Bolt CLI for terminal and VS Code
Install once, log in, then run and build from any terminal — including VS Code.
Last updated · September 2026
On this page
The Bolt CLI brings the same autonomous authorized-testing loop to your terminal: one prompt in, arranged output out. No browser needed. In VS Code, open the integrated terminal and use the same commands.
Prerequisites: account, then tokens
- Create your account
Sign up and sign in through the web workspace first — the CLI has no signup of its own.
- Top up tokens
Bolt runs draw from your prepaid balance. Check it with bolt balance after login; runs fail with Insufficient token balance when empty.
- Sign in from the terminal
bolt signin opens your browser and hands the terminal a token. Every CLI run bills your balance exactly like a workspace run.
Install
npm install -g bolt-sec bolt --help
npm install -g ./cli bolt --help
./cli is the CLI folder inside the BeeraSafe repo. Use it when you have the code checked out. End users install the published package bolt-sec instead. Requires Node 18+. No other dependencies. Or run without installing: npx bolt-sec run "..." --target example.com.
Log in once
bolt signin bolt auth status bolt balance
bolt signin is the whole flow: it opens your browser, you sign in there, and the terminal receives the token. No password is ever typed into your shell. A consent page names the account and machine before anything is granted, and approval returns a single-use code that only that terminal can redeem, valid for 10 minutes.
The CLI listens on 127.0.0.1 only, on a random free port, so nothing is exposed on your network. Add --no-browser to print the URL instead of opening it; over SSH, forward the printed port with ssh -L. The token is long-lived (1 year), stored at ~/.bolt/config.json with mode 600. --url is only needed for local dev or self-hosted backends (defaults to your last login, else BOLT_URL, else https://bolt.beerasafe.com). Server mints it at POST /api/cli/token/exchange and accepts it as Authorization: Bearer on /api/generate and dashboard reads. Env overrides: BOLT_URL, BOLT_TOKEN.
There is no password path and no headless credential flag: a typed password would sit in shell history and the process list. bolt login and bolt signin are the same browser flow — if you are already signed in on the web, the browser opens straight to a one-click consent page and the terminal is signed in. Over SSH, add --no-browser and open the printed URL locally.
Run and build
bolt run "get admin endpoints on subdomains of tesla.com" --target tesla.com
bolt build "nmap NSE script to detect exposed admin logins" --target tesla.com --out ./bolt-out
bolt build extracts fenced CODE blocks and saves each file (*.nse, *.py, *.sh) into --out (default ./bolt-out). Bolt does read-only checks server-side and writes complete scripts; you execute them from your own Kali/WSL.
Agent loop: let the model work the terminal
bolt run "refactor src/auth.ts to use the new session store" --tools bolt -p "what does this repo do?"
With --tools (or -p print mode), the model reads and searches your project, asks before editing files or running shell commands, and feeds each result back into the next step — up to 8 iterations. Reads and searches run free; writes, edits, and shell commands ask once or for the session; destructive commands are refused outright and everything mutating stays inside the directory you started in. Without a terminal to ask (-p, pipes), mutations are denied unless you pass --allow-all.
Interactive mode and sessions
bolt bolt run "is this phish real?" --mode defensive -f ./mail.eml -c bolt session list
Bare bolt opens an interactive agent on the Bolt backend only — no providers, no model picker. Type @path to attach a file inline (Tab completes paths). / lists commands with Tab completion, /agents lists task agents (sweep, probe, build, plan, validate, triage), /agent <name> arms one for the next prompt, /init explores the project and writes BOLT.md, /resume picks a saved session back up, /tools toggles local tools, /copy copies the last answer, /models shows the backend. Sessions persist under ~/.bolt/sessions; -c continues the latest, -s resumes one by id, and --file is repeatable.
VS Code
- Open the integrated terminal (Ctrl+`) and run the same bolt commands — no extension required.
- Keep the repo open beside the terminal: generated files land in ./bolt-out for review before running.
- Use --evidence ./alert.json to attach case files without pasting.
Not logged in?
Run bolt login (bolt signin works too) and approve in the browser. Check bolt auth status afterwards.
No code files saved?
The run produced prose, not fenced code. Re-ask as a build task (bolt build ...) and check the code tab equivalent in raw output.
401 Authentication required?
Token expired or revoked. Run bolt login again to mint a fresh token.
The model didn't touch my files?
Writes, edits, and shell commands need approval: answer the terminal prompt, allow for the session, or pass --allow-all. In print mode and pipes, mutations are denied without --allow-all.
Permission denied outside the project?
Writes, edits, and the shell are sandboxed to the directory where you started bolt. Start bolt from the project root instead.
The browser did not open?
Add --no-browser to print the URL and open it yourself. Over SSH, forward the printed port with ssh -L <port>:127.0.0.1:<port> and use the URL as-is.
The consent page asked me to deny something I did not start?
Do not approve it, and close the tab. The CLI rejects any response that does not match the request it made, so nothing is shared.

