Skip to main content
Glama

ycli

One Yandex 360 toolkit — four ways to use it. Drive Tracker, Wiki, and Forms from a CLI, an MCP server, a Python SDK, or a Claude Code plugin. Built for AI agents first — pleasant for humans too.

English · Русский

CI Coverage PyPI Python License Docs DeepWiki

  • 🧩 One SDK, four surfaces — write logic once, use it as a CLI, an MCP server, a Python library, or a Claude Code plugin.

  • 🤖 Agent-native — the MCP server exposes read and write tracker_*, wiki_*, forms_* tools, one per SDK/CLI operation, plus a cross-cutting status tool (counts in Coverage), with honest annotations (reads are marked read-only; writes declare whether they are destructive/idempotent); ycli mcp start --read-only serves a reads-only view for cautious deployments, and --toolsets core serves a curated everyday profile when a host limits how many tools it accepts.

  • 🛡️ Trustworthy — typed pydantic models, the real Yandex API quirks handled for you, and a test suite kept at 100% coverage.

  • ⚡ Zero-friction start — uv add yandex-cli, ycli auth login, go.

The full documentation (tutorial, how-to guides, the CLI, MCP and SDK reference) is at bim-ba.github.io/ycli.

Install

uv add yandex-cli            # CLI + Python SDK
uv add 'yandex-cli[mcp]'     # …plus the MCP server (`ycli mcp start`)

Run it without installing, or install it as a standalone tool:

uvx yandex-cli --help                 # one-off, no install
uv tool install yandex-cli            # persistent CLI
uv tool install 'yandex-cli[mcp]'     # …with the MCP server

pip install yandex-cli works too. The CLI ships as both yandex-cli and the short ycli.

Using an AI harness (Claude Code, Claude Desktop, Cursor, VS Code, Codex, Gemini CLI, opencode, Docker)? See Install in your harness.

The SDK's ServiceAccountAuth (IAM tokens minted from a Yandex Cloud service-account key) needs the service-account extra: uv add 'yandex-cli[service-account]'.

Related MCP server: Yandex Tracker MCP

Quick start

Pick the surface that fits how you work.

uv add yandex-cli
ycli --help
ycli tracker issues get TRACKER-1
ycli wiki pages get onboarding

Output formats — a global --format / -o picks how results print (the global options work before or after the subcommand: ycli -o json tracker issues get K = ycli tracker issues get K -o json; a command that declares an option of its own, like forms answers export --format, keeps it):

ycli tracker issues get TRACKER-1            # auto: a pretty table on a TTY…
ycli tracker issues get TRACKER-1 | jq .     # …and raw JSON when piped (agent/script-safe)
ycli -o yaml wiki pages get onboarding       # or: -o json | -o yaml | -o pretty
ycli --jq .summary tracker issues get TRACKER-1   # filter the JSON with jq; a string prints bare

--jq EXPR runs a jq program over the command's JSON result and prints like jq -r: a string comes out raw, anything else as one compact JSON value per line. It cannot be combined with -o yaml / -o pretty, and it needs the jq Python package (a dependency; it has no build for Windows on ARM).

Deleting asks first. A command that destroys data (every delete, clear, abort…) asks DELETE <url> — this deletes data. Continue? on stderr when you are at a terminal, and exits 1 if you decline. In a script, a pipe or CI there is no one to ask, so it fails with exit 2 until you pass --yes / -y: ycli tracker boards delete 7 --yes. Reads and ordinary writes never ask.

Preview a write. --dry-run sends nothing for any write: it prints the request instead (method, URL, body; never your token), through the same -o / --jq output, and exits 0. Reads still run, so a command that reads and then writes shows its first write only: ycli tracker boards delete 7 --dry-run. (The two commands that ask the API itself to validate a request, forms filling submit and wiki pages move, call that --validate-only.)

