
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
@j-256/ccam
Advanced tools
Command-line tool for the Salesforce Commerce Cloud Account Manager REST API.
The AM API is largely undocumented. ccam gives Account Manager administrators a tool that covers every resource, every subresource, and every finder -- exportable to CSV/TSV/YAML/JSON for audits, automation, and integrations.
Built for:
Highlights:
ccam user list --org <id> --format csv produces a spreadsheet-ready roster.~/.config/ccam/credentials with 0600 permissions.ccam with no arguments for a keyboard-driven resource browser.For programmatic use, see ccam-sdk -- the typed TypeScript library that powers this CLI.
npm install -g @j-256/ccam
The install adds a ccam binary to your PATH. Requires Node.js 22 or later.
ccam talks to Account Manager over OAuth2, so you need an AM API client before you can log in. If you already use sfcc-ci or other Commerce Cloud tooling, you can reuse that client; otherwise see the getting-started guide for a step-by-step walkthrough.
Once you have a client ID (and secret, for confidential clients):
ccam auth login --client-id <your-client-id>
This opens a browser to AM, captures the authorization code on a loopback server, and saves a profile to ~/.config/ccam/profiles.yaml (non-secret) and ~/.config/ccam/credentials (0600; contains refresh token).
Non-interactive alternatives:
ccam auth login --client -- client_credentials flow (for CI/automation)ccam auth login --password -- ROPC flow (when SSO/MFA are not enforced)ccam auth login --manual -- browser flow without a loopback server (for SSH/headless)For non-profile-based auth, set:
export CCAM_CLIENT_ID="your-client-id"
export CCAM_CLIENT_SECRET="your-client-secret"
export CCAM_HOST="https://account.demandware.com" # optional, this is the default
For user-context operations (e.g. ccam user current):
export CCAM_USER="your-email@example.com"
export CCAM_USER_PASSWORD="your-password"
Resolution order: CLI flags > env vars > active profile > defaults.
List users:
ccam user list
Filter users:
ccam user list --org abc123 --role def456
ccam user list --login user@example.com
ccam user list --org-realm-access abc123
Filter organizations:
ccam org list --name "Acme Corp"
ccam org list --starts-with "Acme"
ccam org list --sf-account-id "001..."
Export to CSV:
ccam user list --org abc123 --format csv > users.csv
| Format | Use case | CLI flag |
|---|---|---|
table | Human-readable display (TTY default) | -f table or --format table |
json | Machine-readable, piping to jq | -f json, --format json, or -j |
csv | Spreadsheet import, data analysis | -f csv or --format csv |
tsv | Tab-separated (better for whitespace) | -f tsv or --format tsv |
yaml | Config files, human-readable structured | -f yaml or --format yaml |
When output is piped (not a TTY), JSON is the default.
Common aliases are -f, --format, -p, --profile, -s, --sort, and -j, --json. --fields, --page, --size, and --host remain long-only because their first letters belong to the more reusable aliases or to help. Auth login and logout also accept -p, --profile; credential and flow selectors remain explicit long options.
| Resource | Command |
|---|---|
| Users | ccam user |
| Organizations | ccam org |
| API Clients | ccam client |
| Roles | ccam role |
| Realms | ccam realm |
| Permissions | ccam permission |
| Service Types | ccam service-type |
| Instances | ccam instance |
| Org Configurations | ccam org-config |
Most resources support list (paginated) and get <id>.
Additional commands:
get by login (default) or by ID (--id), current, audit, roles, instances, assigned-realms, assigned-instances, create, update, delete, reset, disable, revoke-verifier, grant-role, revoke-role.realms, instances, audit, update.audit, assigned-realms, assigned-instances, create, update, delete, set-password, set-auth-type, grant-role, revoke-role.validate-filter.Users and API Clients support --expand on get to include related resources (organizations, roles, or organizations,roles). Roles and Org Realms support --expand serviceType and --expand instance respectively.
ccam user list maps filter flags to AM API finder methods:
| Flag | API finder | Example |
|---|---|---|
--login <email> | findByLogin | ccam user list --login user@example.com |
--org <id> | findByOrg | ccam user list --org abc123 |
--org <id> --all | findAllByOrg | ccam user list --org abc123 --all |
--role <id> | findByRole | ccam user list --role def456 |
--org <id> --role <id> | findByOrgAndRole | ccam user list --org abc123 --role def456 |
--org-realm-access <id> | findByOrgRealmAccess | ccam user list --org-realm-access abc123 |
Add --modified-after <date> with --role to filter by modification date.
MIT
FAQs
CLI for the Salesforce Commerce Cloud Account Manager API
We found that @j-256/ccam demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.