Metadata-Version: 2.5
Name: trustarc-cli
Version: 1.0.2
Summary: Command-line interface for the TrustArc platform APIs
Project-URL: Homepage, https://trustarc.com
Author: TrustArc
Keywords: cli,compliance,privacy,trustarc
Classifier: Environment :: Console
Classifier: Intended Audience :: Developers
Classifier: Operating System :: OS Independent
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3.14
Requires-Python: >=3.14
Requires-Dist: httpx>=0.28.1
Requires-Dist: inflection>=0.5.1
Requires-Dist: packaging>=24
Requires-Dist: rich>=13.0
Requires-Dist: typer>=0.12
Description-Content-Type: text/markdown

# trustarc-cli

`ta` is the command-line interface for the TrustArc platform APIs. Commands are built from each product's live API spec, so new endpoints show up without upgrading the CLI.

Use it directly from your terminal, in scripts, or as a tool for AI agents such as Claude Code, Codex and Cursor.

## Install

With [uv](https://docs.astral.sh/uv/getting-started/installation/) (installs Python 3.14 for you if needed):

```bash
uv tool install trustarc-cli
```

Or with [pipx](https://pipx.pypa.io) (requires Python 3.14+):

```bash
pipx install trustarc-cli
```

## Update

```bash
ta self-update
```

`ta` checks for a new release once a day and prints a notice to stderr when one is available. Set `TA_NO_UPDATE_CHECK=1` to turn the check off (e.g. in CI).

## Quick start

```bash
ta config setup --env prod-us     # your region: prod-us, prod-eu or prod-in
ta auth login                     # OAuth login via browser (PKCE)
ta services                       # list configured services for this env
ta dmrm business-process list     # example call
```

## Use with AI agents

`ta` is built to be driven by an AI agent as well as by a person:

- API responses are printed as JSON on stdout, and the update notice goes to stderr, so output can be parsed as-is.
- `--help` and `--schema` let the agent discover operations and their request/response shapes without calling the API.
- Log in once with `ta auth login`; the agent reuses the saved token.

`ta` is new, so agents don't know it yet. Add this line once to the instructions file your agent reads on every session (`CLAUDE.md` for Claude Code, `AGENTS.md` for Codex, Cursor and most other agents):

```markdown
Use the `ta` CLI for anything in TrustArc (run `ta --help` to find commands).
```

Then ask the way you normally would:

> How many business processes do we have in TrustArc?

> Which vendors have high risk scores?

> Show me the data subject requests that are overdue.

> Add Acme Corp as a third party.

For a create, update or delete, the agent sees in `--help` that the command changes data and should confirm with you before running it.

## Command tree

```
ta
├── auth
│   ├── login                       # OAuth login (browser + PKCE)
│   ├── logout                      # revoke + clear local tokens
│   └── status                      # current token expiry / user
├── config
│   ├── show                        # current env + login state
│   ├── setup                       # pick region
│   └── reset                       # delete ~/.ta/config.json
├── services                        # list all services for the current env
├── files
│   └── upload <path>               # upload a file, print its file_url
├── self-update                     # upgrade to the latest release
└── <service>                       # e.g. dmrm, tc, am, cpm, ccm, irm, pc, cst, evidence, org
    ├── refresh                     # re-fetch this service's OpenAPI spec
    └── <resource>                  # e.g. business-process, trust-center
        └── <action> [args]         # e.g. list, get-by-internal-id, upsert
```

### Inspecting operations

```bash
ta <service> --help                     # list resources
ta <service> <resource> --help          # list actions
ta <service> <resource> <action> --help # show args/options
ta <service> <resource> <action> --schema   # request/response schema (no API call)
```

### Passing arguments

- **Path params** → positional: `ta dmrm business-process get-by-internal-id <id>`
- **Query params** → `--flag`: `ta tc subscription list --since 2026-01-01`
- **Body** → `--body '<json>'`: `ta dmrm business-process upsert --body '{"internalId":"...","name":"..."}'`
- **Files** → upload first, then put the `file_url` in the body field that takes it (see `--schema`): `URL=$(ta files upload -q ./policy.pdf)`

### Regions and auth

Tokens are stored per env at `~/.ta/auth/<env>.json`. Spec caches at `~/.ta/openapi/<env>/<service>.json` (10-minute TTL; auto-refreshed when stale).

Switch region:

```bash
ta config setup --env prod-eu  # change default region
ta auth login --env prod-eu    # log into a specific region without changing default
```
