惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 三生石上(FineUI控件)
MyScale Blog
MyScale Blog
爱范儿
爱范儿
Y
Y Combinator Blog
Last Week in AI
Last Week in AI
博客园 - Franky
MongoDB | Blog
MongoDB | Blog
aimingoo的专栏
aimingoo的专栏
T
Tailwind CSS Blog
Microsoft Azure Blog
Microsoft Azure Blog
Hugging Face - Blog
Hugging Face - Blog
博客园_首页
阮一峰的网络日志
阮一峰的网络日志
WordPress大学
WordPress大学
月光博客
月光博客
Martin Fowler
Martin Fowler
A
About on SuperTechFans
有赞技术团队
有赞技术团队
酷 壳 – CoolShell
酷 壳 – CoolShell
I
InfoQ
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
J
Java Code Geeks
博客园 - 聂微东
宝玉的分享
宝玉的分享

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant
From curl to agent-ready API package: FirstCall CLI walkt...
Monde kim · 2026-05-15 · via DEV Community

Monde kim

When you hand an AI agent a raw curl command with an API key baked in, you're trusting it - and every tool it calls - to never log, retry, or forward that secret. That trust is hard to audit.

FirstCall is a local-first Rust workbench that turns verified API calls into redacted agent packages. Secret values are stripped before export. A 112-check validator runs before any agent can import the package. HTTP actually executes locally before a recipe is promoted - no "trust me it works."

Here is the full CLI lifecycle, run live against the v0.1.0 release binary.


CLI lifecycle demo

FirstCall CLI lifecycle


Step 1 - version

$ firstcall-cli version
firstcall-cli 0.1.0

Enter fullscreen mode Exit fullscreen mode

Step 2 - package a verified recipe

$ firstcall-cli package \
    --recipe-json fixtures/verified-agent-recipe.json \
    --out ./tmp/demo-pkg

Exported agent package to ./tmp/demo-pkg

Enter fullscreen mode Exit fullscreen mode

Step 3 - validate (112 checks)

$ firstcall-cli validate-package --dir ./tmp/demo-pkg

Package: ./tmp/demo-pkg
Status: valid
Checks passed: 112
Warnings: 0
Errors: 0
MCP compile smoke: not_requested

Enter fullscreen mode Exit fullscreen mode

112 checks cover manifest integrity, redaction invariants, slot/auth consistency, and import-readiness flags.

Step 4 - inspect before import

$ firstcall-cli inspect-package --dir ./tmp/demo-pkg

Validation status: valid
Import readiness: ready
Requires local re-verification: yes
Raw secrets imported: no
Validation checks passed: 112
Validation errors: 0

Enter fullscreen mode Exit fullscreen mode

Requires local re-verification: yes is set automatically on every import. A recipe cannot be re-exported without running local HTTP verification first.

Step 5 - import and list

$ firstcall-cli import-package --dir ./tmp/demo-pkg

Import status: imported
Imported recipe id: 1
Recipe: example_update_user
Method: POST
URL template: https://api.example.com/users/${user_id}?api_key=${FIRSTCALL_API_KEY}
Requires local re-verification: yes
Secrets imported: no
App storage modified: yes

$ firstcall-cli recipe-list

Recipes: 1
- ID: 1
  Recipe: example_update_user
  Method: POST
  Auth style: bearer
  Requires local re-verification: yes

Enter fullscreen mode Exit fullscreen mode

The URL template shows named slots (${user_id}, ${FIRSTCALL_API_KEY}) - actual values are never stored in the package.


Live HTTP verify - GitHub API (real request)

$ FIRSTCALL_BEARER_TOKEN=$GITHUB_TOKEN \
    firstcall-cli verify --recipe-json fixtures/github-user-recipe.json

Recipe: GitHub Authenticated User
Method: GET
URL template: https://api.github.com/user
HTTP status: 200
Outcome: success
Blocker: none
Updated verification time: 2026-05-15T01:46:16Z

Enter fullscreen mode Exit fullscreen mode

HTTP 200, real GitHub endpoint, token never written to output.


Desktop GUI workbench

The same trust chain runs in the desktop GUI: paste a curl command or OpenAPI spec, review the parsed candidate, fill runtime slots and auth, execute locally, review the attempt, promote to recipe.

FirstCall desktop GUI workbench


Install

Download a binary for your OS from GitHub Releases - includes both firstcall (GUI) and firstcall-cli.

Or build from source:

cargo build --locked

Enter fullscreen mode Exit fullscreen mode

CLI-only (no GUI dependencies):

cargo build --locked --bin firstcall-cli --no-default-features

Enter fullscreen mode Exit fullscreen mode


What it accepts

curl, OpenAPI (local JSON/YAML), Postman Collection, HAR, .http/.rest, Hurl, Bruno/OpenCollection. GraphQL-over-HTTP is detected from JSON bodies.

Remote OpenAPI $ref and multipart file uploads are not supported in v0.1.