An endpoint ycli has not wrapped. ycli api PATH --service tracker|wiki|forms calls it like gh api would, with the same auth, retries, output and exit codes:

ycli api issues/TRACKER-1 --service tracker --jq .summary           # GET (the default method)
ycli api issues/TRACKER-1/comments --service tracker -F text=@note.md   # POST: a field turns it into one
ycli api pages/descendants --service wiki -f slug=docs --paginate   # every page, as one JSON array

PATH is relative to the service's base URL; a full URL of a service needs no --service, and any other host is refused (your token never goes elsewhere). -f key=value is a string, -F is typed (true, null, numbers, JSON, @file for a file's text, key[sub]=v to nest, key[]=v for an array); fields of a GET or DELETE go to the query string, otherwise to a JSON body (--input FILE sends a raw body instead). -H 'Name: value' adds a header, -X sets the method, and --dry-run, --yes and --jq behave as everywhere. --paginate follows Tracker's Link: rel="next" and Wiki's next_cursor; Forms pages its listings in more than one way, so pass its paging parameters with -f yourself.

Run it over stdio (needs the mcp extra):

ycli mcp start               # full read/write tool set (honest annotations)
ycli mcp start --read-only   # reads-only view for cautious deployments

Serving every tool costs a large tools/list and some hosts cap a request (VS Code allows 128 tools), so pick what the session needs:

Flag

Serves

--toolsets tracker,wiki

only those services (tracker, wiki, forms); default all

--toolsets core

a curated everyday profile of about 40 tools (issues, comments, transitions, worklog, wiki pages and search, form reads)

--tools a,b / --exclude-tools a,b

add or hide single tools by name (unknown names fail at start)

--read-only

no write tools; always wins over the flags above

--tool-search

lists a search tool and a call proxy instead of the tools; use it with a large set

status_get is always served. The listing omits output schemas and doctest examples (results still carry structuredContent), which cuts tools/list from about 1.9 MB to about 0.5 MB for the full set.

For several users, serve it over HTTP: each MCP client signs its user in through Yandex ID (OAuth), and every tool call runs with that user's own Yandex token. Setup, including the Yandex OAuth app and the reverse proxy, is in Self-host over HTTP.

ycli mcp start --transport http --toolsets core   # needs YCLI__MCP__BASE_URL and an OAuth app

List the tool names a given set of flags exposes without running the server:

ycli mcp methods --toolsets core --read-only

Point an MCP client at it — no prior install needed via uvx (tools are namespaced tracker_*, wiki_*, forms_*):

{
  "mcpServers": {
    "yandex": {
      "command": "uvx",
      "args": ["--from", "yandex-cli[mcp]", "ycli", "mcp", "start"],
      "env": {
        "YANDEX_ID_OAUTH_TOKEN": "...",
        "YANDEX_ID_ORGANIZATION_ID": "..."
      }
    }
  }
}
from ycli.yandex.tracker.client import TrackerClient

tracker = TrackerClient(oauth_token="…", organization_id="…")
issue = tracker.issues.get("TRACKER-1")
print(issue.summary)
/plugin marketplace add bim-ba/ycli
/plugin install yandex-360@ycli

Teaches an agent to drive Yandex 360 through ycli — including the real API quirks. See plugins/yandex-360/.

Skills (Claude Code plugin)

Skill

Use for

yandex-360

Entry point — install + auth, pick a surface (CLI/MCP/SDK), route to a domain

yandex-360-tracker

Issues, epics, comments, transitions, links, worklog, changelog

yandex-360-wiki

Wiki pages, page tree, comments, attachments, YFM authoring

yandex-360-forms

Forms, questions/schema, responses, publishing

The skills encode the read/write commands and the gnarly Yandex API quirks (epic-vs-parent, transition discovery, permanent wiki slugs, fields= rules, Forms host/header traps, answers pagination).

Configure

ycli reads two values from the environment (or a .env file — cp .env.example .env):

YANDEX_ID_OAUTH_TOKEN=...        # a Yandex OAuth token with Tracker/Wiki/Forms access
YANDEX_ID_ORGANIZATION_ID=...    # your Yandex 360 organization id

ycli sends the org id as X-Org-Id for every service (HTTP header names are case-insensitive per RFC 9110, so one casing serves all).

Optional settings follow the YCLI__<GROUP>__<SETTING> pattern; ycli rejects an invalid value at startup and names the variable:

Variable

Default

Meaning

YCLI__HTTP__TIMEOUT_SECONDS

30

Per-request timeout, seconds (> 0)

YCLI__HTTP__RETRIES

3

Retries for idempotent requests on 429/5xx (≥ 0)

YCLI__HTTP__MAX_ITEMS

500

Item cap for listings without --limit/--all (> 0)

YCLI__LOGGING__LEVEL

WARNING

DEBUG, INFO, WARNING, ERROR or CRITICAL; -v means INFO (every HTTP request), -vv means DEBUG

YCLI__LOGGING__FORMAT

text

text or json (one object per line); logs always go to stderr

Get your credentials

Yandex issues OAuth tokens only through a registered application, so it's a one-time app registration plus one command.

