---
title: "Command reference"
description: "Every ezgh command and flag, generated from ezgh's own help."
---

> Documentation Index
> Fetch the complete documentation index at: https://docs.ezghcloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Command reference

{/* Generated by ezgh-cli's internal/tools/clidocs from the ezgh command tree. Don't edit: change the command's help in ezgh-cli and regenerate. */}

Generated from ezgh-cli commit `0688df41a869c023cba29d669f3057d941276e55`.

## Usage

```sh
ezgh <command> [flags]
```

ezgh manages EZGH Cloud from the command line: organizations and projects, IAM (users, bots, groups, policies, API keys), quotas, the Trails audit log, and OCR.

Log in with `ezgh login` (or `ezgh login --device` without a browser). Machines use an API key from `EZGH_API_KEY` instead. Profiles keep separate logins and settings side by side.

## Global flags

Every command takes these flags, and `-h`, `--help` to print its help.

| Flag | Type | Default | Description |
| --- | --- | --- | --- |
| `--debug` | boolean |  | log each request and answer to stderr (never credentials) |
| `--no-headers` | boolean |  | leave the header row out of tables |
| `--org` | string |  | organization, by ID or slug (default: `EZGH_ORG`, then the profile's) |
| `-o`, `--output` | string |  | output format: table, json or yaml (default: the profile's, else table) |
| `--profile` | string |  | profile to use (default: `EZGH_PROFILE`, then the configured default, then "default") |
| `--project` | string |  | project, by ID, slug or name (default: `EZGH_PROJECT`, then the profile's) |
| `--timeout` | duration | `30s` | how long one request may take |

