Skip to main content

Install and sign in

Requires Node.js 22 or newer.
The same release is on npm as @amerged/ohmyhost-cli and @amerged/ohmyhost-mcp. Both sources install the ohmyhost and ohmyhost-mcp commands, so keep one source per computer and upgrade from the one already installed (npm ls --global names it). To switch, first remove the other pair: npm uninstall --global @ohmyhost/product-cli @ohmyhost/mcp for the archives, npm uninstall --global @amerged/ohmyhost-cli @amerged/ohmyhost-mcp for npm. Release manifest and checksums · Current release Run ohmyhost login --json and open the returned sign-in URL. The link already carries its confirmation code, so you do not type one. Sign in there, or create your account on that same page if you do not have one yet; signing up is open. Use the organizations returned by whoami; when several are available, select the one for this project. If none exists, create one through the get-started Skill.

Authenticate

The CLI accepts two credentials and picks in this order:
  1. OHMYHOST_TOKEN — a user API token. Set it and the CLI works immediately. No browser, no login.
  2. A login saved by ohmyhost login — used only when OHMYHOST_TOKEN is unset. With several, choose --profile-name NAME or OHMYHOST_PROFILE=NAME (saved accounts).
OHMYHOST_TOKEN wins whenever set; no saved login is read. Naming another account or a checkout linked for another organization fails environment_token_context_mismatch before execution. If the value is not a valid sk_… token the command fails with invalid_environment_token and does not fall back. These commands need the interactive login and refuse a token: login, logout, organization create|list|use, and token create|list|revoke. Run those in a process without OHMYHOST_TOKEN; preserve the existing private token file. Other commands use the token’s current permissions and workspace role.

Inspect and select a project

Run inside the repository:
Resolve actual hosted blockers. Without a root ohmyhost.yaml, run ohmyhost init --json once blockers are resolved; --root DIR selects a nested app and --region eu prepares EU storage. Commit and push the file. Init never overwrites an existing configuration. Reuse an existing project, or create one after choosing isolated or shared data, protected or public Dev access, and setting HOSTING_REGION to the chosen us or eu:
ORGANIZATION_ID comes from whoami. Create a unique PROJECT_REQUEST_KEY once and retain it for retries. PROJECT_OPERATION_ID is the creation response’s operation.id. After success, select the created project’s ID from the list as PROJECT_ID.

Connect and deploy

Read the workspace’s GitHub connection first. If it is not connected, an Owner or Admin runs connect:
Open its single authorization.authorization_url, then repeat the same connect request/key after browser confirmation until status is connected. This link handles installation/user authorization when needed. A failed or expired attempt needs the reported last_failure resolved and a new connect key for the same workspace. Set GITHUB_OWNER and GITHUB_REPOSITORY to a repository covered by that installation. Retain one unique SOURCE_REQUEST_KEY for this source link:
Observe the returned source-link operation; it needs no second browser authorization for a covered repository. Missing access is repaired through github.connection.settings_url returned by GitHub status, then the same link command/key. No build starts until you deploy a plan. From the repository root, link also records .ohmyhost/ and adds /.ohmyhost/ to .gitignore. Later commands may omit --project; the CLI names the selected project on stderr. A checkout keeps one link per organization: when several match, supply --project or --profile-name (linked_project_selection_required). Use the full SHA of the pushed commit as COMMIT_SHA:
Read the plan, its requirements and credit effects. Set application runtime secrets if required. Take PLAN_ID from plan.id, retain a new DEPLOY_REQUEST_KEY, and execute the approved plan:

Verify progress and the application

OPERATION_ID is the deploy response’s operation.id. A wait timeout leaves the accepted operation running; inspect it without submitting another deployment. Follow returned polling guidance. If dev_access_mode is protected, the clean URL answers 404 without a session: open the reusable share_url first, then test the clean Dev URL. If it is public, open the clean Dev URL directly. Keep the share link out of logs and project notes. The Owner can change the mode with ohmyhost project dev-access mode, replace the link with ohmyhost project dev-share rotate, or revoke it with ohmyhost project dev-share revoke.

Common follow-ups

PROJECT_ETAG is project.etag from project status. Renaming breaks links to the old address; read project addresses first. For later automation, create a token from Profile → API Tokens or the token commands. New tokens stay valid until revoked. MCP setup uses the same account access.