Skip to main content

Level CLI Reference

Reference for lvl command groups, output formats, pagination, resource references, and safety behavior.

Use this article as a map of the Level CLI command tree. For the exact flags and JSON output shape in your installed version, use normal help or the generated skill reference:

lvl --help
lvl skill describe

For example:

lvl device list --help
lvl skill describe device list

Command syntax

The general form is:

lvl [--profile ] [arguments] [flags]

Show the top-level command list:

lvl --help

Show every generated reference entry:

lvl skill describe

Profiles and authentication

Level CLI includes a built-in prod profile for https://api.level.io.

Profile selection follows this order:

  1. The root --profile flag.

  2. The LVL_PROFILE environment variable.

  3. The saved default profile.

  4. The built-in prod profile.

Common commands:

Command

Purpose

lvl auth login

Sign in through a browser-based approval flow.

lvl auth status

Verify the active session and organization.

lvl auth logout

Revoke the active session and remove local credentials.

lvl profile list

List configured API-server profiles.

lvl profile create <name> <url>

Add a profile. Use --default to select it immediately.

lvl profile use <profile>

Set the default profile.

lvl profile delete <profile>

Remove local profile configuration and credentials.

⚠️ WARNING: Deleting a profile does not revoke its server-side session. Run lvl --profile <profile> auth logout before deleting it.

CLI updates

Release builds keep themselves current by default. When you run a normal lvl command, the CLI applies any previously discovered signed update and reruns the command with the new binary. If no update is pending, it checks for one in the background and can apply it on the next invocation. Automatic update failures do not stop the command you asked lvl to run.

Command

Purpose

lvl self-update

Check for and install the latest published build immediately. This works even when automatic updates are disabled.

lvl self-update --check

Report whether an update is available without installing it.

lvl self-update url

Show the release URL currently used for updates.

lvl self-update url <url>

Save a custom release URL in ~/.lvl/config.yaml.

lvl self-update url --reset

Remove the custom URL and return to the built-in production source.

Set auto_update: false in ~/.lvl/config.yaml to disable automatic checks and startup updates. You can still run lvl self-update manually.

Output formats

Most commands display a human-readable table or summary by default.

Use JSON output:

lvl device list -o json

Use the built-in jq filter:

lvl device list --jq '.list[] | {id, name, online}'

--jq implies JSON. It cannot be combined with explicit table output.

CSV export commands write raw CSV to standard output:

lvl device export > devices.csv
lvl alert export > alerts.csv
lvl run export > runs.csv

Automation and monitor-policy specification commands use --format yaml|json, with YAML as the default. They do not use the standard -o flag for the specification itself.

Pagination

Most resource list commands support:

Flag

Behavior

--limit <count>

Return up to the requested number of records. The default is 100.

--limit all

Fetch every result page.

--page <number>

Return a 1-based page.

--limit all cannot be combined with --page.

Paginated commands include alert, automation, automation-trigger, device, file, monitor, monitor-policy, run, script, tag, update, update-summary, update-device, update-log, and update-exclusion lists.

API keys, groups, custom fields, profiles, and variables use unpaginated lists.

In JSON list output, count is the total number of matching server records, not the number returned on the current page.

Resource references

Many commands accept an ID or a human-readable reference. An exact ID match takes priority. Name and alias matching is case-insensitive.

Common forms include:

Resource

Accepted references

Device

ID, hostname, name, nickname, or <group>/<hostname>

Device group

ID, name, or nested path such as Ops/Maintenance

Automation

ID or name

Script

ID or name

Repository file

ID or filename, with or without its extension

Monitor policy

ID or name

Tag

Name

Custom field

Name or generated reference

Update exclusion

ID or KB number, with or without the KB prefix

If a reference matches more than one resource, the CLI stops and lists the candidates instead of choosing one.

Alert commands

Command

Purpose

alert list

List active, resolved, or all alerts.

alert get <alert-id>

Get one alert.

alert resolve

Resolve alerts by ID or filters.

alert unresolve <alert-id>...

Reopen resolved alerts by ID.

alert export

Export matching alerts as CSV.

API key commands

Command

Purpose

apikey list

List API keys.

apikey get <api-key>

Get one API key. Use --reveal to show the full token in table output.

apikey create

Create a read-only or read-and-write API key.

apikey update <api-key>

Update an API key.

apikey delete <api-key>...

Permanently delete API keys.

⚠️ WARNING: API key JSON output contains the full token. Protect terminal output, exported files, and CI logs.

Automation commands

Command

Purpose

automation list

List automations.

automation get <automation>

Get one automation.

automation create

Create an automation from flags or a specification file.

automation spec <automation>

Export an automation specification.

automation apply -f <spec>

Reconcile an existing automation with a specification.

automation update <automation>

Update automation properties.

automation delete <automation>...

Archive automations.

automation restore <automation>...

Restore archived automations.

automation run <automation>

Run an automation on devices or groups.

automation trigger ...

List, add, update, delete, or manually run triggers.

automation action ...

Add, update, or delete actions.

automation variable ...

Manage automation variables.

automation group ...

Manage automation groups.

Status values:

  • automation list reports active when an automation has at least one enabled trigger, manual when it has no enabled triggers, and archived when it is archived.

  • automation trigger list reports active for an enabled trigger and disabled for a trigger that is not enabled.

  • Automation execution is controlled by trigger state. The legacy automation-level enabled value does not determine these statuses or whether triggers can start runs.

Trigger and action mutation commands accept --json or --json-file. The payload must contain exactly one supported type, and unknown fields are rejected.

Run lvl automation action --help or lvl skill describe automation action for the action types supported by your installed version.

⚠️ WARNING:automation apply can delete triggers and actions that are absent from the specification. The apply is not transactional. Run with --dry-run and review the plan first.

Application commands

Use these commands to review the organization-wide application inventory and drill down to versions or individual installs.

Command

Purpose

app list

List one aggregated row per application name, publisher, and platform. Supports pagination.

app summary

Show application and install counts, including application counts by platform, for the filtered scope.

app versions <app>

List versions of one application with install and device counts.

app installs [<app>]

List individual installs of one application, or omit <app> and pass exactly one --device to list that device's complete application inventory. Supports pagination.

app uninstall [<app>...]

Send uninstall commands for selected application installs. Positional application references are equivalent to repeatable --app flags.

File uploads

Upload one or more local files to the Level file repository:

lvl file upload <path>...

By default, lvl uses the local filename. To choose a custom name for one file, use --name without an extension:

lvl file upload <path> --name <name>

The file extension always comes from the local file. The --name option applies to a single file only.

Did this answer your question?