## Commands

| Command | Description |
| --- | --- |
| [`ezgh auth`](/cli/reference/auth) | Credentials: status, login, logout, API keys for profiles |
| [`ezgh auth login`](/cli/reference/auth-login) | Log in with your EZGH Cloud account (OAuth 2.1) |
| [`ezgh auth logout`](/cli/reference/auth-logout) | Log out: revoke the profile's login and forget its credential |
| [`ezgh auth set-api-key`](/cli/reference/auth-set-api-key) | Store an API key as the profile's credential, read from stdin |
| [`ezgh auth status`](/cli/reference/auth-status) | Show which profile and credential commands use |
| [`ezgh completion`](/cli/reference/completion) | Generate the autocompletion script for the specified shell |
| [`ezgh completion bash`](/cli/reference/completion-bash) | Generate the autocompletion script for bash |
| [`ezgh completion fish`](/cli/reference/completion-fish) | Generate the autocompletion script for fish |
| [`ezgh completion powershell`](/cli/reference/completion-powershell) | Generate the autocompletion script for powershell |
| [`ezgh completion zsh`](/cli/reference/completion-zsh) | Generate the autocompletion script for zsh |
| [`ezgh config`](/cli/reference/config) | Read and change the active profile's settings |
| [`ezgh config get`](/cli/reference/config-get) | Print one of the active profile's settings, as configured |
| [`ezgh config list`](/cli/reference/config-list) | List the settings commands run with, and where each comes from |
| [`ezgh config set`](/cli/reference/config-set) | Set one of the active profile's settings |
| [`ezgh config unset`](/cli/reference/config-unset) | Clear one of the active profile's settings |
| [`ezgh iam`](/cli/reference/iam) | Identity and access: users, invitations, bots, groups, policies, API keys, SCIM, actions, permissions |
| [`ezgh iam actions`](/cli/reference/iam-actions) | The IAM actions policies can allow or deny |
| [`ezgh iam actions list`](/cli/reference/iam-actions-list) | List every IAM action: the platform's and each registered product's |
| [`ezgh iam api-keys`](/cli/reference/iam-api-keys) | API keys: credentials for code, acting as a user or bot |
| [`ezgh iam api-keys create`](/cli/reference/iam-api-keys-create) | Create an API key for yourself or a bot; the key is shown once |
| [`ezgh iam api-keys delete`](/cli/reference/iam-api-keys-delete) | Revoke an API key, by ID, name or prefix |
| [`ezgh iam api-keys list`](/cli/reference/iam-api-keys-list) | List API keys, newest first: every key with apiKeys.list, otherwise your own |
| [`ezgh iam bots`](/cli/reference/iam-bots) | Bots: non-human members that act through API keys |
| [`ezgh iam bots create`](/cli/reference/iam-bots-create) | Create a bot: a non-human member that acts through API keys |
| [`ezgh iam bots delete`](/cli/reference/iam-bots-delete) | Delete a bot, and with it its API keys |
| [`ezgh iam bots get`](/cli/reference/iam-bots-get) | Show a bot, by ID, slug or name |
| [`ezgh iam bots list`](/cli/reference/iam-bots-list) | List the organization's bots |
| [`ezgh iam bots update`](/cli/reference/iam-bots-update) | Rename a bot, change its groups, or replace its directly attached policies |
| [`ezgh iam groups`](/cli/reference/iam-groups) | Groups: policies attached to a group apply to all its members |
| [`ezgh iam groups add-members`](/cli/reference/iam-groups-add-members) | Add users or bots to a group |
| [`ezgh iam groups create`](/cli/reference/iam-groups-create) | Create a group |
| [`ezgh iam groups delete`](/cli/reference/iam-groups-delete) | Delete a group (its members lose the access its policies gave them) |
| [`ezgh iam groups get`](/cli/reference/iam-groups-get) | Show a group with its members and policies, by ID, slug or name |
| [`ezgh iam groups list`](/cli/reference/iam-groups-list) | List the organization's groups |
| [`ezgh iam groups remove-members`](/cli/reference/iam-groups-remove-members) | Remove users or bots from a group |
| [`ezgh iam groups update`](/cli/reference/iam-groups-update) | Change a group's name or description, or replace its policies |
| [`ezgh iam invitations`](/cli/reference/iam-invitations) | The organization's invitations (invite with `ezgh iam users invite`) |
| [`ezgh iam invitations get`](/cli/reference/iam-invitations-get) | Show an invitation, with its accept link |
| [`ezgh iam invitations list`](/cli/reference/iam-invitations-list) | List the organization's invitations, newest first |
| [`ezgh iam invitations revoke`](/cli/reference/iam-invitations-revoke) | Revoke a pending invitation |
| [`ezgh iam permissions`](/cli/reference/iam-permissions) | Check what you're allowed to do |
| [`ezgh iam permissions check`](/cli/reference/iam-permissions-check) | Check whether you may do actions, on the organization or a resource |
| [`ezgh iam policies`](/cli/reference/iam-policies) | Policies: what users, bots and groups may do |
| [`ezgh iam policies attach`](/cli/reference/iam-policies-attach) | Attach a policy to a user, bot or group |
| [`ezgh iam policies create`](/cli/reference/iam-policies-create) | Create a custom policy |
| [`ezgh iam policies delete`](/cli/reference/iam-policies-delete) | Delete a custom policy |
| [`ezgh iam policies detach`](/cli/reference/iam-policies-detach) | Detach a policy from a user, bot or group |
| [`ezgh iam policies get`](/cli/reference/iam-policies-get) | Show a policy and its document: a managed policy's name, or a custom one's ID, slug or name |
| [`ezgh iam policies list`](/cli/reference/iam-policies-list) | List managed and custom policies |
| [`ezgh iam policies update`](/cli/reference/iam-policies-update) | Change a custom policy's name, description or document |
| [`ezgh iam scim`](/cli/reference/iam-scim) | SCIM provisioning: your identity provider manages people and groups |
| [`ezgh iam scim status`](/cli/reference/iam-scim-status) | Show whether SCIM provisioning is on, its base URL, and what it provisioned |
| [`ezgh iam scim tokens`](/cli/reference/iam-scim-tokens) | SCIM tokens: what your identity provider authenticates with |
| [`ezgh iam scim tokens create`](/cli/reference/iam-scim-tokens-create) | Create a SCIM token for your identity provider; the token is shown once |
| [`ezgh iam scim tokens delete`](/cli/reference/iam-scim-tokens-delete) | Delete a SCIM token, by ID, name or prefix; deleting the last one turns SCIM off |
