Getting started

Quickstart

For first-time registration, create an account. For another target with the same account, create a workspace. This page covers authentication and a first read with an existing account.

1. Sign in

orc auth login

Open the URL printed in your terminal, sign in, and authorize the CLI. The CLI saves your credentials. You do not need to register or authenticate for every operation.

If the browser does not open automatically, open the printed URL. To explicitly start browser authentication from a non-interactive terminal, use orc auth login --web.

orc auth status --json

For an API key already provided by your secret manager, initialize from standard input:

printf '%s' "$ORCHESTOR_API_KEY" | orc init

2. Confirm your workspace

orc workspace current
orc workspaces list
orc workspace use YOUR_WORKSPACE_ID

Replace YOUR_WORKSPACE_ID with a workspace ID returned by the list command. You can override the selection for a data command with --workspace.

A browser login success message alone does not prove workspace access. If invitation redemption or initial organization setup remains, continue in Welcome.

3. Retrieve data

orc brands list --format table
orc prompts list --json
orc reports visibility get --json

An empty brand list is normal for a new workspace. Verify authentication, workspace selection, and the actual API read separately.

4. Connect an agent

Follow Connect an agent and verify a read to install Skills and authorize the hosted MCP connection for your client.

If brands or answers are still empty, run the first observation to generate candidates, confirm them, and retrieve results.

Separate accounts or execution environments

Use a named profile to store another credential:

orc auth login --profile my-project
ORCHESTOR_PROFILE=my-project orc auth status --json
ORCHESTOR_PROFILE=my-project orc workspaces list --json

Creating another workspace with the same account does not require another profile or login. Continue to workspace creation.

An API key in the environment takes precedence over saved sign-in credentials. Use orc status --json to check the active source. For unattended CI, see API key setup and CI permissions.