> This page is for CLI.

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developer.deel.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developer.deel.com/_mcp/server.

# AI agents and the CLI

> How coding agents use the Deel CLI, and how it complements the MCP server

Coding agents such as Claude Code, Cursor, and Codex do their work in a shell: they read help output, run commands, and parse the results. The Deel CLI gives them Deel operations in exactly that form. No Deel-specific plugin, software development kit (SDK), or tool definition is needed; an agent that can run `deel --help` can run every command.

## What an agent session looks like

Given a task such as "add a 500 bonus to contract C123," an agent lists the available commands, reads the exact contract with `--help --json`, generates a body skeleton, fills it in, then calls. The discovery steps run offline, needing neither a token nor network access, so the agent can plan the call completely before making it. See [Discover before calling](/cli/agents/workflows#discover-before-calling) for the full sequence.

## Behavior an agent depends on

These CLI properties are what let an agent use it without a special integration:

| Property                                | Effect on agent behavior                                                                                                                                                                                          |
| --------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--help --json` contracts               | The agent reads flags, request fields, types, and enumerations instead of guessing field names from prose                                                                                                         |
| `--generate-input` skeletons            | The agent starts from a complete, correctly typed body and only fills in values                                                                                                                                   |
| JSON envelope on stdout                 | Results are parsed, not scraped; `--fields` and `--jq` keep them small                                                                                                                                            |
| JSON errors on stderr with `error.code` | The agent can tell a fixable input mistake from an authorization or policy problem                                                                                                                                |
| Deterministic idempotency keys          | An agent that retries after an ambiguous failure cannot create a duplicate record                                                                                                                                 |
| Non-interactive detection               | With `CI=true`, or `CLAUDE_CODE`, `CURSOR`, or `CODEX` present, output is JSON even on a pseudo-terminal. Note that `deel auth login` still prompts when stdin is a TTY, so pipe the token in or use `DEEL_TOKEN` |
| Local request log                       | Every request the agent made is recorded with the token masked, so a session can be audited afterwards                                                                                                            |

## Which agents

Any agent that can execute shell commands can use the CLI. The table lists the environments the CLI recognizes and where its instructions usually live.

| Agent                        | Detected through                                               | Where to put CLI instructions                   |
| ---------------------------- | -------------------------------------------------------------- | ----------------------------------------------- |
| Claude Code                  | `CLAUDE_CODE`                                                  | `CLAUDE.md` in the project or home directory    |
| Cursor                       | `CURSOR`                                                       | A rule file under `.cursor/rules/`              |
| OpenAI Codex                 | `CODEX`                                                        | `AGENTS.md` in the project                      |
| CI runners and hosted agents | `CI=true`                                                      | The job definition or the agent's system prompt |
| Other agents                 | Not detected; output is JSON whenever stdout is not a terminal | The agent's system prompt or tool description   |

This detection only changes whether output is JSON by default; it never changes what a command actually does.

## CLI or MCP server

Deel provides two integration interfaces for AI clients, depending on your transport, authentication, and operational requirements.

|                | Deel CLI                                                                  | [Deel MCP server](/mcp)                                                     |
| -------------- | ------------------------------------------------------------------------- | --------------------------------------------------------------------------- |
| Best for       | Agents that execute work in a shell: coding agents, automation agents, CI | Conversational assistants: Claude, ChatGPT, Cursor chat, custom MCP clients |
| Interface      | Commands and JSON                                                         | MCP tools over HTTP                                                         |
| Authentication | Personal access token, stored in the OS keychain or injected as a secret  | OAuth2 handled by the client, or a personal access token                    |
| Discovery      | `deel --help`, `--help --json`, `--generate-input`                        | `tools/list`                                                                |
| Runs in        | Wherever the agent runs commands: laptop, container, CI runner            | On Deel infrastructure; nothing to install                                  |

The two can be used together: a chat assistant connected through MCP and a coding agent using the CLI in the repository are governed by the same token scopes.

## Trust model

An agent using the CLI acts with the permissions of the token it holds. Limit what a mistake can do with three practices:

* **Scope the token** to the operations the agent needs and nothing more.
* **Keep the agent in the demo environment** (`DEEL_ENV=demo`) until the workflow is proven, then switch to production deliberately.
* **Leave local logging on.** The log records every request, with the token masked and bodies omitted, which makes an agent session reviewable.

[Agent workflows](/cli/agents/workflows) covers these in detail.

## Next steps

#### [Set up a coding agent](/cli/agents/setup)

Install the CLI where the agent runs and add the instruction block

#### [Agent workflows](/cli/agents/workflows)

Discovery, request bodies, errors, retries, jobs, and guardrails

#### [Command structure](/cli/usage/command-structure)

Details of --help --json and --generate-input

#### [MCP server](/mcp)

Connect conversational AI clients to Deel