Use this article as a map of the Level CLI command tree. For the exact flags and JSON output shape in your installed version, use normal help or the generated skill reference:
lvl --help
lvl skill describe
For example:
lvl device list --help
lvl skill describe device list
Command syntax
The general form is:
lvl [--profile ] [arguments] [flags]
Show the top-level command list:
lvl --help
Show every generated reference entry:
lvl skill describe
Profiles and authentication
Level CLI includes a built-in prod profile for https://api.level.io.
Profile selection follows this order:
The root
--profileflag.The
LVL_PROFILEenvironment variable.The saved default profile.
The built-in
prodprofile.
Common commands:
Command | Purpose |
| Sign in through a browser-based approval flow. |
| Verify the active session and organization. |
| Revoke the active session and remove local credentials. |
| List configured API-server profiles. |
| Add a profile. Use |
| Set the default profile. |
| Remove local profile configuration and credentials. |
⚠️ WARNING: Deleting a profile does not revoke its server-side session. Run lvl --profile <profile> auth logout before deleting it.
CLI updates
Release builds keep themselves current by default. When you run a normal lvl command, the CLI applies any previously discovered signed update and reruns the command with the new binary. If no update is pending, it checks for one in the background and can apply it on the next invocation. Automatic update failures do not stop the command you asked lvl to run.
Command | Purpose |
| Check for and install the latest published build immediately. This works even when automatic updates are disabled. |
| Report whether an update is available without installing it. |
| Show the release URL currently used for updates. |
| Save a custom release URL in |
| Remove the custom URL and return to the built-in production source. |
Set auto_update: false in ~/.lvl/config.yaml to disable automatic checks and startup updates. You can still run lvl self-update manually.
Output formats
Most commands display a human-readable table or summary by default.
Use JSON output:
lvl device list -o json
Use the built-in jq filter:
lvl device list --jq '.list[] | {id, name, online}'--jq implies JSON. It cannot be combined with explicit table output.
CSV export commands write raw CSV to standard output:
lvl device export > devices.csv
lvl alert export > alerts.csv
lvl run export > runs.csv
Automation and monitor-policy specification commands use --format yaml|json, with YAML as the default. They do not use the standard -o flag for the specification itself.
Pagination
Most resource list commands support:
Flag | Behavior |
| Return up to the requested number of records. The default is 100. |
| Fetch every result page. |
| Return a 1-based page. |
--limit all cannot be combined with --page.
Paginated commands include alert, automation, automation-trigger, device, file, monitor, monitor-policy, run, script, tag, update, update-summary, update-device, update-log, and update-exclusion lists.
API keys, groups, custom fields, profiles, and variables use unpaginated lists.
In JSON list output, count is the total number of matching server records, not the number returned on the current page.
Resource references
Many commands accept an ID or a human-readable reference. An exact ID match takes priority. Name and alias matching is case-insensitive.
Common forms include:
Resource | Accepted references |
Device | ID, hostname, name, nickname, or |
Device group | ID, name, or nested path such as |
Automation | ID or name |
Script | ID or name |
Repository file | ID or filename, with or without its extension |
Monitor policy | ID or name |
Tag | Name |
Custom field | Name or generated reference |
Update exclusion | ID or KB number, with or without the |
If a reference matches more than one resource, the CLI stops and lists the candidates instead of choosing one.
Alert commands
Command | Purpose |
| List active, resolved, or all alerts. |
| Get one alert. |
| Resolve alerts by ID or filters. |
| Reopen resolved alerts by ID. |
| Export matching alerts as CSV. |
API key commands
Command | Purpose |
| List API keys. |
| Get one API key. Use |
| Create a read-only or read-and-write API key. |
| Update an API key. |
| Permanently delete API keys. |
⚠️ WARNING: API key JSON output contains the full token. Protect terminal output, exported files, and CI logs.
Automation commands
Command | Purpose |
| List automations. |
| Get one automation. |
| Create an automation from flags or a specification file. |
| Export an automation specification. |
| Reconcile an existing automation with a specification. |
| Update automation properties. |
| Archive automations. |
| Restore archived automations. |
| Run an automation on devices or groups. |
| List, add, update, delete, or manually run triggers. |
| Add, update, or delete actions. |
| Manage automation variables. |
| Manage automation groups. |
Status values:
automation listreportsactivewhen an automation has at least one enabled trigger,manualwhen it has no enabled triggers, andarchivedwhen it is archived.automation trigger listreportsactivefor an enabled trigger anddisabledfor a trigger that is not enabled.Automation execution is controlled by trigger state. The legacy automation-level
enabledvalue does not determine these statuses or whether triggers can start runs.
Trigger and action mutation commands accept --json or --json-file. The payload must contain exactly one supported type, and unknown fields are rejected.
Run lvl automation action --help or lvl skill describe automation action for the action types supported by your installed version.
⚠️ WARNING:automation apply can delete triggers and actions that are absent from the specification. The apply is not transactional. Run with --dry-run and review the plan first.
Application commands
Use these commands to review the organization-wide application inventory and drill down to versions or individual installs.
Command | Purpose |
| List one aggregated row per application name, publisher, and platform. Supports pagination. |
| Show application and install counts, including application counts by platform, for the filtered scope. |
| List versions of one application with install and device counts. |
| List individual installs of one application, or omit |
| Send uninstall commands for selected application installs. Positional application references are equivalent to repeatable |
File uploads
Upload one or more local files to the Level file repository:
lvl file upload <path>...
By default, lvl uses the local filename. To choose a custom name for one file, use --name without an extension:
lvl file upload <path> --name <name>
The file extension always comes from the local file. The --name option applies to a single file only.
