opensre (TTY required). Type a slash command at the prompt, or describe what you want in plain language — the action agent can route intent to the right command.
Run /help anytime for the live command list grouped by category. In a TTY, bare /help opens an interactive picker; selecting a command runs it directly.
When you type / and browse completions with the arrow keys, the full description of the highlighted command appears in the hint line above the prompt.
Commands marked elevated may prompt for confirmation unless trust mode is on. Non-TTY sessions fail closed on elevated actions.
How the REPL works
TTY vs non-TTY: The full experience (interactive menus, confirmations, onboarding wizards) requires a real terminal. Piping input or running in CI sets non-interactive mode — elevated commands are rejected unless trust mode was enabled in a prior interactive session (prefer explicit CLI commands outside the REPL for automation).
Unknown commands: Typos suggest the closest registered command (
Did you mean /integrations?). Run /help for the authoritative list — it always matches your installed OpenSRE version.
Keyboard shortcuts:
Quick reference
Help and exit
Session
Investigation
Integrations, models, and tools
Privacy and history
Tasks and background work
Watchdog
Agents and alerts
CLI parity
These commands delegate to the same Click CLI you would run outside the REPL.System
Commands with interactive menus (TTY)
Bare invocation opens a picker or submenu:Using /help
Help categories mirror the REPL grouping: Quick Access, Session, Integrations/Models/Tools, Investigation, Privacy, Tasks, Agents, Alerts, CLI parity, and System.
Quick Access duplicates frequently used commands (
/investigate, /integrations, /model, /health, /watch, /status, /help) for faster discovery in the picker.
Session commands
/status
Shows a snapshot of the current REPL session:
Use
/status for session state. Use /health for integration connectivity.
/cost
Shows LLM usage tracked locally for the current REPL session. This is not cloud-provider billing and does not read your vendor invoice.
Measured vs estimated:
When any estimate is included, the table title notes
(includes estimates) and rows show measured vs estimated splits.
What increments the counter: Normal LLM chat turns and planner calls. What does not: Non-LLM command handling such as history recall or prompt rendering.
Token totals reset on /new or when session identity is rotated. They do not carry across /resume. See Session History.
/context
Displays key/value infra metadata collected during investigations and chat — typically service, cluster, region, or similar fields extracted from alert text and investigation state.
/resume). It is passed as overrides to subsequent /investigate runs so the pipeline does not re-ask for environment details you already established.
/effort
Set reasoning depth for OpenAI and Codex providers in this REPL session only.
Bare
/effort prints the current level, the config default for your provider/model, and supported choices. /status includes the same field.
Other providers (Anthropic, Ollama, etc.) ignore /effort; the shell prints a hint suggesting /model set openai or /model set codex. Set OPENSRE_REASONING_EFFORT in the environment for non-interactive defaults. See LLM providers.
/trust
Trust mode skips execution confirmation prompts for elevated commands (/save, /watch, /cancel, /uninstall, integration remove, etc.).
/trust opens an interactive on/off menu. Trust mode is a session preference — it is not restored by /resume.
/verbose
Toggle TRACER_VERBOSE logging for the REPL process (deeper internal logs to stderr).
/clear
Clears the terminal and re-renders the OpenSRE banner. Does not reset session state, token usage, LLM conversation context, or accumulated infra context.
/compact
Summarizes older conversation context, keeps recent messages, and persists a compaction entry in the session file. Future /resume calls replay the summary before the kept messages.
/sessions
List up to 20 recent sessions stored on disk, newest first:
The current row updates duration live. Sessions with no name show
(current) or ↩ <resumed-from> when applicable.
/resume
Restore LLM conversation context and accumulated infra context from a previous session.
Current session: If the ID prefix matches the session you are already in,
/resume is a no-op — OpenSRE prints a hint to pick a previous session from /sessions.
When you resume a different session, OpenSRE:
- Switches the active session file to the target session
- Restores
cli_agent_messagesso the assistant remembers prior turns - Restores
accumulated_contextkeys - Reprints conversation history (user prompts, assistant replies, slash commands)
Warning: Resuming a different session replaces the current session’s LLM context if messages already exist.
Session replay reads the current version-2 session tree format. Older session files are ignored by
/sessions and /resume. See Session History.
/new
Rotate to a new session file while keeping the current LLM conversation thread and accumulated context.
Use
/new after a long /resume so /sessions stays tidy without losing your place in the conversation.
Exit paths
/exit, /quit, double Ctrl+C, or Ctrl+D (empty prompt) all print:
Investigation commands
Three ways to start RCA from the REPL:
Investigations inherit accumulated context from earlier runs in the same session.
/investigate
During a run:
- Output streams to the terminal like chat
- Ctrl+C cancels and marks the task cancelled
/tasksshows the investigation task id and status- On completion,
last_stateis updated for/lastand/save - Infra fields from the result merge into accumulated context
last_state.
/template
Print starter alert JSON to stdout — copy, edit, save, then /investigate your-file.json.
/last
Reprint the root cause and report sections from the most recent successful investigation in this session.
problem_md or slack_message). If no investigation ran yet, prints a dim empty-state message.
/save
Write the last investigation to disk. Requires confirmation unless trust mode is on.
Parent directories must exist or be creatable; write failures print the underlying error.
