The whole platform, from your terminal
Chat with any API, ship a proxy in one command, sidecar a Next.js app, tunnel localhost — and manage every setting, tenant, group and domain without leaving the shell. Allow agents to create and maintain proxies using the CLI.
- No signup for apichat, create, init or dev
- Node 18+ — works with npx, no install
- Scriptable with --json · add --verbose to see the exact API calls
$ npx apiblaze apichat --target pokeapi_openapi.yaml
✓ proxy live → https://pokeapi4821.tryabz.run/1.0.0/prod
✓ MCP server → pokeapi4821.mcp.apiblaze.com
you › what types is ditto?
GET /api/v2/pokemon/ditto → 200 64ms
agent › Ditto is a Normal-type Pokémon.
you › ▍
60-second quickstart
# 1 — chat with any API (spec in, chat out — no signup)
$ npx apiblaze apichat --target https://…/openapi.yaml
# 2 — or just put a proxy in front of any URL (callers sign in with GitHub; add --apikey for keys)
$ npx apiblaze create --target https://api.example.com
# 3 — building a Next.js app? sidecar it
$ npx apiblaze init
# 4 — claim everything to your account when ready
$ npx apiblaze login && npx apiblaze claim
Command reference
Grouped exactly like apiblaze --help. Every command supports --help and most support --verbose.
Chat
Talk to your API — and chat your way to configuration.
$ npx apiblaze apichat --target <server|spec-file|spec-url>Turn any API into a chat. --target is smart: give it a server base URL (the spec is auto-discovered), a local OpenAPI file, or a remote OpenAPI URL — it detects which and starts asking questions. No login needed — it creates a live proxy + MCP server (Claude/ChatGPT-connectable via GitHub sign-in), then every answer shows the real call it made. Logged in, access defaults to invite-only (just you + emails you pre-approve); anonymous proxies stay open.
$ npx apiblaze agentChat with an assistant that builds and runs your APIs — describe what you want and it makes the calls (billed per turn).
$ npx apiblaze agent openapi <project>Interactive OpenAPI designer. Reviews captured traffic, proposes spec patches, then /publish — or opens a GitHub PR back to your repo.
$ npx apiblaze agent authz <project>Interactive access-rules designer. Drafts who-can-do-what rules per route; publishes watch-only, /enable to enforce.
$ npx apiblaze agent mcp <project>Interactive MCP catalogue designer. Pick which routes become tools, then /publish to {project}-{tenant}.mcp.apiblaze.com.
$ npx apiblaze llm set-keyOptional: store your own LLM provider key locally (OpenRouter / Anthropic / DeepSeek / OpenAI) — lifts chat model quality, bills your key.
Setup
Live in one command — no signup needed.
$ npx apiblaze create --target https://api.example.comCreate a proxy — no login needed. Callers sign in with GitHub by default (OAuth — no API key is minted); pass --apikey to protect it with keys and print them instead. Given an OpenAPI spec it also asks whether to prevent unauthorized users from taking unauthorized actions (default yes): only the person who created a thing, or an admin, can change it. It works immediately and prints your live endpoint, a ready-to-run try-it and a claim link: open that link later to create an account and keep the proxy (otherwise it’s cleaned up after 72h with no traffic).
$ npx apiblaze create --target https://petstore3.swagger.io/api/v3/openapi.jsonThe SAME --target flag, given a spec instead of a bare URL — it detects OpenAPI files and URLs automatically. Your routes, the API version and one environment per `servers` entry all come from the spec.
$ npx apiblaze create --target https://api.example.com --autoZero prompts, start to finish — for scripts, CI, and one-liners. Same answers as the interactive run: sign-in door, every ownership rule on, admin step printed as a command to run later. With no --name it generates one from the target host (api.example.com → apiexample7k3x), takes every confirmation as yes and auto-picks the tenant. Needs no TTY. With --json, a sign-in proxy reports api_key: null — there is none.
$ npx apiblaze create --target https://api.example.com --oauth '{"provider":"google","clientId":"…","clientSecret":"…"}'The sign-in door, three shapes: bare --oauth = the APIblaze-hosted GitHub sign-in (managed — what you get with no flag at all); '{"iss","aud","jwks"}' = trust YOUR hosted login's JWTs; '{"provider","clientId","clientSecret"}' = the APIblaze-hosted login page with YOUR OAuth app (github · google · microsoft · facebook · auth0).
$ npx apiblaze initSet up the sidecar in a Next.js app: every external call your app makes surfaces in the dev console; approve one and it routes through APIblaze with zero code changes.