1. Register an OAuth app at oauth.yandex.ru and grant it the Tracker, Wiki, and Forms permissions (read and write — the CLI and the MCP server both write; the read scopes alone suffice only if you run the MCP server with ycli mcp start --read-only). Put the ClientID — and the Client secret if you want the headless flow — in your .env (ycli reads it from there):

YANDEX_OAUTH_CLIENT_ID=...        # from your app
YANDEX_OAUTH_CLIENT_SECRET=...    # optional — enables the headless device flow

2. Log in. ycli auth login gets a token, detects your organization, and writes both into .env:

ycli auth login
  • client id + secret → the device flow: ycli prints a code and a https://ya.ru/device link; approve there and it captures the token — no redirect, works over SSH.

  • only the client id (or --implicit) → the browser flow: ycli opens the Yandex authorize page; approve, then copy the token it displays and paste it back.

Check it any time with ycli auth status: it shows whose token it is (from Yandex ID), your organization (its name needs the optional directory:read_organization scope; without it you get the id and a note) and whether each service accepts the token. ycli tracker auth status (or wiki, forms) probes just that one service. Both exit non-zero when a service rejects the token.

Headless (device flow):

# 1. start the flow — returns a user_code + verification_url
curl -s -X POST https://oauth.yandex.ru/device/code -d "client_id=$YANDEX_OAUTH_CLIENT_ID"
# 2. open https://ya.ru/device, enter the user_code, approve
# 3. exchange the device_code for the token
curl -s -X POST https://oauth.yandex.ru/token \
  -d grant_type=device_code -d "code=<device_code>" \
  -d "client_id=$YANDEX_OAUTH_CLIENT_ID" -d "client_secret=$YANDEX_OAUTH_CLIENT_SECRET"

Browser (implicit): open https://oauth.yandex.ru/authorize?response_type=token&client_id=<ClientID> in a logged-in browser, approve, and copy the token from the page. (Plain curl can't — implicit needs an interactive browser session.)

Organization id: tracker.yandex.ru/admin/orgs → your organization → copy the identifier.

The Yandex documentation behind each step:

Step

Yandex docs

Register the OAuth app

Registering an app (Yandex ID)

Device flow (ycli auth login with a secret)

Entering the code on the authorization page

Browser flow (--implicit)

Obtain a token manually

Token and organization header per service

Tracker · Wiki · Forms API access

Exit codes

A failed ycli command exits with a code that says what kind of failure it was, so a script can branch without parsing the message.

Code

Meaning

When

0

ok

the command succeeded

1

failure

any other failure: a 4xx the API rejected, an unmapped error, a declined confirmation

2

usage

a bad command line or an invalid YCLI__… setting

3

not found

the API answered 404 (or the token cannot see the object)

4

auth

401 / 403, or no credentials set

5

rate limited

the API answered 429 and the retries ran out (the hint shows Retry-After)

6

transient

a 5xx, a timeout or a lost connection: worth retrying later

Coverage

ycli wraps 334 operations across 62 resources of the Tracker, Wiki, and Forms REST API. Every one is reachable from the Python SDK and the CLI, and 322 MCP tools serve them to agents (321 per service plus status_get).

Legend. ✅ in CLI or MCP means the resource is reachable on that surface; MCP tools carry honest hints (reads are readOnlyHint, writes say whether they are destructive or idempotent), and ycli mcp start --read-only serves only the reads. Resource and operation names link to the official Yandex API reference. A ✅ says ycli wraps the operation; where it differs from what Yandex publishes is listed under Against the published API. Generated from the code by scripts/gen_coverage.py; do not edit by hand.