Integrations, models, and tools
Choosing the right diagnostic command
/health
Read-only pass/fail report for the local OpenSRE agent, LLM connectivity, and each configured integration.
/verify.
/verify
Shortcut for integration connectivity checks (same as opensre integrations verify / make verify-integrations).
/integrations
Bare
/integrations opens an interactive menu in a TTY with service pickers for show/remove.
/mcp
MCP-capable integrations only (subset of the full integration catalog).
/model
Show or change LLM provider and models. Updates project .env (default: repository root .env, override with OPENSRE_PROJECT_ENV_PATH), ~/.opensre/opensre.json, and resets in-process LLM caches.
Credential guard: Switching to a provider without prompt-safe auth status fails fast with setup instructions. Run
/auth login <provider> or export the provider API key before switching. If status is stale, run /auth verify <provider>.
Reasoning vs toolcall model: Reasoning model drives chat and planning; toolcall model drives investigation tool invocation when the provider exposes a separate slot (common on Anthropic/OpenAI).
Interactive /model menu flow: pick provider → reasoning model (or default) → optional toolcall model (keep, match-reasoning, or explicit).
See LLM providers.
/tools
List tools available to investigation and chat surfaces in this build (name, source, surfaces).
/list command — use domain-specific list commands (see Natural language actions).
Privacy and history
Command history (up-arrow recall) is separate from session history (/sessions). Full redaction patterns and env vars: Interactive Shell Privacy.
/history
Bare
/history opens an interactive menu in a TTY (presets: 100, 500, 1000, 5000 for retention).
/privacy
Tasks and background work
Long-running work is tracked in a per-session task registry surfaced by/tasks.
Task kinds
Task statuses
/tasks
/cancel or /unwatch.
/cancel
- Matches task id by prefix (must be unique among active/recent tasks)
- Only running tasks accept cancellation
- Investigations: signals cancel; press Ctrl+C if streaming continues
- Watchdogs: prefer
/unwatchfor watchdog-specific messaging
/stop
Prints guidance only — does not kill processes:
/background
Session-local async investigation mode. Launch an RCA, keep using the shell, and get the finished report delivered to email or Telegram.
email requires the smtp integration; telegram requires the telegram integration. Interactive shell only — there is no opensre background … CLI command. Full guide: Background investigations.
Watchdog commands
Monitor a local process and send Telegram alarms when CPU, memory, or runtime thresholds breach. Configure Telegram credentials before use (via/onboard or env — see messaging docs).
/watch
On start:
/trust on(optional — skips/watchconfirmation)/watch <pid> --max-cpu 80— use a real PID (e.g. the REPL’s Python process)/watches— confirmrunningstatus and threshold string/unwatch abc12— request stop;/watchesshould showcancelled
/watch 12345 --max-cpu "80".
/watches
/unwatch
/cancel also works; /unwatch validates the task kind.
/watchdog
CLI-parity syntax (subprocess to opensre watchdog):
/watch inside the REPL — it registers tasks for /watches and /tasks automatically.
Agents and alerts
Fleet coordination is documented further on Agents. Register discovered agents withopensre fleet scan --register before /fleet trace targets them.
/fleet
Kill confirmation: Without
--force, prompts [y/N]. --force skips prompt (still elevated tier unless trust mode).
/alerts
If the listener is inactive, prints a warning. Incoming alerts also appear in
/status as incoming alerts. Post alerts to your configured webhook/listener URL during setup; the REPL can start investigations from plain language.
CLI parity commands
These spawnopensre … subprocesses. Output is captured into the REPL buffer for non-interactive subcommands; wizards attach to the real TTY.
/onboard
/remote
/config
~/.opensre/config.yml. Prefer env vars for secrets; use config for structured interactive-shell settings.
/cron
/sentry
/messaging
/watch alarms and some delivery features.
/hermes
/guardrails
Related: Masking.
/tests
Synthetic tests can run for a long time; default timeout is generous — use
/cancel to stop.
/update
/debug
opensre debug --help.
/uninstall
System commands
/doctor
Environment diagnostic distinct from /health:
ok, warn, or error with detail text.
Use /doctor before first install debugging; use /health before an incident to verify integrations.
/version
/exit and /quit
/resume hint. Prefer over killing the terminal so session files flush cleanly.
Trust mode and confirmations
Non-TTY: elevated commands fail closed (error message, no side effect).
Natural language actions
You do not need to memorize every slash command. Examples:
List intents — there is no global
/list:
When the planner is uncertain, it asks for clarification or falls back to help — it does not silently run elevated commands.
Compound requests (“health then integrations”) execute as an ordered sequence of slash actions.
Common workflows
First-time setup
Incident triage (local)
Pick up yesterday’s thread
Switch model mid-session
Monitor a runaway process
Debug integration failures
Troubleshooting
Related docs
- Session History — persistence format, privacy,
/newvs/clear - Interactive Shell Privacy — redaction, env vars, threat model
- Investigation overview — RCA workflow, plain-language actions, CLI investigate
- LLM providers —
/modeland/effort - Agents — fleet dashboard, bus, trace, budgets
- Cron —
/cronscheduled deliveries - Hermes —
/hermes watch - Remote runtime investigation —
/remote