designer tool mutating local |
Remove a tool node and related connections from a local workflow XML document. |
designer.tool.replace-connections |
designer_local | mutating | yes | designer tool connections mutating local |
Apply connection-fragment replacements inside a local workflow XML document. |
designer.workflow.context |
designer_local | read-only | yes | designer workflow context local |
Build local workflow context from a workflow XML artifact. |
designer.workflow.run |
designer_local | read-only | yes | designer workflow run local |
Run the local workflow capability surface with dry-run-aware validation. |
Non-goals for This Doc
Section titled “Non-goals for This Doc”This spec intentionally does not duplicate:
- every flag, positional argument, or alias
- every payload schema
- every API endpoint path
- every implementation detail of module layout
Those details belong in command help, ayx discover --deep, targeted handoff docs, or generated references.