Tracker

Issues & work items

Agile boards

Resource

Operations

CLI

MCP

boards

list · get · create · edit · delete

✅

✅

sprints

list · get · create · edit · delete · start · archive

✅

✅

columns

list · get · create · edit · delete

✅

✅

Dictionaries

Resource

Operations

CLI

MCP

priorities

list · create · edit

✅

✅

statuses

list · create · edit

✅

✅

resolutions

list · create · edit

✅

✅

issuetypes

list · create · edit

✅

✅

linktypes

list

✅

✅

Fields, queues & structure

Automation & bulk

Resource

Operations

CLI

MCP

macros

list · get · create · edit · delete

✅

✅

triggers

list · get · create · edit · webhook_log

✅

✅

autoactions

get · create · logs · log_detail

✅

✅

dashboards

create · add_cycle_time_widget

✅

✅

bulk

update · move · transition · get · issues

✅

✅

import

task · comment · link · worklog · file · comment_file

✅

✅

Entities, users & search

Wiki

Pages

Collaboration

Resource

Operations

CLI

MCP

comments

list · thread · thread_get · create · delete

✅

✅

attachments

list · get · preview · download · download_by_url · delete · attach · upload

✅

✅

access

create · update · delete · clear

✅

✅

Grids (dynamic tables)

Async & uploads

Resource

Operations

CLI

MCP

operations

clone_get · gridclone_get · move_get

✅

✅

uploadsessions

create · get · upload_part · finish · abort · abort_all

✅

✅

Identity

Resource

Operations

CLI

MCP

me

get

✅

✅

Forms

Surveys & questions

Responses & export

Resource

Operations

CLI

MCP

answers

get · list · list_all · export · export_results · download_export · integrations_list · delete · restore

✅

✅

operations

get

✅

✅

Integrations

Resource

Operations

CLI

MCP

hooks

list · get · create · modify · delete

✅

✅

subscriptions

list · get · create · modify · delete · attach

✅

✅

variables

list

✅

✅

notifications

list · get · status_get · restart · cancel · errors_list

✅

✅

Distribution

Resource

Operations

CLI

MCP

keysets

list · get · create · modify · delete · download

✅

✅

filling

get · submit · suggest

✅

✅

Media

Resource

Operations

CLI

MCP

files

upload · verify · download · delete

✅

✅

images

upload · clone

✅

✅

Identity

Resource

Operations

CLI

MCP

me

get

✅

✅

Every resource and operation above deep-links to the Yandex API reference: 318 of 334 operations resolve to their own endpoint page and 15 to their resource's page. No public API reference exists yet for tracker.linktypes, tracker.linktypes.list, shown as plain text. See CONTRIBUTING.md for the intentional exclusions (UI-only endpoints with no public REST API) and per-method notes.

Against the published API

What ycli sends, replayed from its contract tests, compared with what Yandex publishes: the Wiki and Forms OpenAPI documents and Tracker's API reference (prose, so only operations and the query parameters a page lists are compared). The published side is the snapshot in scripts/api_snapshot/; a weekly job fetches it again and opens an issue when Yandex has changed it.

Service

Published

Wrapped

Not wrapped

Operations that differ

Source

Tracker

190

188

0 (+2 on purpose)

