v0.20.0
This release makes ayx an agent-first CLI. It removes the bundled terminal UI,
picks its output format based on who is calling, strengthens Alteryx One
authentication, and adds the Agent Studio asset commands.
It also carries the work originally tagged v0.19.2, which was never published.
See Validation below.
The bundled TUI is gone
Section titled “The bundled TUI is gone”ayx tui is removed per ADR 0004. A hidden stub returns a remediation envelope
for this release cycle and is deleted in 0.21.0. Everything it did has a
first-class command: profile, auth, and connectivity setup live in ayx onboard, ayx one login, ayx profile, and ayx doctor.
Output adapts to the caller
Section titled “Output adapts to the caller”Without --output, ayx emits compact JSON when stdout is not a terminal or an
agent host is detected (AYX_AGENT, CLAUDECODE, AI_AGENT), and text on a
terminal. AYX_OUTPUT=<mode> overrides the automatic choice, and --output
overrides everything. Piping to a human reader now wants AYX_OUTPUT=text.
ayx completions <shell> is exempt, so redirected completion scripts stay
scripts.
Compact output projects the underlying resource rather than transport timing,
retry, and raw-response metadata. It stays honest about what it dropped: list
results carry omitted_fields, truncated, shown_count, and total_count,
so a caller can always tell it is reading a projection and knows the flag that
returns the rest. --output json-full remains the lossless diagnostic format.
Workspace people and admin lists read the service’s nested list wrapper and show useful identifiers, including email when present. An unknown list wrapper reports an actionable compatibility cue instead of falsely claiming there are no items.
--jq <FILTER> and --raw-output run a jq filter over the rendered, redacted
document in-binary. The filter cannot read the process environment or host
clock, and cannot change the exit code.
Durable Alteryx One OAuth API-token sign-in
Section titled “Durable Alteryx One OAuth API-token sign-in”ayx one login --oauth-api-token is a guided, explicitly non-OTP setup path for
an OAuth 2.0 API token generated in Alteryx One. It asks for the public client
ID and hides the refresh-token entry. The CLI verifies the pair before
persisting it under the profile’s secret policy: the operating-system credential
store under the default secure policy, or the profile file under plaintext,
including the fallback you consent to when the credential store is unavailable.
Access tokens are renewed from that refresh credential when needed, and neither
token appears in normal command output.
An ordinary ayx one login retains an existing OAuth API-token credential
instead of spending a refresh grant. Use the explicit API-token mode only to set
up or replace that credential.
Agent Studio assets
Section titled “Agent Studio assets”Adds the documented one agent-assets command family for bounded Agent Studio
asset discovery and registration workflows. Mutating operations use the standard
dry-run and confirmation protections.
Credential and output fixes
Section titled “Credential and output fixes”A review pass over the authentication work found several defects worth calling out for anyone deciding whether to upgrade:
- Replacing an OAuth credential no longer leaves the secret it replaced behind in the OS keyring, where it stayed valid and unreachable by any cleanup path.
- An explicit
--client-idis no longer ignored when the selected workspace already stores one, which had broken the credential-replacement flow the API-token mode exists to serve. - A stale profile-level access-token reference no longer rejects the login that would replace it.
--auth-method oauth-refreshno longer prompts for a refresh token it already has, which blocked indefinitely in sessions with a terminal but no human.- Result and detail views keep the
dry_run,mutating, andappliedflags, which previously fell out of the projection on applied mutations. --output json-fullredactsprivateKey,accountKey,sharedKey,signature, andcsrf, and provider error text is scrubbed of credential-shaped runs.- An applied multipart upload verifies the selected workspace identity before sending, like every other applied mutation.
Validation
Section titled “Validation”This release is gated by formatting, generated command-surface validation, workspace clippy, locked workspace tests, a release build, and the published cross-platform tag workflow.
The v0.19.2 tag was cut earlier from part of this work and did not clear those
gates: its release build failed on every platform. The tag was withdrawn rather
than published, its branch was reviewed, and the resulting fixes are listed
above. That work ships here instead, which is why there is no v0.19.2 release.