Skip to navigation

AI agents and the CLI

Coding agents such as Claude Code, Cursor, and Codex do their work in a shell: they read help output, run commands, and parse the results. The Deel CLI gives them Deel operations in exactly that form. No Deel-specific plugin, software development kit (SDK), or tool definition is needed; an agent that can run deel --help can run every command.

What an agent session looks like

Given a task such as “add a 500 bonus to contract C123,” an agent lists the available commands, reads the exact contract with --help --json, generates a body skeleton, fills it in, then calls. The discovery steps run offline, needing neither a token nor network access, so the agent can plan the call completely before making it. See Discover before calling for the full sequence.

Behavior an agent depends on

These CLI properties are what let an agent use it without a special integration:

PropertyEffect on agent behavior
--help --json contractsThe agent reads flags, request fields, types, and enumerations instead of guessing field names from prose
--generate-input skeletonsThe agent starts from a complete, correctly typed body and only fills in values
JSON envelope on stdoutResults are parsed, not scraped; --fields and --jq keep them small
JSON errors on stderr with error.codeThe agent can tell a fixable input mistake from an authorization or policy problem
Deterministic idempotency keysAn agent that retries after an ambiguous failure cannot create a duplicate record
Non-interactive detectionWith CI=true, or CLAUDE_CODE, CURSOR, or CODEX present, output is JSON even on a pseudo-terminal. Note that deel auth login still prompts when stdin is a TTY, so pipe the token in or use DEEL_TOKEN
Local request logEvery request the agent made is recorded with the token masked, so a session can be audited afterwards

Which agents

Any agent that can execute shell commands can use the CLI. The table lists the environments the CLI recognizes and where its instructions usually live.

AgentDetected throughWhere to put CLI instructions
Claude CodeCLAUDE_CODECLAUDE.md in the project or home directory
CursorCURSORA rule file under .cursor/rules/
OpenAI CodexCODEXAGENTS.md in the project
CI runners and hosted agentsCI=trueThe job definition or the agent’s system prompt
Other agentsNot detected; output is JSON whenever stdout is not a terminalThe agent’s system prompt or tool description

This detection only changes whether output is JSON by default; it never changes what a command actually does.

CLI or MCP server

Deel provides two integration interfaces for AI clients, depending on your transport, authentication, and operational requirements.

Deel CLIDeel MCP server
Best forAgents that execute work in a shell: coding agents, automation agents, CIConversational assistants: Claude, ChatGPT, Cursor chat, custom MCP clients
InterfaceCommands and JSONMCP tools over HTTP
AuthenticationPersonal access token, stored in the OS keychain or injected as a secretOAuth2 handled by the client, or a personal access token
Discoverydeel --help, --help --json, --generate-inputtools/list
Runs inWherever the agent runs commands: laptop, container, CI runnerOn Deel infrastructure; nothing to install

The two can be used together: a chat assistant connected through MCP and a coding agent using the CLI in the repository are governed by the same token scopes.

Trust model

An agent using the CLI acts with the permissions of the token it holds. Limit what a mistake can do with three practices:

  • Scope the token to the operations the agent needs and nothing more.
  • Keep the agent in the demo environment (DEEL_ENV=demo) until the workflow is proven, then switch to production deliberately.
  • Leave local logging on. The log records every request, with the token masked and bodies omitted, which makes an agent session reviewable.

Agent workflows covers these in detail.

Next steps