Scripting and CI
This page collects the patterns that make unattended runs reliable: non-interactive authentication, a pinned version, error handling, and job polling. The CLI prints a JSON envelope, reports failures in a stable error envelope, and sends an idempotency key with every write.
Non-interactive authentication
Inject the token as a secret and pass it through the environment or stdin. Never write it to the workspace.
deel auth status is a preflight check: it fails with auth.missing or auth.invalid before the script does any work.
Pin the CLI version
Beta releases can change commands and output. Pin the version in automation and upgrade deliberately.
Fail fast and read error codes
Use set -e semantics for the exit status and jq for the reason.
Retryable conditions (429, 5xx) are already retried by the CLI up to three times. A script that sees http.429 after that should back off for longer rather than loop immediately.
Retry safety
Every mutating command carries a deterministic idempotency key derived from its content. Re-running a failed script step sends the same key and cannot create a duplicate record. If a step must create a second identical record on purpose, pass a new --idempotency-key. See Idempotency and retries.
Build bodies with jq
Generate request bodies from your own data instead of templating strings.
For bulk operations, map a CSV or database export into the array shape the operation expects and pass it with --input file://. Bulk adjustment operations accept up to 50 items per request; split larger sets into batches.
Follow asynchronous jobs
Bulk commands return a job_id. Poll until the job reaches a terminal status and inspect failed items. See Asynchronous jobs for a complete loop.
GitHub Actions example
This job writes real payroll data in production. Review the batch file before wiring this into a real pipeline, and treat DEEL_ENV: prod as a deliberate choice, not a default to copy unexamined.
Runners set CI=true, so the CLI treats the session as non-interactive and prints JSON regardless of flags.
Logging in CI
The local log is written to the runner’s home directory and discarded with the job. Disable it with DEEL_LOG=off if the runner’s filesystem is shared or persisted, or keep it and upload it as an artifact for auditing; tokens are masked and bodies are omitted by default.