25

API reference

Wiki

56

56

0

15

OpenAPI

Forms

84

84

0

15

OpenAPI

Not wrapped on purpose

Operation

Why

GET /boards

boards list reads the paginated GET /boards/_paginate

GET /users

users list reads the paginated GET /users/_relative

Sent by ycli, not published

ycli

Its request

entities.attachment_download

GET /attachments/{file_id}/{filename}

linktypes.list

GET /linktypes

Parameters and fields

Operation

ycli

Difference

POST /bulkchange/_move

bulk.move

query parameters ycli cannot send: notify

POST /bulkchange/_transition

bulk.transition

query parameters ycli cannot send: notify

POST /bulkchange/_update

bulk.update

query parameters ycli cannot send: notify

POST /entities/{entity_type}

entities.create

query parameters ycli cannot send: fields

PATCH /entities/{entity_type}/{entity_ID}

entities.edit

query parameters ycli cannot send: expand, fields

POST /entities/{entity_type}/{entity_ID}/attachments/{file_ID}

entities.attachments_attach

query parameters ycli cannot send: expand, fields, notify, notifyAuthor

DELETE /entities/{entity_type}/{entity_ID}/checklistItems

entities.checklists_delete

query parameters ycli cannot send: expand, fields, notify, notifyAuthor

PATCH /entities/{entity_type}/{entity_ID}/checklistItems

entities.checklists_edit

query parameters ycli cannot send: expand, fields, notify, notifyAuthor

POST /entities/{entity_type}/{entity_ID}/checklistItems

entities.checklists_create

query parameters ycli cannot send: expand, fields, notify, notifyAuthor

DELETE /entities/{entity_type}/{entity_ID}/checklistItems/{checklist_item_ID}

entities.checklists_delete_item

query parameters ycli cannot send: expand, fields, notify, notifyAuthor

PATCH /entities/{entity_type}/{entity_ID}/checklistItems/{checklist_item_ID}

entities.checklists_edit_item

query parameters ycli cannot send: expand, fields, notify, notifyAuthor

POST /entities/{entity_type}/{entity_ID}/checklistItems/{checklist_item_ID}/_move

entities.checklists_move

query parameters ycli cannot send: expand, fields, notify, notifyAuthor

POST /entities/{entity_type}/{entity_ID}/comments

entities.comments_create

query parameters ycli cannot send: expand, isAddToFollowers, notify, notifyAuthor

DELETE /entities/{entity_type}/{entity_ID}/comments/{comment_ID}

entities.comments_delete

query parameters ycli cannot send: notify, notifyAuthor

PATCH /entities/{entity_type}/{entity_ID}/comments/{comment_ID}

entities.comments_edit

query parameters ycli cannot send: expand, isAddToFollowers, notify, notifyAuthor

GET /entities/{entity_type}/{entity_ID}/events/_relative

entities.history

query parameters ycli cannot send: direction, newEventsOnTop, selected

POST /issues

issues.create

query parameters ycli cannot send: notify

POST /issues/_search

issues.search

query parameters ycli cannot send: expand, perScroll, scrollId, scrollTTLMillis, scrollType

GET /issues/_suggest

issues.suggest

query parameters ycli cannot send: embed, expand, fields, full, queue

POST /issues/{id_задачи}/_move

issues.move

query parameters ycli cannot send: expand, initialStatus, moveAllFields, notify, notifyAuthor

GET /issues/{issue_ID}

issues.get

query parameters ycli cannot send: expand, fields

GET /issues/{issue_ID}/changelog

changelog.list

query parameters ycli cannot send: field, sort, type

GET /issues/{issue_ID}/comments

comments.list

query parameters ycli cannot send: expand

GET /priorities

priorities.list

query parameters ycli cannot send: localized

GET /queues

queues.list

query parameters ycli cannot send: expand

Parameters and fields

Operation

ycli

Difference

GET /pages

pages.get

query parameters ycli cannot send: raise_on_redirect, revision_idresponse fields ycli drops: active_revision, actuality, breadcrumbs, redirect

POST /pages

pages.create

query parameters ycli cannot send: fields, is_silentresponse fields ycli drops: active_revision, actuality, breadcrumbs, redirect

GET /pages/descendants

pages.descendants

query parameters ycli cannot send: include_self, show_all

DELETE /pages/{idx}

pages.delete

query parameters ycli cannot send: recursive

GET /pages/{idx}

pages.get_by_id

query parameters ycli cannot send: raise_on_redirect, revision_idresponse fields ycli drops: active_revision, actuality, breadcrumbs, redirect

POST /pages/{idx}

pages.update

query parameters ycli cannot send: allow_merge, fields, is_silentresponse fields ycli drops: active_revision, actuality, breadcrumbs, redirect

POST /pages/{idx}/append-content

pages.append_content

query parameters ycli cannot send: fields, is_silentresponse fields ycli drops: active_revision, actuality, breadcrumbs, redirect

GET /pages/{idx}/attachments

attachments.list

query parameters ycli cannot send: order_by, order_direction

GET /pages/{idx}/attachments/{file_id}

attachments.get

response fields ycli drops: is_downloadable, user

GET /pages/{idx}/comments

comments.list, comments.thread

query parameters ycli cannot send: order_by, order_direction, status_filter

POST /pages/{idx}/comments

comments.create

response fields ycli drops: author, is_deleted, reactions, resolve_status

GET /pages/{idx}/descendants

pages.descendants_by_id

query parameters ycli cannot send: include_self, show_all

GET /pages/{idx}/grids

pages.grids

query parameters ycli cannot send: order_direction

GET /pages/{idx}/resources

resources.list

query parameters ycli cannot send: order_direction

POST /recovery_tokens/{idx}/recover

recovery.restore

response fields ycli drops: pages_count

Parameters and fields

Operation

ycli

Difference

GET /answers

answers.get

response fields ycli drops: started

GET /operations/{operation_id}

operations.get

response fields ycli drops: result

GET /surveys

surveys.list

query parameters ycli cannot send: favourite, group, name, orderby, ownership, published, show_all

