# Reachpad CLI – Spin up free sandboxes in seconds to develop and host apps

> Source: <https://github.com/Reachpad/reachpad-cli>
> Published: 2026-08-25 23:59:10+00:00

Run coding agents in durable cloud workspaces: disk and memory survive the machine underneath, so a paused workspace resumes mid-session.

With Homebrew on Apple silicon macOS or x86_64/arm64 Linux:

```
brew install reachpad/tap/reachpad
```

With npm, anywhere Node 18+ runs:

```
npm install -g @reachpad/cli
```

Or with the checksum-verifying installer:

```
curl -fsSL https://reachpad.dev/install | sh
```

Linux x86_64/arm64 (musl, static) and macOS arm64/x86_64. The script fetches
the latest release from this repository, verifies its checksum against
SHA256SUMS, and installs to `~/.local/bin/reachpad`

(override with
`REACHPAD_INSTALL_DIR`

).

All three deliver the same binary. `@reachpad/cli`

is a launcher around it, not
a second implementation — see [ npm/README.md](/Reachpad/reachpad-cli/blob/main/npm/README.md), which also
explains the macOS quarantine problem npm sidesteps.

Run Reachpad:

```
reachpad
```

On first use, the CLI shows a short code, opens WorkOS hosted sign-in, and then lists your workspaces. WorkOS handles the account login and any required MFA or SSO. After approval, Reachpad exchanges the short-lived WorkOS token once and saves a user-scoped Reachpad credential and the production endpoint with mode 0600. No password or authentication factor is entered into Reachpad.

On a remote machine without a usable browser, run `reachpad auth login --no-browser`

and open the displayed URL on another device. The manual
credential flow remains available from
[reachpad.dev/connect](https://reachpad.dev/connect) as a recovery path.

Then list, create, or attach to a workspace:

```
reachpad ws list
reachpad ws create --name scratch
reachpad attach <workspace-id>
```

Useful maintenance commands:

```
reachpad doctor
reachpad update
reachpad completions bash
reachpad completions zsh
reachpad completions fish
```

`reachpad update`

respects how Reachpad was installed: Homebrew installs are
directed to `brew upgrade reachpad`

and npm installs to `npm install -g @reachpad/cli@latest`

, while installer-managed binaries are updated in place
after the release checksum is verified. Whoever installed the binary owns it —
a second writer is how a working install becomes a broken one.

Docs: [reachpad.dev/docs/cli](https://reachpad.dev/docs/cli)

This repository carries the full CLI source: the `reach`

package (shipped
binary name `reachpad`

) and its three library crates (`proto`

, the frozen
wire protocol; `authz`

, Biscuit verify and offline attenuation; `runtime`

,
the config and tracing shell). Release binaries are built from this source
by [the release workflow](/Reachpad/reachpad-cli/blob/main/.github/workflows/release.yml) on GitHub's
runners, and every release carries a SHA256SUMS the install script verifies.
To build it yourself (needs Rust and `protoc`

):

```
cargo build --release -p reach
./target/release/reachpad --version
```

Every release tarball also carries a signed build-provenance attestation, so the chain is checkable without trusting us:

```
gh attestation verify reachpad-<target>.tar.gz --repo Reachpad/reachpad-cli
```

That proves the bytes came out of this repository's release workflow at the commit the tag names. It rests on no key of ours — the signing identity is a short-lived credential minted for that one workflow run, and the record is in a public transparency log.

The snapshot is synced from a private monorepo on every release, so file an
issue rather than a PR for changes; a PR here would be overwritten by the
next sync (the sync script and its header in `Cargo.toml`

say the same).
The CLI is an ordinary client of a public API: it holds no platform secrets
and nothing it does is privileged (the server refuses anything a stranger
could not do).

Source-available; copyright Tako Research, all rights reserved.
