Skip to content

v0.20.0

This release makes ayx an agent-first CLI. It removes the bundled terminal UI, picks its output format based on who is calling, strengthens Alteryx One authentication, and adds the Agent Studio asset commands.

It also carries the work originally tagged v0.19.2, which was never published. See Validation below.

ayx tui is removed per ADR 0004. A hidden stub returns a remediation envelope for this release cycle and is deleted in 0.21.0. Everything it did has a first-class command: profile, auth, and connectivity setup live in ayx onboard, ayx one login, ayx profile, and ayx doctor.

Without --output, ayx emits compact JSON when stdout is not a terminal or an agent host is detected (AYX_AGENT, CLAUDECODE, AI_AGENT), and text on a terminal. AYX_OUTPUT=<mode> overrides the automatic choice, and --output overrides everything. Piping to a human reader now wants AYX_OUTPUT=text. ayx completions <shell> is exempt, so redirected completion scripts stay scripts.

Compact output projects the underlying resource rather than transport timing, retry, and raw-response metadata. It stays honest about what it dropped: list results carry omitted_fields, truncated, shown_count, and total_count, so a caller can always tell it is reading a projection and knows the flag that returns the rest. --output json-full remains the lossless diagnostic format.

Workspace people and admin lists read the service’s nested list wrapper and show useful identifiers, including email when present. An unknown list wrapper reports an actionable compatibility cue instead of falsely claiming there are no items.

--jq <FILTER> and --raw-output run a jq filter over the rendered, redacted document in-binary. The filter cannot read the process environment or host clock, and cannot change the exit code.

Durable Alteryx One OAuth API-token sign-in

Section titled “Durable Alteryx One OAuth API-token sign-in”

ayx one login --oauth-api-token is a guided, explicitly non-OTP setup path for an OAuth 2.0 API token generated in Alteryx One. It asks for the public client ID and hides the refresh-token entry. The CLI verifies the pair before persisting it under the profile’s secret policy: the operating-system credential store under the default secure policy, or the profile file under plaintext, including the fallback you consent to when the credential store is unavailable. Access tokens are renewed from that refresh credential when needed, and neither token appears in normal command output.

An ordinary ayx one login retains an existing OAuth API-token credential instead of spending a refresh grant. Use the explicit API-token mode only to set up or replace that credential.

Adds the documented one agent-assets command family for bounded Agent Studio asset discovery and registration workflows. Mutating operations use the standard dry-run and confirmation protections.

A review pass over the authentication work found several defects worth calling out for anyone deciding whether to upgrade:

  • Replacing an OAuth credential no longer leaves the secret it replaced behind in the OS keyring, where it stayed valid and unreachable by any cleanup path.
  • An explicit --client-id is no longer ignored when the selected workspace already stores one, which had broken the credential-replacement flow the API-token mode exists to serve.
  • A stale profile-level access-token reference no longer rejects the login that would replace it.
  • --auth-method oauth-refresh no longer prompts for a refresh token it already has, which blocked indefinitely in sessions with a terminal but no human.
  • Result and detail views keep the dry_run, mutating, and applied flags, which previously fell out of the projection on applied mutations.
  • --output json-full redacts privateKey, accountKey, sharedKey, signature, and csrf, and provider error text is scrubbed of credential-shaped runs.
  • An applied multipart upload verifies the selected workspace identity before sending, like every other applied mutation.

This release is gated by formatting, generated command-surface validation, workspace clippy, locked workspace tests, a release build, and the published cross-platform tag workflow.

The v0.19.2 tag was cut earlier from part of this work and did not clear those gates: its release build failed on every platform. The tag was withdrawn rather than published, its branch was reviewed, and the resulting fixes are listed above. That work ships here instead, which is why there is no v0.19.2 release.