Commands

Every ranwhat command

Eight commands in one tool, and no account for any of them. Start with check: it reads what your agents ran and what they left on disk, and changes nothing.

01 / Overview

A bare ranwhat lists them all.

watch, clean and scan each have a page of their own. The other five are below, and every flag is at the end.

uvx ranwhat
  ranwhat  · find out what your AI agents actually did

  check    watch and clean in one pass, changing nothing
  watch    what your agents already ran on this machine
  clean    credentials sitting in plaintext in agent transcripts
  sources  every agent ranwhat reads, and where it looked
  scan     the authority a set of credentials carries
  live     the same, asked of each token's own provider
  demo     see the output without setting anything up
  update   refresh the capability catalogue (needs a subscription)

  Start here:
    uvx ranwhat check
    uvx ranwhat demo

  No account needed. live and --pull-usage ask only the provider that
  issued each token, and update only fetches the catalogue. Everything
  else reads locally and sends nothing.
  Full options: uvx ranwhat --help
02 / check

check: watch and clean in one pass.

The one to start with. It reads every agent's history for the last 30 days and reports both halves: the actions watch flags, and the secrets clean finds. Every secret it finds is hidden in what it prints.

$ uvx ranwhat check

It never changes a file: check --apply is refused, and masking is left to clean. --json prints the actions and the secrets as one document. It exits with status 2 when it found no history to read, so a script can tell a machine with nothing on it from a clean one.

Flags: --days N, --source ID, --path ID=PATH, --root PATH, --state-dir PATH, --json.

03 / sources

sources: every agent it reads, and where it looked.

Twelve agents, each from where it keeps its history. sources says which it found on this machine, the folders it checked, and whether clean can mask secrets there or only read them.

ranwhat sources
  ranwhat sources  · the agents ranwhat reads

  Claude Code (claude-code): found, 1 transcript
    ~/.claude/projects (default)
    clean can mask it

  Codex (codex): found, 1 session
    ~/.codex (default)
    clean can mask it

  GitHub Copilot CLI (copilot-cli): not found
    ~/.copilot (default)
  …

  Point an agent elsewhere with --path ID=PATH; --source ID reads only
  that one.

check, watch and clean read them all by default. --source ID reads only that agent, and --path ID=PATH reads one from somewhere else, a backup or a copy from another machine. The watch page lists every agent.

Flags: --source ID, --path ID=PATH, --json.

04 / live

live: the same scan, asked of each token's provider.

scan scores the credentials a profile file describes. live asks the tokens themselves: each one goes to the provider that issued it, for read-only introspection, and nowhere else.

$ uvx ranwhat live

It reads GitHub, Google, Slack and Stripe tokens from the environment: RANWHAT_GITHUB_TOKEN, RANWHAT_GOOGLE_TOKEN, RANWHAT_SLACK_TOKEN and RANWHAT_STRIPE_TOKEN. The matching flags work too, but a token on the command line is visible to every user on the machine through ps, and lands in your shell history. --pull-usage also reads which grants were used, from each provider's own record.

Flags: --pull-usage, --github-org ORG, --window-days N, --controls PATH, --html PATH, --json.

05 / demo

demo: a whole report, with nothing to set up.

demo runs scan on a profile that ships with ranwhat: an agent called support-copilot, holding Google, GitHub, AWS, Slack and Stripe credentials. Read a report before you point ranwhat at anything of yours.

$ uvx ranwhat demo

--html report.html writes it as a page as well: the example report is that file, published as it comes out. Nothing goes online.

Flags: --html PATH, --json.

06 / update

update: a newer capability catalogue.

scan, live and demo rate each scope against a catalogue of what it allows, and one ships with ranwhat. update fetches a newer one for a Plus subscription, and Plus is not available yet.

ranwhat update
$ uvx ranwhat update --status
  No feed cached. The bundled catalogue is in use.
  A subscription adds providers as they ship new scopes:
  https://ranwhat.com/pricing

It is the only command that talks to ranwhat's own server, and it sends the subscription token and nothing else. Keep the token in RANWHAT_TOKEN, or pass --token once with --save-token. --status stays offline.

Flags: --token TOKEN, --save-token, --status.

07 / Flags

Every flag, and the commands that take it.

Flags go before or after the command. A flag a command does not take is refused, not ignored.

FlagCommandsWhat it does
--days N check, watch, clean How far back to read each agent's history, in days. 30 by default.
--source ID check, watch, clean, sources Read only this agent, and repeat it for more; every agent by default. IDs: claude-code, codex, gemini, copilot-cli, qwen, grok, droid, kimi-code, kimi, pi, muse-code, openclaw.
--path ID=PATH check, watch, clean, sources Read this agent's history from PATH instead of its default place, one per agent. sources says what each PATH is.
--root PATH check, watch, clean Claude Code's transcript directory, ~/.claude/projects by default. The same as --path claude-code=PATH.
--state-dir PATH check, watch, clean OpenClaw's state directory, ~/.openclaw by default. The same as --path openclaw=PATH.
--json every command but update Print the result as JSON instead of the report.
--apply clean Mask everything found without asking, after a backup to ~/.ranwhat/backups. check refuses it.
--no-interactive clean Report and exit, instead of opening the review session.
--html PATH demo, scan, live Write the report as a page to PATH as well.
--pull-usage scan, live Read which grants were used from each provider's own record, read only: AWS, GitHub, Google and Stripe. Slack has no usage pull.
--aws-profile NAME scan, with --pull-usage The AWS CLI profile to read usage with. It needs the aws command on your PATH.
--github-org ORG scan and live, with --pull-usage The GitHub organisation whose audit log holds the usage. GitHub's pull needs it.
--window-days N scan and live, with --pull-usage How far back to read usage, in days. 90 by default.
--github, --google, --slack, --stripe TOKEN live, and --pull-usage A token for that provider. Prefer RANWHAT_GITHUB_TOKEN and the like: a value given as a flag is visible to every user on the machine through ps, and lands in your shell history.
--controls PATH live A controls JSON to pair with what the tokens report.
--token TOKEN update The subscription token. Prefer RANWHAT_TOKEN, or save it once with --save-token.
--save-token update Write the token to ~/.ranwhat/token, readable by you alone, so later runs need no flag.
--status update Report the cached catalogue and exit, without going online.