Commands
Every ranwhat command
Eight commands in one tool, and no account for any of them. Start with check: it reads what your agents ran and what they left on disk, and changes nothing.
A bare ranwhat lists them all.
watch, clean and scan each have a page of their own. The other five are below, and every flag is at the end.
ranwhat · find out what your AI agents actually did check watch and clean in one pass, changing nothing watch what your agents already ran on this machine clean credentials sitting in plaintext in agent transcripts sources every agent ranwhat reads, and where it looked scan the authority a set of credentials carries live the same, asked of each token's own provider demo see the output without setting anything up update refresh the capability catalogue (needs a subscription) Start here: uvx ranwhat check uvx ranwhat demo No account needed. live and --pull-usage ask only the provider that issued each token, and update only fetches the catalogue. Everything else reads locally and sends nothing. Full options: uvx ranwhat --help
check: watch and clean in one pass.
The one to start with. It reads every agent's history for the last 30 days and reports both halves: the actions watch flags, and the secrets clean finds. Every secret it finds is hidden in what it prints.
It never changes a file: check --apply is refused, and masking is left to clean. --json prints the actions and the secrets as one document. It exits with status 2 when it found no history to read, so a script can tell a machine with nothing on it from a clean one.
Flags: --days N, --source ID, --path ID=PATH, --root PATH, --state-dir PATH, --json.
sources: every agent it reads, and where it looked.
Twelve agents, each from where it keeps its history. sources says which it found on this machine, the folders it checked, and whether clean can mask secrets there or only read them.
ranwhat sources · the agents ranwhat reads Claude Code (claude-code): found, 1 transcript ~/.claude/projects (default) clean can mask it Codex (codex): found, 1 session ~/.codex (default) clean can mask it GitHub Copilot CLI (copilot-cli): not found ~/.copilot (default) … Point an agent elsewhere with --path ID=PATH; --source ID reads only that one.
check, watch and clean read them all by default. --source ID reads only that agent, and --path ID=PATH reads one from somewhere else, a backup or a copy from another machine. The watch page lists every agent.
Flags: --source ID, --path ID=PATH, --json.
live: the same scan, asked of each token's provider.
scan scores the credentials a profile file describes. live asks the tokens themselves: each one goes to the provider that issued it, for read-only introspection, and nowhere else.
It reads GitHub, Google, Slack and Stripe tokens from the environment: RANWHAT_GITHUB_TOKEN, RANWHAT_GOOGLE_TOKEN, RANWHAT_SLACK_TOKEN and RANWHAT_STRIPE_TOKEN. The matching flags work too, but a token on the command line is visible to every user on the machine through ps, and lands in your shell history. --pull-usage also reads which grants were used, from each provider's own record.
Flags: --pull-usage, --github-org ORG, --window-days N, --controls PATH, --html PATH, --json.
demo: a whole report, with nothing to set up.
demo runs scan on a profile that ships with ranwhat: an agent called support-copilot, holding Google, GitHub, AWS, Slack and Stripe credentials. Read a report before you point ranwhat at anything of yours.
--html report.html writes it as a page as well: the example report is that file, published as it comes out. Nothing goes online.
Flags: --html PATH, --json.
update: a newer capability catalogue.
scan, live and demo rate each scope against a catalogue of what it allows, and one ships with ranwhat. update fetches a newer one for a Plus subscription, and Plus is not available yet.
$ uvx ranwhat update --status
No feed cached. The bundled catalogue is in use.
A subscription adds providers as they ship new scopes:
https://ranwhat.com/pricingIt is the only command that talks to ranwhat's own server, and it sends the subscription token and nothing else. Keep the token in RANWHAT_TOKEN, or pass --token once with --save-token. --status stays offline.
Flags: --token TOKEN, --save-token, --status.
Every flag, and the commands that take it.
Flags go before or after the command. A flag a command does not take is refused, not ignored.
| Flag | Commands | What it does |
|---|---|---|
--days N |
check, watch, clean | How far back to read each agent's history, in days. 30 by default. |
--source ID |
check, watch, clean, sources | Read only this agent, and repeat it for more; every agent by default. IDs: claude-code, codex, gemini, copilot-cli, qwen, grok, droid, kimi-code, kimi, pi, muse-code, openclaw. |
--path ID=PATH |
check, watch, clean, sources | Read this agent's history from PATH instead of its default place, one per agent. sources says what each PATH is. |
--root PATH |
check, watch, clean | Claude Code's transcript directory, ~/.claude/projects by default. The same as --path claude-code=PATH. |
--state-dir PATH |
check, watch, clean | OpenClaw's state directory, ~/.openclaw by default. The same as --path openclaw=PATH. |
--json |
every command but update | Print the result as JSON instead of the report. |
--apply |
clean | Mask everything found without asking, after a backup to ~/.ranwhat/backups. check refuses it. |
--no-interactive |
clean | Report and exit, instead of opening the review session. |
--html PATH |
demo, scan, live | Write the report as a page to PATH as well. |
--pull-usage |
scan, live | Read which grants were used from each provider's own record, read only: AWS, GitHub, Google and Stripe. Slack has no usage pull. |
--aws-profile NAME |
scan, with --pull-usage | The AWS CLI profile to read usage with. It needs the aws command on your PATH. |
--github-org ORG |
scan and live, with --pull-usage | The GitHub organisation whose audit log holds the usage. GitHub's pull needs it. |
--window-days N |
scan and live, with --pull-usage | How far back to read usage, in days. 90 by default. |
--github, --google, --slack, --stripe TOKEN |
live, and --pull-usage | A token for that provider. Prefer RANWHAT_GITHUB_TOKEN and the like: a value given as a flag is visible to every user on the machine through ps, and lands in your shell history. |
--controls PATH |
live | A controls JSON to pair with what the tokens report. |
--token TOKEN |
update | The subscription token. Prefer RANWHAT_TOKEN, or save it once with --save-token. |
--save-token |
update | Write the token to ~/.ranwhat/token, readable by you alone, so later runs need no flag. |
--status |
update | Report the cached catalogue and exit, without going online. |