---
name: reminix
description: Use when working with Reminix (reminix.com) — reading or changing a workspace in Reminix through its MCP tools, the `reminix` command line or its API. Covers signing in, choosing the workspace, every operation, errors and pagination.
---

# Reminix

Reminix turns scripts and AI-written code into safe, shared team capabilities — each with a UI for people, an API and tool interface for software and agents, and scheduled runs, governed with permissions, secrets, approvals, logs and versions.

Everything belongs to a **workspace**. You act as the person who signed
you in, with their role in that workspace and only the access they
granted — if they could not do something in the app, neither can you.

## Choose how to connect

- **MCP tools** (preferred when your client has them — names like `workspace_get`): the server is `https://mcp.reminix.com/mcp`. Connecting opens the person's browser to sign in, pick ONE workspace and the access. The tools you see are exactly what they allowed.
- **Command line** `reminix` (`npm install -g @reminix/cli`): `reminix login` signs in through the browser; without a browser, the person sets `REMINIX_TOKEN` to a personal access token. Add `--json` to EVERY command: output is the API's JSON, errors are JSON on stderr, exit code 0 means success.
- **HTTP API** `https://api.reminix.com/v1` with `Authorization: Bearer <token>`; the OpenAPI document is `https://api.reminix.com/v1/openapi.json`.

## Rules

- Find the workspace first (`reminix workspace list --json`); pass `--workspace <slug>` or ask the person which one. Never guess a slug.
- Read before you change anything, and say what you will change before you do.
- An operation that cannot be undone (a delete) needs the person's explicit go-ahead — only then pass `--yes`.
- Lists return one page: pass `nextCursor` as `cursor` (`--cursor`) for the next.
- Writes are safe to retry: the CLI sends an `Idempotency-Key`; over HTTP, send your own.
- Errors carry `code` and `message`: `unauthorized` → sign in again; `forbidden` → this sign-in lacks the access or role (tell the person what is missing — never work around it); `rate_limited` → wait for `Retry-After`; `invalid_request` → fix the input from `details`.

## Operations

| Command | MCP tool | What it does |
| --- | --- | --- |
| `reminix capabilities create` | `capabilities_create` | Create a capability |
| `reminix capabilities get <slug>` | `capabilities_get` | Get a capability |
| `reminix capabilities list` | `capabilities_list` | List capabilities |
| `reminix capabilities update <slug>` | `capabilities_update` | Change a capability |
| `reminix capability-settings get` | `capability_settings_get` | Get the workspace's capability settings |
| `reminix capability-versions create <slug>` | `capability_versions_create` | Upload a version |
| `reminix capability-versions list <slug>` | `capability_versions_list` | List a capability's versions |
| `reminix capability-versions publish <slug> <number>` | `capability_versions_publish` | Publish a version |
| `reminix runs create <slug>` | `runs_create` | Run a capability |
| `reminix runs get <id>` | `runs_get` | Get a run |
| `reminix runs list` | `runs_list` | List runs |
| `reminix runs logs <id>` | `runs_logs` | Get a run's log |
| `reminix schedules list <slug>` | `schedules_list` | List a capability's schedules |
| `reminix secrets list` | `secrets_list` | List secrets |
| `reminix triggers list <slug>` | `triggers_list` | List a capability's triggers |
| `reminix user me` | — | Identify the authenticated user |
| `reminix user revoke-token` | — | Revoke the token making this request |
| `reminix workspace approval-actions list` | `workspace_approval_actions_list` | List the actions you can ask approval for |
| `reminix workspace approval-requests create` | `workspace_approval_requests_create` | Ask a person to approve an action |
| `reminix workspace approval-requests get <requestId>` | `workspace_approval_requests_get` | Check an approval request |
| `reminix workspace audit-events list` | `workspace_audit_events_list` | List workspace audit events |
| `reminix workspace event-types list` | `workspace_event_types_list` | List event types |
| `reminix workspace get` | `workspace_get` | Identify the authenticated workspace |
| `reminix workspace invitations list` | `workspace_invitations_list` | List pending invitations |
| `reminix workspace members list` | `workspace_members_list` | List workspace members |
| `reminix workspace teams list` | `workspace_teams_list` | List teams |
| `reminix workspace usage` | `workspace_usage` | Get the workspace's usage this month |
| `reminix workspace webhook-deliveries list <endpointId>` | `workspace_webhook_deliveries_list` | List an endpoint's deliveries |
| `reminix workspace webhook-deliveries redeliver <endpointId> <deliveryId>` | `workspace_webhook_deliveries_redeliver` | Redeliver an event |
| `reminix workspace webhook-endpoints get <endpointId>` | `workspace_webhook_endpoints_get` | Get a webhook endpoint |
| `reminix workspace webhook-endpoints list` | `workspace_webhook_endpoints_list` | List webhook endpoints |
| `reminix workspace webhook-endpoints test <endpointId>` | `workspace_webhook_endpoints_test` | Send a test event |

`reminix <command> --help` lists each command's inputs; `reminix api <method> <path>` calls any endpoint directly.

