
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@otakit/cli
Advanced tools
Upload and release CLI for OtaKit.
capacitor.config.*The normal hosted flow is dashboard-first. Create the app in the dashboard,
paste its appId into plugins.OtaKit.appId, then ship:
otakit login
npm run build
otakit upload --release
If you want to create the app from the CLI instead:
otakit register --slug com.example.app
There is no otakit init.
The CLI reads these files when present:
capacitor.config.tscapacitor.config.jscapacitor.config.mjscapacitor.config.cjscapacitor.config.jsonImportant values:
webDir: "out",
plugins: {
OtaKit: {
appId: "app_xxxxxxxx",
// Optional:
// channel: "staging",
// serverUrl: "https://your-server.com/api/v1"
}
}
Resolution order:
capacitor.config.*Main rules:
appId: --app-id -> OTAKIT_APP_ID -> plugins.OtaKit.appIdserverUrl: --server -> OTAKIT_SERVER_URL -> plugins.OtaKit.serverUrl -> https://console.otakit.appoutputDir: upload path arg -> OTAKIT_BUILD_DIR / OTAKIT_OUTPUT_DIR -> webDir--release -> unnamed channel, --release <channel> -> named channelAuth precedence:
OTAKIT_TOKENotakit loginOrganization rules:
OTAKIT_ORGANIZATION_IDotakit organization select changes the local default without changing the dashboard workspaceVersion precedence:
--versionOTAKIT_VERSION<base>+otk.<commit>.<run>otakit upload
upload onlyotakit upload --release
upload and release to the unnamed channelotakit upload --release staging
upload and release to a named channelotakit release <bundleId> --channel staging
promote an existing bundle laterReleases are append-only. The newest release for
(appId, channel, runtimeVersion) is what devices see on manifest checks.
otakit loginotakit logoutotakit whoamiotakit organization selectotakit register --slug <slug>otakit upload [path] [--release [channel]]otakit upload --release --auto-revert [--auto-revert-rate <1-95>] [--auto-revert-min-sample <10-100000>] — server reverts the release if too many devices roll back within 24h (defaults: 20% of ≥50)otakit release [bundleId] [--channel <channel>]otakit releases [--channel <channel> | --base]otakit listotakit delete <bundleId> --forceotakit push send --title <title> --body <body> [--url <path>] [--topic <t>] [--channel <c>] [--user <id>] [--yes] — send a push notification (Push notifications add-on)otakit push campaigns / otakit push campaign <id> — delivery statusotakit config validateotakit config resolve --jsonotakit generate-signing-keyotakit mcp [--project-root <path>]Run the local stdio server from the Capacitor project it should access:
npx -y @otakit/cli@latest mcp
The project root and organization are fixed when the server starts. For a configured
project, the CLI uses plugins.OtaKit.appId to select its owning organization and
the server verifies current membership. An organization key is already fixed to its
owning organization. For app-less projects, otakit login stores a named default;
change it with otakit organization select and restart the MCP connection. Users do
not need an organization ID for interactive setup.
Do not put an OtaKit token in tool arguments. The server reuses OTAKIT_TOKEN or the
stored otakit login session and honors OTAKIT_SERVER_URL for self-hosted
installations. App-less automation may set OTAKIT_ORGANIZATION_ID; the
--organization-id flag remains an advanced per-process override.
The hosted remote server is https://console.otakit.app/mcp. It is a separate,
deployment-enabled surface for account operations and cannot read or upload files
from your local project. A deployment that has not enabled it returns a clear
503 response; local stdio MCP continues to work independently. See the
MCP and Agent Skills guide for Claude Code, Codex,
OAuth scopes, and remote setup.
export OTAKIT_TOKEN=otakit_sk_...
export OTAKIT_APP_ID=app_xxxxxxxx
export OTAKIT_BUILD_DIR=out
otakit upload --release
Set OTAKIT_SERVER_URL only for custom or self-hosted servers.
index.htmlbundles/initiatebundles/finalizereleasesThe CLI does not own app creation or channel strategy. It packages the build, uploads it, and optionally promotes it.
pnpm --filter @otakit/cli build
pnpm --filter @otakit/cli typecheck
pnpm --filter @otakit/cli dev
FAQs
CLI for uploading and releasing OtaKit OTA bundles
The npm package @otakit/cli receives a total of 744 weekly downloads. As such, @otakit/cli popularity was classified as not popular.
We found that @otakit/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.