| [`ezgh iam scim tokens list`](/cli/reference/iam-scim-tokens-list) | List the organization's SCIM tokens |
| [`ezgh iam users`](/cli/reference/iam-users) | Users: the organization's people |
| [`ezgh iam users get`](/cli/reference/iam-users-get) | Show a user, by user ID or email |
| [`ezgh iam users invite`](/cli/reference/iam-users-invite) | Invite someone into the organization; prints the accept link |
| [`ezgh iam users list`](/cli/reference/iam-users-list) | List the organization's users |
| [`ezgh iam users remove`](/cli/reference/iam-users-remove) | Remove someone from the organization: their groups and policies go, and their API keys are revoked |
| [`ezgh iam users update`](/cli/reference/iam-users-update) | Change the groups a user is in, or replace the policies attached to them directly |
| [`ezgh invitations`](/cli/reference/invitations) | Your own invitations into organizations (needs a login, not an API key) |
| [`ezgh invitations accept`](/cli/reference/invitations-accept) | Accept an invitation, joining its organization |
| [`ezgh invitations decline`](/cli/reference/invitations-decline) | Decline an invitation |
| [`ezgh invitations get`](/cli/reference/invitations-get) | Show one of your invitations |
| [`ezgh invitations list`](/cli/reference/invitations-list) | List your pending invitations |
| [`ezgh login`](/cli/reference/login) | Log in with your EZGH Cloud account (OAuth 2.1) |
| [`ezgh logout`](/cli/reference/logout) | Log out: revoke the profile's login and forget its credential |
| [`ezgh ocr`](/cli/reference/ocr) | OCR: the model catalog, processors, and processing documents |
| [`ezgh ocr models`](/cli/reference/ocr-models) | OCR models: what each can read, and its versions |
| [`ezgh ocr models get`](/cli/reference/ocr-models-get) | Show a model: its versions, capabilities and limits |
| [`ezgh ocr models list`](/cli/reference/ocr-models-list) | List the OCR models |
| [`ezgh ocr process`](/cli/reference/ocr-process) | Read the text in a document (PDF, PNG, JPEG, TIFF, WebP) with a processor |
| [`ezgh ocr processors`](/cli/reference/ocr-processors) | OCR processors: a model and its settings, in a project (`--project`) |
| [`ezgh ocr processors create`](/cli/reference/ocr-processors-create) | Create a processor: a model and its settings, to process documents with |
| [`ezgh ocr processors delete`](/cli/reference/ocr-processors-delete) | Delete a processor |
| [`ezgh ocr processors disable`](/cli/reference/ocr-processors-disable) | Disable a processor: processing with it is refused until it's enabled |
| [`ezgh ocr processors enable`](/cli/reference/ocr-processors-enable) | Enable a disabled processor |
| [`ezgh ocr processors get`](/cli/reference/ocr-processors-get) | Show a processor, by ID, slug or name |
| [`ezgh ocr processors list`](/cli/reference/ocr-processors-list) | List the project's OCR processors, newest first |
| [`ezgh ocr processors update`](/cli/reference/ocr-processors-update) | Change a processor's name or settings |
| [`ezgh orgs`](/cli/reference/orgs) | Organizations |
| [`ezgh orgs get`](/cli/reference/orgs-get) | Show an organization (default: the active one), by ID or slug |
| [`ezgh orgs leave`](/cli/reference/orgs-leave) | Leave the organization: your groups, policies and API keys there go |
| [`ezgh orgs list`](/cli/reference/orgs-list) | List the organizations you belong to |
| [`ezgh profiles`](/cli/reference/profiles) | Profiles: separate logins and settings (work and CI, several organizations) |
| [`ezgh profiles create`](/cli/reference/profiles-create) | Create a profile |
| [`ezgh profiles delete`](/cli/reference/profiles-delete) | Delete a profile: log it out (revoking its login) and remove its settings and keychain entry |
| [`ezgh profiles list`](/cli/reference/profiles-list) | List profiles with their domain, identity, and whether their login still works |
| [`ezgh profiles rename`](/cli/reference/profiles-rename) | Rename a profile, moving its credential |
| [`ezgh profiles use`](/cli/reference/profiles-use) | Make a profile the default |
| [`ezgh projects`](/cli/reference/projects) | Projects |
| [`ezgh projects create`](/cli/reference/projects-create) | Create a project |
| [`ezgh projects delete`](/cli/reference/projects-delete) | Delete a project |
| [`ezgh projects get`](/cli/reference/projects-get) | Show a project (default: the active one), by ID, slug or name |
| [`ezgh projects list`](/cli/reference/projects-list) | List the organization's projects |
| [`ezgh projects update`](/cli/reference/projects-update) | Rename a project |
| [`ezgh quotas`](/cli/reference/quotas) | Service quotas: how much of each product the organization may have or use |
| [`ezgh quotas get`](/cli/reference/quotas-get) | Show one quota, with the value and usage of each scope (project, resource) it has |
| [`ezgh quotas list`](/cli/reference/quotas-list) | List the organization's quotas, with values and usage |
| [`ezgh trails`](/cli/reference/trails) | Trails, the audit log: look up events, or query them with SQL |
| [`ezgh trails events`](/cli/reference/trails-events) | Look up events, newest first (the last 7 days unless `--from` says otherwise) |
| [`ezgh trails events get`](/cli/reference/trails-events-get) | Show one event in full |
| [`ezgh trails query`](/cli/reference/trails-query) | Trails Query: SQL over the organization's events, run asynchronously |
| [`ezgh trails query cancel`](/cli/reference/trails-query-cancel) | Cancel a queued or running query |
| [`ezgh trails query get`](/cli/reference/trails-query-get) | Show a query's status |
| [`ezgh trails query list`](/cli/reference/trails-query-list) | List query history, newest first (everyone's with audit.queries.list, else your own) |
| [`ezgh trails query results`](/cli/reference/trails-query-results) | Print a finished query's rows, or download them as CSV or JSON Lines |
| [`ezgh trails query run`](/cli/reference/trails-query-run) | Run a query: wait for it and print its rows as they're read |
| [`ezgh trails query schema`](/cli/reference/trails-query-schema) | List the trails table's columns (and, with -o json, the functions queries may use) |
| [`ezgh version`](/cli/reference/version) | Print ezgh's version, commit and build date |
| [`ezgh whoami`](/cli/reference/whoami) | Ask the platform who you are: user or bot, organization, credential |

Source: https://docs.ezghcloud.com/cli/reference/index.mdx