$ npx apiblaze sidecar approve <origin>Route an origin through APIblaze (creates its proxy). deny dismisses a candidate; remove un-routes it and deletes the proxy.
$ npx apiblaze dev 3000Put your localhost behind a public URL and stream every request in real time. Auto-creates a proxy if you don’t have one; captures requests even before your server is up.
$ npx apiblaze loginDevice-flow login (via GitHub). Opens your browser, stores your token and active team.
$ npx apiblaze claim [code]Keep what you built while logged out: attaches those proxies (and their keys & settings) to your account. Omit the code on the machine you created them from; --team puts them in an existing team instead of a new one.
$ npx apiblaze team [name|id]Switch the active team (prompts if you have more than one).
$ npx apiblaze whoamiShow who you are — both API Producer and API Consumer identities — plus active team and token expiry.
$ npx apiblaze logoutSign out (asks whether to drop the Producer or Consumer login).
Control plane
Managing what you built: settings, customer workspaces (tenants), groups, domains.
$ npx apiblaze config [project] [key] [value]Browse and change EVERY proxy setting & feature — interactive menu with no arguments, git-config-style get/set with them (e.g. config myapi throttling.proxyQuota 10000). Works logged-out to explore.
$ npx apiblaze projectsList every project in your active team.
$ npx apiblaze tenantManage tenants — the workspaces your consumers live in. Bare command opens the interactive picker (settings, app clients, providers).
$ npx apiblaze groupManage a tenant’s users & groups — create, nest a group inside a group, add users. Bare command lists groups; group users shows the directory + identities seen in traffic.
$ npx apiblaze apikeys mint --tenant <slug> --for <email>Issue an API key to a named person: calls made with it count as that person, and ownership rules trust it. Without --for it is a plain consumer key for the tenant (your backend then says who is calling with X-End-User-Id); without --tenant it is a control-plane key for your team.
$ npx apiblaze admins add <email> --tenant <slug>Crown a tenant’s admins for the Users & Groups widget — the widget authorizes the signed-in user and seals its admin list, so the FIRST admin is seeded here by the key holder. Accepts the widget’s tenant ref (e.g. nino) or the real tenant name.
$ npx apiblaze iam <project> on|offTurn users & groups on for a proxy’s tenant: identified calls (X-End-User-Id, a login token, or a per-user key) get their user’s groups applied — group rules and per-user limits take effect. Off = calls pass with no group resolution.
$ npx apiblaze identified <project> require|allow-anonRequire every call to say which person it’s for. require rejects unattributed calls loudly (403) instead of silently passing them with no groups — the credential says which app is calling; identity says which person it acts for. allow-anon lifts it.
$ npx apiblaze preapprove <email|domain>Allow someone to sign in to an access-restricted API — one email (someone@acme.com) or a whole company domain (acme.com = anyone @acme.com). Rules are tenant-wide and pair with an API set to “pre-approved users only” (the same control as apichat’s invite mode). --list shows the allow-list; --remove drops an entry.
$ npx apiblaze rule "<plain English>" <project>Write an access rule in one shot — e.g. "users see only their own rows". Starts watch-only (reports what it would block, blocks nothing); --enforce turns it on (billed per turn). Run it with just the project — npx apiblaze rule <project> — to review the ownership rules read from your spec as a checkbox list: no sentence, no AI turn, works logged-out.
$ npx apiblaze domain add <project>Use your own domain: add shows the DNS records to set; status tracks validation & TLS; set-base picks which version/environment your main URL serves.
$ npx apiblaze target <project> --url <url>Change where a proxy forwards requests — per environment with --env.
$ npx apiblaze throttle <project>Set rate limits and quotas: per-user and per-end-user requests/second, plus a proxy-wide quota.
$ npx apiblaze spec get <project>Print the current OpenAPI document; spec set replaces it from a local file. (To build one by chatting: apiblaze agent openapi.)
$ npx apiblaze rename <project> --display-name <name>Change a proxy’s display name.
$ npx apiblaze export <project> --kongMigrate out: export config and data as a runnable Kong OSS bundle (decK config + plugins + docker-compose). Consumers keep their existing keys via hash export.
$ npx apiblaze delete <project>Delete a proxy and everything under it (asks first).
Data plane
Act as a consumer of your own (or anyone’s) API.
$ npx apiblaze consumer loginLog in to a tenant’s portal as a consumer (device flow).
$ npx apiblaze consumer apikeysList your consumer API keys (reveals expiring ones), then offer to create one.
$ npx apiblaze consumer tokensShow the logged-in consumer access / refresh / id tokens.