CLI reference
Commands, niiro.yml, CI, and the failure patterns worth knowing.
Commands
- niiro init
- Detects the stack, writes niiro.yml, stores the project token, offers a CI step. With --project it runs without prompts.
- niiro push
- Filters, scans for secrets, uploads the delta, reports which videos the change affects.
- niiro status
- Last sync, number of stale videos, link into the portal.
- niiro login
- Stores the token in the OS keychain. In CI use NIIRO_TOKEN instead.
niiro.yml
include is an allowlist: what is not listed never leaves your machine. exclude removes files a pattern would otherwise include.
project: acme-webinclude:- src/components/**- src/app/**- tailwind.config.ts- src/styles/**exclude:- "**/*.test.*"- "**/__mocks__/**"
Always excluded
Even when a pattern would include them: environment files, node_modules, .git, lockfiles and binaries over 5 MB. The project token is write-only, it can create snapshots but never read code or anything derived from it.
Secret scan
gitleaks runs over the filtered file list before every upload. A finding stops the push and names file and line. --allow-secret <fingerprint> is a deliberate override, logged on our side, and the same scan runs again on the server.
CI
init offers a generated workflow; a manual push stays equivalent. In CI the token comes from the NIIRO_TOKEN variable instead of the keychain.
name: niiroon:push:branches: [main]jobs:push:runs-on: ubuntu-lateststeps:- uses: actions/checkout@v4- run: npx @niiro/cli pushenv:NIIRO_TOKEN: ${{ secrets.NIIRO_TOKEN }}
Goal: run niiro push in this repository's CI. Context: https://niiro.io/docs/cli.md 1. Add a pipeline step that runs `npx @niiro/cli push` on every push to the main branch. 2. Read the token from a CI secret named NIIRO_TOKEN. 3. Open a pull request with the change. Done when the pipeline is green and the pull request explains the step.
When something fails
- Push never arrives
- Run the CLI where niiro.yml lives; in a monorepo that is usually the frontend package. In CI, check that NIIRO_TOKEN is set.
- Secret found
- Exclude the file or rotate the value. Use --allow-secret only for values that are meant to be public.
- Upload interrupted
- Push again: files already uploaded are skipped. An incomplete snapshot is discarded after 24 hours.
- Framework not recognized
- The analysis still runs on the raw CSS and we take a look at your setup. The report says so openly.
Updated 2026-08-05