POST /surveys

surveys.create

response fields ycli drops: allow_multiple_answers, author, auto_publication, captcha, file_storage, fill_again, follow, followers, footer, hashed_id, iframe, max_count, metric, need_auth, quiz, share, show_last_answer, stats, styles, teaser, texts, validator_urlmodel fields that are not published: modified

GET /surveys/{survey_id}

surveys.get

response fields ycli drops: allow_multiple_answers, author, auto_publication, captcha, file_storage, fill_again, follow, followers, footer, hashed_id, iframe, max_count, metric, need_auth, quiz, share, show_last_answer, stats, styles, teaser, texts, validator_urlmodel fields that are not published: modified

PATCH /surveys/{survey_id}

surveys.modify

response fields ycli drops: allow_multiple_answers, author, auto_publication, captcha, file_storage, fill_again, follow, followers, footer, hashed_id, iframe, max_count, metric, need_auth, quiz, share, show_last_answer, stats, styles, teaser, texts, validator_urlmodel fields that are not published: modified

GET /surveys/{survey_id}/answers

answers.list, answers.list_all

query parameters ycli cannot send: date_from, date_to, format, ordering, page_size, questions, use_slugs

POST /surveys/{survey_id}/answers/export

answers.export

response fields ycli drops: result

POST /surveys/{survey_id}/questions

questions.create

response fields ycli drops: account_id, columns, conditions, data_source, fixed, header, hint_source, image, items, modify_choices, multichoice, quiz_comment, quiz_items, rows, show_first, validators, widget

DELETE /surveys/{survey_id}/questions/{question_id}

questions.delete

query parameters ycli sends that are not published: force

GET /surveys/{survey_id}/questions/{question_id}

questions.get

query parameters ycli cannot send: with_slugsresponse fields ycli drops: account_id, columns, conditions, data_source, fixed, header, hint_source, image, items, modify_choices, multichoice, quiz_comment, quiz_items, rows, show_first, validators, widget

PATCH /surveys/{survey_id}/questions/{question_id}

questions.modify

response fields ycli drops: account_id, columns, conditions, data_source, fixed, header, hint_source, image, items, modify_choices, multichoice, quiz_comment, quiz_items, rows, show_first, validators, widget

GET /surveys/{survey_id}/suggest

filling.suggest

response fields ycli drops: address, avatar, board, city, cloud_uid, country_id, department, display_text, email, floor_id, floor_number, full_name, group_id, login, office_id, parent_id, population, queue, region, role_scope, row_id, slug, status, tracks_count, type, uid, url, yandex_uid

POST /surveys/{survey}/form

filling.submit

response fields ycli drops: quiz_resultmodel fields that are not published: results, scores, total_scores

GET /users/me

me.get

response fields ycli drops: display, login

Development

uv sync --all-extras   # --all-extras pulls in the `mcp` extra the tests exercise
uv run pytest          # 100% coverage gate; HTTP stubbed with `MockAPI` (no live network)

The source layout and the invariants that keep it regular are in ARCHITECTURE.md; see CONTRIBUTING.md for conventions and how to add an endpoint. Contributions welcome.

License

MIT © 2026 Sava Znatnov

Maintenance

ActivityActive
ResponsivenessResponsive

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    A
    maintenance
    Exposes selected operations of an existing REST/OpenAPI app as MCP tools with generated schemas, permission annotations, and a risk class, requiring explicit opt-in before anything is listed and a second flag for destructive calls. Enforces security-first guardrails such as environment-injected auth, a single confined base URL, timeouts, response caps, rate limiting, and a local test console for trying tools.
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables read-only MCP access to Yandex Tracker for retrieving issues with comments and attachment metadata, searching issues, reading issue history, downloading attachments, and finding users. It also supports connection status checks and token configuration without exposing secrets.
    44 npm
    MIT