Install the CLI#
On macOS (Apple Silicon or Intel) and Linux x86_64:
curl -fsSL https://oak.space/install | sh
On Windows x86_64, from PowerShell:
irm https://oak.space/install.ps1 | iex
The installer picks the native binary for your machine, verifies its minisign signature, and puts it at ~/.local/bin/oak (%USERPROFILE%\.local\bin\oak.exe on Windows). If that directory isn't on your PATH, the installer prints the line to add.
| Installer variable | Effect |
|---|---|
INSTALL_DIR | Install somewhere else โ e.g. /usr/local/bin on a CI image, so the binary is already on PATH. |
OAK_NO_LOGIN=1 | Skip the "Log in now?" prompt at the end. (It's skipped automatically when there's no terminal.) |
On macOS the installer also fetches the Oak Mount app that lazy mounts need; if it can't, the first oak mount installs it instead. See Setting up mounts.
Linux ARM64: binaries are published on the GitHub releases page, but the installer doesn't select them yet. Download
oakforlinux-arm64from there and put it on yourPATH.
Sign in#
oak login
oak whoami # prints the username you're signed in as
oak login opens your browser at oak.space, where you sign in however you normally do (password or GitHub), and hands a token back to the CLI over a one-shot local callback. On a machine with no browser โ an SSH session, a container โ it prints a URL instead: open it on any other device, approve, and paste the one-time code it shows back into the terminal.
The token is saved in ~/.oak/credentials and lasts 90 days. Run oak login again to refresh it, or oak logout to remove it.
To check which credential the CLI is actually using โ handy when a push 404s on a repo you know exists โ run:
oak auth status
It reports where the credential came from (never the secret itself), which server, and the identity the server resolves it to.
Non-interactive machines and CI#
oak login needs a human once. For scripts, CI jobs, and long-running agents, use an API key instead and export it:
export OAK_API_KEY=oak_...
OAK_API_KEY beats every stored credential. Create keys โ including narrowly scoped, read-only, or single-repo keys โ as described in API keys and tokens.
Self-hosted or staging servers#
Every command that talks to a server takes -r, --remote <URL> (default https://oak.space). You can also set OAK_REMOTE for a whole shell. Once a checkout is linked to a server, it remembers which one.
Keep it up to date#
oak upgrade # latest stable release
oak upgrade --canary # track the rolling pre-release channel
Upgrades are signature-checked like the installer. The CLI checks for a new version at most once a day and prints a one-line notice; set OAK_NO_UPDATE_CHECK=1 to turn that off.
Shell completion#
oak completions zsh > ~/.zfunc/_oak # zsh
oak completions bash > ~/.local/share/bash-completion/completions/oak # bash
oak completions fish > ~/.config/fish/completions/oak.fish # fish
elvish and powershell are supported too.
Teach your agent#
If you use a coding agent, install the bundled skill in each repo you work in:
oak skill install # into ./.claude/skills/ โ commit it
oak skill install --global # or into ~/.claude/skills/ for every project
More in Working with agents.
Uninstall#
Delete the binary (~/.local/bin/oak) and, if you want to drop your login and local mount state too, ~/.oak/. On macOS, also delete Oak Mount from /Applications. Repositories you've cloned are ordinary directories; each one's Oak metadata lives in its own .oak/ folder.
Next: Quickstart.