Authenticated marketplace CLI · Node.js 18+

Use APIMarket from your terminal

The api command is the authenticated marketplace client. apimarket is its compatibility alias. The standalone api-tester is a separate generic HTTP tester; api can inspect your account, use marketplace API keys, show seller tasks, and access authorized marketplace-team read queues.

Download and install the api package

Download apimarket-api-cli.zip with the button above, extract it, and run these commands from the extracted folder. Node.js 18 or newer is required. The ZIP contains only the authenticated CLI package — not the marketplace application or any credentials.

Quick command reference

All commands below use the saved marketplace URL and token after login. Add --json to read commands when you need machine-readable output.

api --help
api auth status
api whoami

# Discover APIs and plans
api categories
api browse --q weather
api browse-bundles
api api show API_SLUG
api api plans API_SLUG

# Buy and monitor access
api checkout --plan PLAN_ID
api subscribe --plan PLAN_ID
api keys
api keys create --name "Laptop key"
api keys rotate KEY_ID
api keys revoke KEY_ID
api subscriptions
api subscriptions set overage_on SUBSCRIPTION_ID
api wallet
api usage --days 30
api orders
api notifications
api notifications read NOTIFICATION_ID

# Gateway calls use a marketplace API key, not the CLI token
APIMARKET_API_KEY=am_REPLACE_WITH_BUYER_KEY api call API_SLUG /vehicle/{number}
api call API_SLUG /path -X POST \
  -H 'Content-Type: application/json' \
  -d '{"example":true}'

# Seller read/work queues; add-api creates metadata only
api seller add-api --name "Example API" --category CATEGORY_ID --type rest
api seller apis
api seller tasks
api seller plans
api seller bundles
api seller analytics
api seller payouts

# Authorized marketplace-team read queues
api admin dashboard
api admin tasks
api admin apis
api admin orders
api admin payouts
api admin users
api admin categories
api admin reviews
api admin coupons
api admin broadcasts
api admin support
api admin refunds
api admin roles
api admin settings

# Retire the current CLI token
api auth logout

Full CLI documentation

APIMarket authenticated CLI

The marketplace CLI gives buyers, sellers, and authorized admins a terminal workspace. It is separate from the generic unauthenticated developer tester.

Install

Download api CLI ZIP from the public [Developer CLI page](/developer-cli.php) or [authenticated CLI guide](/cli-guide.php). The download is apimarket-api-cli.zip; it contains only package.json, README.md, and bin/api.js.

macOS / Linux

curl -fL "https://your-marketplace.example/developer-cli.php?download=node" -o apimarket-api-cli.zip
unzip apimarket-api-cli.zip -d apimarket-api-cli
cd apimarket-api-cli
npm install -g .
api login --url https://your-marketplace.example

Windows PowerShell

$zip = Join-Path $HOME "Downloads\apimarket-api-cli.zip"
Invoke-WebRequest -Uri "https://your-marketplace.example/developer-cli.php?download=node" -OutFile $zip
$dir = Join-Path $HOME "apimarket-api-cli"
Expand-Archive -Path $zip -DestinationPath $dir -Force
Set-Location $dir
npm install -g .
api login --url https://your-marketplace.example

In Windows PowerShell, curl is commonly an alias for Invoke-WebRequest; GNU flags such as -fsSL do not apply. Use Invoke-WebRequest as above or call curl.exe -fL explicitly. The CLI requires Node.js 18 or newer. auth login starts a ten-minute browser/device authorization flow. The browser session is the existing APIMarket account; the CLI never receives the account password.

If your machine does not allow global npm installs, do not use sudo just for this client. Run it directly from the extracted folder instead:

node ./bin/api.js --help
node ./bin/api.js auth login --url https://your-marketplace.example

PowerShell equivalent:

node .\bin\api.js auth login --url https://your-marketplace.example

The authenticated CLI has no server process to keep running.