## For people only

Never do these yourself, even if you could — ask for approval (below) or tell the person to do it in the app, and why:

- Change the workspace's capability settings: Governance settings are a person's to change; an agent must not loosen them
- Schedule a capability: Schedules and triggers run as the person who created them — a person creates and changes them
- Delete a schedule: Schedules and triggers run as the person who created them — a person creates and changes them
- Change a schedule: Schedules and triggers run as the person who created them — a person creates and changes them
- Delete a secret: Secret values are a person's to handle; an agent asks the person to add the secret
- Save a secret: Secret values are a person's to handle; an agent asks the person to add the secret
- Run a capability on an event: Schedules and triggers run as the person who created them — a person creates and changes them
- Delete a trigger: Schedules and triggers run as the person who created them — a person creates and changes them
- Change a trigger: Schedules and triggers run as the person who created them — a person creates and changes them
- Redeem an approved request (command line): Returns a secret; secrets never enter an agent's conversation — the command line writes them to a file.
- Add a webhook endpoint: Changes where workspace data is sent. A person configures webhook endpoints (Settings → Webhooks in the app).
- Remove a webhook endpoint: Changes where workspace data is sent. A person configures webhook endpoints (Settings → Webhooks in the app).
- Re-enable a webhook endpoint: Changes where workspace data is sent. A person configures webhook endpoints (Settings → Webhooks in the app).

## When a person must approve

Some actions are never yours to take alone — creating an API key, adding or removing a webhook endpoint, and others the product lists. ASK instead, and wait for a person:

- MCP: `workspace_approval_actions_list` shows what can be asked and its input; `workspace_approval_requests_create` files it with your reason — show the person the returned `approveUrl`; `approval_requests_get` tells you when it is decided. A secret it creates is shown to the approving person, never to you.
- Command line: `reminix workspace approval-actions list --json`; `reminix workspace approval-requests create --action <id> --input '{…}' --reason "…" --json` (show the person the `approveUrl`); then, for an action that creates a secret, `reminix workspace approval-requests redeem <id> --wait --write-env .env` — it waits for the decision and writes the secret into the file WITHOUT printing it. Never ask the person to paste a secret to you.
- Requests expire after 24 hours; a denied request is final — ask the person what they want instead.

## More

- Documentation for agents: https://reminix.com/docs/llms.txt (index) and https://reminix.com/docs/llms-full.txt (everything)
- Errors: https://reminix.com/docs/errors/

## What Reminix is

Reminix turns scripts and AI-written code into **capabilities**: shared,
governed units a team runs from a UI, the API, an agent, or a schedule.
Each published change is a new version; runs that need a person go
through approvals; secrets are used by runs and never shown back.

## Publishing a capability

**Search first:** `capabilities list --q "<words>"` (or `--tag`) — if the
team already has one that does the job, use it (and tell the person)
instead of writing a new one.

To turn a script in the person's repository into a capability: write a
folder with `reminix.json` (`slug`, `name`, `description`, `entry`,
`inputSchema` — a JSON Schema with `"type": "object"`, plus `tags`) and
a `README.md` saying what it does and when to use it, and an entry file
(JavaScript or TypeScript; it may import other files and npm packages —
install them in the folder first) that default-exports
`async run(inputs, ctx)` and returns JSON; then run
`reminix capabilities publish <folder>`. That uploads a DRAFT. Publishing
it from your token files a request a person approves — tell the person,
with the link; never try to work around it. Every change is a new
version.

A run may answer **202 — awaiting approval** (the capability's policy):
tell the person, give them the link, and read the run later for its
output. A capability you cannot see is "not found" — don't guess others.

## Secrets

A capability that needs an API key uses a workspace **secret**. Never
ask the person for a secret's value, never put one in code, a manifest,
inputs or a command line. List what exists with `secrets list` (names
and hosts only); if the one you need is missing, tell the person its
name and hosts and ask them to add it in Settings → Secrets (or with
`reminix secrets set NAME --hosts …`, the value piped in).

To call an API from a capability, declare in `reminix.json`:
`"hosts": ["api.example.com"]` and, per secret,
`"secrets": { "NAME": { "host": "api.example.com", "header": "Authorization", "value": "Bearer {secret}" } }`.
The code calls `fetch` WITHOUT credentials — Reminix attaches them. Use
`"env"` (plain values) only when the person says the secret allows it.

## Schedules and triggers

To run a capability on a timetable or on an event, tell the person to add
a schedule or trigger on its page (they run as whoever creates them; you
cannot create them). You can list them: `schedules list`,
`triggers list`. Runs they start show `interface: "schedule"` or
`"trigger"`.

## Status

To run a published capability: `runs.create` with `{ "inputs": {…} }`
matching its input schema (a 400 lists each wrong field in `details`);
the answer is the finished run — `status`, `output` or `error`. Its
code reaches only its version's `hosts` (none by default) and has at
most 30 seconds. Read its log with
`runs.logs`. Over MCP each published capability is also its own tool,
`run_<slug>`; on the command line,
`reminix capabilities run <slug> --input '<json>'`.
