惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google DeepMind News
Google DeepMind News
罗磊的独立博客
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Last Week in AI
Last Week in AI
云风的 BLOG
云风的 BLOG
T
The Blog of Author Tim Ferriss
Y
Y Combinator Blog
A
About on SuperTechFans
WordPress大学
WordPress大学
B
Blog
Martin Fowler
Martin Fowler
Jina AI
Jina AI
I
InfoQ
P
Proofpoint News Feed
小众软件
小众软件
S
SegmentFault 最新的问题
V
V2EX
B
Blog RSS Feed
量子位
大猫的无限游戏
大猫的无限游戏
aimingoo的专栏
aimingoo的专栏
博客园 - 三生石上(FineUI控件)
MongoDB | Blog
MongoDB | Blog
美团技术团队

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant
From curl to agent-ready API package: FirstCall CLI walkt...
Monde kim · 2026-05-15 · via DEV Community

Monde kim

When you hand an AI agent a raw curl command with an API key baked in, you're trusting it - and every tool it calls - to never log, retry, or forward that secret. That trust is hard to audit.

FirstCall is a local-first Rust workbench that turns verified API calls into redacted agent packages. Secret values are stripped before export. A 112-check validator runs before any agent can import the package. HTTP actually executes locally before a recipe is promoted - no "trust me it works."

Here is the full CLI lifecycle, run live against the v0.1.0 release binary.


CLI lifecycle demo

FirstCall CLI lifecycle


Step 1 - version

$ firstcall-cli version
firstcall-cli 0.1.0

Enter fullscreen mode Exit fullscreen mode

Step 2 - package a verified recipe

$ firstcall-cli package \
    --recipe-json fixtures/verified-agent-recipe.json \
    --out ./tmp/demo-pkg

Exported agent package to ./tmp/demo-pkg

Enter fullscreen mode Exit fullscreen mode

Step 3 - validate (112 checks)

$ firstcall-cli validate-package --dir ./tmp/demo-pkg

Package: ./tmp/demo-pkg
Status: valid
Checks passed: 112
Warnings: 0
Errors: 0
MCP compile smoke: not_requested

Enter fullscreen mode Exit fullscreen mode

112 checks cover manifest integrity, redaction invariants, slot/auth consistency, and import-readiness flags.

Step 4 - inspect before import

$ firstcall-cli inspect-package --dir ./tmp/demo-pkg

Validation status: valid
Import readiness: ready
Requires local re-verification: yes
Raw secrets imported: no
Validation checks passed: 112
Validation errors: 0

Enter fullscreen mode Exit fullscreen mode

Requires local re-verification: yes is set automatically on every import. A recipe cannot be re-exported without running local HTTP verification first.

Step 5 - import and list

$ firstcall-cli import-package --dir ./tmp/demo-pkg

Import status: imported
Imported recipe id: 1
Recipe: example_update_user
Method: POST
URL template: https://api.example.com/users/${user_id}?api_key=${FIRSTCALL_API_KEY}
Requires local re-verification: yes
Secrets imported: no
App storage modified: yes

$ firstcall-cli recipe-list

Recipes: 1
- ID: 1
  Recipe: example_update_user
  Method: POST
  Auth style: bearer
  Requires local re-verification: yes

Enter fullscreen mode Exit fullscreen mode

The URL template shows named slots (${user_id}, ${FIRSTCALL_API_KEY}) - actual values are never stored in the package.


Live HTTP verify - GitHub API (real request)

$ FIRSTCALL_BEARER_TOKEN=$GITHUB_TOKEN \
    firstcall-cli verify --recipe-json fixtures/github-user-recipe.json

Recipe: GitHub Authenticated User
Method: GET
URL template: https://api.github.com/user
HTTP status: 200
Outcome: success
Blocker: none
Updated verification time: 2026-05-15T01:46:16Z

Enter fullscreen mode Exit fullscreen mode

HTTP 200, real GitHub endpoint, token never written to output.


Desktop GUI workbench

The same trust chain runs in the desktop GUI: paste a curl command or OpenAPI spec, review the parsed candidate, fill runtime slots and auth, execute locally, review the attempt, promote to recipe.

FirstCall desktop GUI workbench


Install

Download a binary for your OS from GitHub Releases - includes both firstcall (GUI) and firstcall-cli.

Or build from source:

cargo build --locked

Enter fullscreen mode Exit fullscreen mode

CLI-only (no GUI dependencies):

cargo build --locked --bin firstcall-cli --no-default-features

Enter fullscreen mode Exit fullscreen mode


What it accepts

curl, OpenAPI (local JSON/YAML), Postman Collection, HAR, .http/.rest, Hurl, Bruno/OpenCollection. GraphQL-over-HTTP is detected from JSON bodies.

Remote OpenAPI $ref and multipart file uploads are not supported in v0.1.