For SSH and automation, sign in on the website, open Account → CLI access, and create a manual token. Avoid putting the token directly in shell history; pass it through the environment instead:

APIMARKET_TOKEN='amc_REPLACE_WITH_TOKEN' \
  api auth login --url https://your-marketplace.example

Windows PowerShell:

$env:APIMARKET_TOKEN = 'amc_REPLACE_WITH_TOKEN'
api auth login --url https://your-marketplace.example
Remove-Item Env:APIMARKET_TOKEN

The --token form is also supported, but a token on a command line may be visible in shell history or process listings.

The token is stored locally in ~/.config/apimarket/config.json on macOS/Linux or %APPDATA%\\APIMarket\\config.json on Windows, with restrictive permissions. Set APIMARKET_CONFIG_DIR to change the local location. Server-side tokens are stored only as SHA-256 hashes and can be revoked from the account page or with api auth logout.

Buyer commands

api whoami
api categories
api browse --q weather
api browse-bundles
api api show vehicle-api
api api plans vehicle-api
api checkout --plan 12
api subscribe --plan 12
api keys
api keys create --name "Laptop key"
api keys rules 3 add --mode allow --cidr 203.0.113.10
api subscriptions
api subscriptions set overage_on 12
api wallet
api usage --days 30
api orders
api notifications
api notifications read

api call sends a buyer marketplace API key through the normal metered PHP gateway. The CLI bearer token is never sent to the provider. Since marketplace key secrets are write-only on the server, supply the buyer key explicitly with --api-key or APIMARKET_API_KEY.

APIMARKET_API_KEY=am_REPLACE_WITH_BUYER_KEY api call vehicle-api /vehicle/{number}
api call vehicle-api /vehicle/{number} --api-key am_REPLACE_WITH_BUYER_KEY
api call graph-api /graphql -X POST \
  -H 'Content-Type: application/json' \
  -d '{"query":"{ health }"}'

Seller commands

Create a metadata-only draft from the terminal. The private provider connection and credentials are configured afterward in the seller web workspace, not sent as buyer inputs or printed by the CLI. The API-first review flow requires a saved connection and at least one enabled plan before submission; the admin approves the API first, then reviews and prices its plans.

api seller add-api \
  --name "Weather API" \
  --category 2 \
  --type rest \
  --tagline "Current weather over HTTP" \
  --description "A short buyer-facing description"

api seller apis
api seller readiness vehicle-number-to-mobile-number
api seller tasks
api seller plans
api seller bundles
api seller analytics
api seller payouts

Seller output is intentionally limited to marketplace metadata. Provider base URLs, credential names/values, passthrough fields, and private connection data are not returned. api seller readiness SLUG reports safe booleans/counts and the next web-workspace steps without returning the private connection.

Admin commands

Admin commands require an active admin role. Subadmins also need the corresponding marketplace permission:

api admin dashboard
api admin tasks
api admin apis
api admin orders
api admin payouts
api admin users
api admin categories
api admin reviews
api admin coupons
api admin broadcasts
api admin support
api admin refunds
api admin roles
api admin settings

Use --json on any read command for scripts and automation. Admin mutations remain in the web review workspace so the existing CSRF, RBAC, audit, notification, and confirmation flows are not bypassed by a terminal token.

CLI security model

The CLI is an authenticated client, not a server shell. It cannot execute PHP, SQL, shell commands, or arbitrary administrator actions. Every server request is checked against the logged-in user, the CLI token, existing seller ownership, subscription/quota rules, and admin RBAC permissions.

A CLI token is equivalent to a password for the account that created it. Protect the local config file, avoid putting tokens in shell history, use HTTPS, revoke unknown tokens from Account → CLI access, and run api logout when retiring a machine. Marketplace API keys are separate credentials used only for gateway calls; restrict them with IP rules where practical and rotate them immediately if exposed.

Seller drafts created through the CLI contain metadata only. Documentation, provider URLs, authentication fields and credentials are rejected by the CLI draft endpoint and must be configured in the protected seller web workspace.

Security: the CLI is a client, not a server shell. It cannot execute PHP, SQL, filesystem, or operating-system commands. Protect and revoke CLI tokens like passwords. Provider URLs and provider credentials remain in the protected seller workflow.