Skip to main content

The dealdesk command line tool

One file, no dependencies, Node.js 18 or later. Install it straight from Deal Desk:

npm install -g https://app.dealdesk.studio/cli/dealdesk-cli.tgz # puts `dealdesk` on your PATH
dealdesk --help

It will also be published on npm as @dealdesk/cli; the command above keeps working.

Signing in​

dealdesk login

The command shows a short code and opens https://app.dealdesk.studio/cli. Sign in as an account owner or admin, check that the code matches, and approve. The tool receives a new key of its own ("CLI on your computer") and saves it in ~/.config/dealdesk/credentials.json, readable only by you. No key ever appears in a URL. dealdesk logout revokes that key.

For CI and scripts, set DEALDESK_API_KEY, or save a key with dealdesk login --key ddk_live_.... DEALDESK_API_KEY in the environment wins over a saved key. dealdesk logout forgets a saved key without revoking it unless you add --revoke.

Commands​

dealdesk whoami
dealdesk library search "past performance with NGA"
dealdesk library add capabilities.pdf
dealdesk teach "We are ISO 9001 certified since 2021."
dealdesk facts list
dealdesk draft --notes call-notes.txt # or: pbpaste | dealdesk draft --notes -
dealdesk proposals list
dealdesk proposals pdf DD-2026-0042 -o proposal.pdf
dealdesk rfp upload RFP-2026-14.docx --wait
dealdesk rfp draft <id> --all --wait
dealdesk rfp requirements <id> --needs-input
dealdesk rfp export <id> # the original .docx, filled in
dealdesk mcp # setup for every MCP client, with your key
dealdesk mcp install claude-code

The full set:

CommandWhat it does
dealdesk whoamiThe account, plan and key in use.
dealdesk library listDocuments in the library.
dealdesk library search "<question>"Passages that answer a question, with citations.
dealdesk library add <file>Add a .docx, .pdf or text file to the library.
dealdesk teach "<fact>"Tell Deal Desk a fact about the company.
dealdesk facts listThe facts taught so far.
dealdesk facts remove <id>Remove a fact.
dealdesk draft --notes <file>Draft a proposal from notes (- reads standard input).
dealdesk proposals listProposals, newest first.
dealdesk proposals get <number>One proposal.
dealdesk proposals pdf <number> -o <file>Download a proposal as a PDF.
dealdesk rfp upload <file> --waitUpload an RFP and wait until it is read.
dealdesk rfp status <id>Reading progress and answer counts.
dealdesk rfp requirements <id> --needs-inputRequirements, optionally only those waiting on a fact.
dealdesk rfp draft <id> --all --waitDraft every open answer; or dealdesk rfp draft <id> <rid> for one.
dealdesk rfp export <id>The original .docx or .xlsx, filled in; --format csv for the compliance matrix.
dealdesk mcpThe MCP setup for every client, with your key filled in.
dealdesk mcp install claude-codeRuns claude mcp add for you (--scope user, project or local).
dealdesk login / dealdesk logoutSign in through the browser; sign out and revoke.

Every command takes --json for scripting. Errors go to standard error; the exit code is 1 for a failed request and 2 for a usage error.

Other servers​

--staging talks to https://app-staging.dealdesk.studio; --base-url <url> (or DEALDESK_BASE_URL) to any other. Keys are saved per server, and a key is only ever sent over HTTPS (plain HTTP is allowed for localhost alone, for running the app locally).

Verify a deployment​

After every deploy, run the smoke check from a checkout of the repository against that stage. It uses the key dealdesk login saved for that server (or DEALDESK_API_KEY), so no key is pasted, and it never prints one:

dealdesk login --staging # once, approved in the browser
node scripts/smoke-developer.mjs --staging # read-only checks
node scripts/smoke-developer.mjs --staging --write # also teach and remove a probe fact, draft a probe proposal
DEALDESK_API_KEY=... node scripts/smoke-developer.mjs --base-url https://app.dealdesk.studio

It checks the OpenAPI document, the account, library list and search, facts, proposals and RFP lists, MCP initialize, tools/list and tools/call, dealdesk whoami --json, that an invalid key gets 401 in the error envelope, and the CORS preflight on /mcp. It prints one line per check with its timing and exits 1 if any check fails. Checks the account's plan does not include are skipped, not failed. Nothing is ever sent.