strazactl
Straza admin CLI
Synopsis
A command that talks to strazad goes to --server, else $STRAZA_SERVER, else the server of your strazactl login. It authenticates with that login, or with an admin API token when STRAZA_API_TOKEN holds one. With a token, every admin call sends it in place of the login, and one line on stderr says so. strazactl login, connect and disconnect act as a person and refuse to run while the token is set, and strazactl logout still ends the stored login.
Inside a coding agent, a command that changes Straza refuses to run on your login, because the agent would act as you. Reads and checks such as policy simulate still work. For automation, use an admin API token in STRAZA_API_TOKEN. An agent proposes config changes through the built-in straza MCP server’s drafting tools. strazactl knows it runs inside a coding agent from the environment variables that Claude Code, the Gemini CLI and the npm build of Codex set for the commands they run.
Every command exits 0 when it did its job and 1 when it did not. An unknown verb exits 1 too. strazactl drafts and strazactl policy diff name other exit codes in their help. A retired verb exits 2 and names what replaced it.
Options
--server string strazad base URL (overrides $STRAZA_SERVER and the server you logged into)
Commands
- strazactl api-token: Manage long-lived admin API tokens, the one credential for automation, connectors and an identity manager’s SCIM push
- strazactl approvals: List and decide approval requests, and mint approver enroll tokens
- strazactl approvers: Inspect and revoke enrolled approver phones and browsers
- strazactl apps: Manage MCP servers
- strazactl assign: Assign a role to a user
- strazactl attestation: Manage the managed-install expected-hash registry
- strazactl audit: Query and verify the audit log
- strazactl bindings: List the access rows of roles on servers
- strazactl catalog: Inspect the effective tool catalog
- strazactl connect: Connect your own account or token to an MCP server; no server lists your connections
- strazactl devices: Inspect and revoke a user’s enrolled devices
- strazactl disconnect: Remove a connection to a server: your own, or another user’s with --user
- strazactl drafts: Check, store, review and publish drafts of changes to MCP servers, roles, access rows and policy sets
- strazactl login: Log in via the OIDC device flow and start a strazactl session
- strazactl logout: End this machine’s strazactl session: revoke it, then delete the stored credentials
- strazactl packs: Manage knowledge packs
- strazactl policy: Validate and manage PolicySets
- strazactl roles: Manage roles
- strazactl sessions: Inspect and revoke sessions
- strazactl signing-keys: List, rotate and retire signing keys
- strazactl sinks: Inspect SIEM sinks and replay parked (dead-letter) events
- strazactl spec: Work with the Straza spec artifacts
- strazactl status: Report the resolved target server, then strazad health and version
- strazactl transcripts: Search recorded conversations by text or by a secret’s value
- strazactl unassign: Take a role away from a user
- strazactl users: Manage users
- strazactl version: Print version information