---
name: suppa-cli
description: Use when working with a Suppa 2.0 tenant from a terminal — tasks, records, entities, custom fields, docs, forms, automations, file attachments. The `suppa` command carries all 99 operations with browser-based login and token storage in the OS keychain. Prefer it over hand-written HTTP calls: validates arguments before sending and explains platform refusals.
---

# Suppa 2.0 from the shell

```
suppa                       groups and counts
suppa help <group>          the commands in one group
suppa help <command>        full description and flags
suppa use-tenant --tenant <alias>   point every later command at a tenant
suppa login                 opens a browser; tokens go to the OS keychain
```

Never ask the user for a token: `suppa login` is the way in.

JSON, non-ASCII text or typed numbers go through `--args-file <path>` (a JSON
object of arguments) or `--args-stdin` — never through quoted inline JSON, which
PowerShell rewrites silently. `--tenant <alias>` points one call elsewhere
without remembering it; `--pretty` re-indents the answer. Exit codes: `0` done,
`1` the tool or the platform refused, or the answer says the work is not done
(`passed: false`, `created: false`, a non-zero `failed`), `2` refused before
anything was sent. A flag's value is never guessed: numbers are plain decimals,
`--context-value 007` stays the text `007`, and a flag that would swallow the
next flag is refused.

Writes are gated — an update, move, close or delete does nothing without
`--confirm`. Show the user what will change, get their word, then re-run with it.

Custom field values ride on the owner record under `customFields`, never as
top-level keys. `suppa resolve-custom-fields` says which are live for a record
and what type each one takes.
