What it is
LLeMbas CLI is a terminal coding agent and project manager — the lembas command, or agent if you let the installer add the alias. It runs on your machine, in your project, on whatever model you point it at.
- Any LLM API — OpenAI-compatible chat (llama.cpp, llama-swap, vLLM, LM Studio, OpenRouter, DeepSeek), OpenAI Responses, Anthropic Messages, Google Gemini and native Ollama. Nothing is predefined: every connection is one you write, or one a LLeMbas server gives you.
- A real TUI, with streaming Markdown, folding reasoning, inline diffs and a context meter.
- Four permission modes — manual, edit, auto, plan — and a short list of catastrophic commands refused in every mode.
- Git-native: every project is a repository and every prompt a snapshot, so
/undoand/redoalways work. - Plan mode with approval, subagents (optionally in their own git worktree), web search, vision, and the project’s own task board and decision log in
.agent/. - Memory and skills that carry across sessions; past sessions are searchable; every skill is also a
/command. - Knowledge bases searched by words and by meaning, and MCP servers, local or remote, with OAuth sign-in.
- Voice: press Ctrl+T and talk; have replies read aloud.
- Release tools:
/changelogdrafts entries from the commits;/releasebumps, dates and makes a signed tag. - Linked to a server: its models, library, voice and search, its credits in the status bar — and sessions you can work from the browser.
Linux only, x64 and arm64 (a baseline x64 build covers CPUs without AVX2). The Gemini and native Ollama dialects are included but have not been tested against real servers yet.
Install
One line: the latest release’s binary for this machine, installed to ~/.local/bin.
curl -fsSL https://github.com/LLeMbas/LLeMbas-CLI/releases/latest/download/get.sh | bashBefore anything is installed, get.sh checks the release’s signed SHA256SUMS and then the binary against it. If no release can be found, fetched or verified, it stops and says so — it never falls back to an unsigned build. It needs curl, sha256sum, gzip and ssh-keygen (openssh-client). Nothing runs as root.
# options go on to the installer
curl -fsSL https://github.com/LLeMbas/LLeMbas-CLI/releases/latest/download/get.sh | bash -s -- --aliases
# a specific release, or the newest beta
curl -fsSL …/get.sh | LEMBAS_REF=v1.0.0 bash
curl -fsSL …/get.sh | LEMBAS_CHANNEL=beta bashThe installer writes commented starter files to ~/.config/lembas/ — config.yaml, and connections.yaml (mode 600) where your models go — and never touches files that already exist.
From a checkout
git clone https://github.com/LLeMbas/LLeMbas-CLI.git
cd LLeMbas-CLI
./install.sh # builds with Bun (offered if missing) → ~/.local/bin/lembasUpdate
LLeMbas CLI updates itself. When the TUI starts it looks — at most once an hour — for a newer release on its channel, checks the signature and checksum, keeps the binary it replaces as lembas.prev, and tells you to /reload. Nothing older than what runs is ever installed by itself.
lembas update # now, from the shell
lembas update --check # only say whether there is one
lembas update v1.0.0 # that release (older too, on purpose)
lembas update --rollback # back to the one before
lembas config set update.channel beta # stable (default) | beta
lembas config set update.auto notify # install (default) | notify | offUpdates can also come from your own fork on GitHub, a Gitea or Forgejo, or any static web directory, signed with your own key — see Configuration → Updates.
Uninstall
lembas uninstall # the binary, the shell block, the editor schemas
lembas uninstall --purge # and settings, connections, sessions, memory, skills
curl -fsSL …/get.sh | bash -s -- --uninstall # the same, when the binary will not runIt lists what it will remove and asks first. A project’s own .agent/ is never touched.
Log in to a server
Logged in to a LLeMbas server, the CLI uses that server’s models — with the settings its administrator chose for each — and, where your account may, its voice, web search and library. Nothing is copied into your config: the models are read from the server at every start.
lembas login https://your-serverIt checks that the address is a LLeMbas server, then shows a link and a code. Open the link (or type the code under Settings → Devices on the server), check the machine’s name and address, and approve. In the TUI the same is /login; a fresh install opens on it.
- The server’s models are named
provider/model, exactly as its API names them. - With no
model:set, a session starts on your account’s default model there. /usageand the status bar show your credits on the server.lembas logoutrevokes the token and removes exactly what the login added. The server can also sign the device out from its side.
Taking agent chats from the browser
To let the server start agent chats on this machine, say where they may work, then run the link as a background service:
# ~/.config/lembas/config.yaml — global only; a project can never set it
remote:
enabled: true
roots: [~/code] # the only directories a remote session may use
max_mode: edit # the most a remote session may run in
terminal: false # true: the web terminal panel may open a shell herelembas service install # a systemd user unit; status, logs -f, uninstall
loginctl enable-linger $USER # if it should run while nobody is logged inThe service dials out to the server and listens on nothing. What the server asks beyond these limits is refused or lowered here. /remote shares the session you have open in a terminal, by name. More in Agent chats.
Everyday use
cd your-project && lembas # the TUI (or: agent)
lembas -c # continue the last session here
lembas run "fix the failing test" # one prompt, no TUIThe first time you open a directory it asks whether to trust it and offers to create a git repository. Per-project settings then live in .agent/. The CLI reads the project’s AGENTS.md (or CLAUDE.md); /init writes one from what the repository says.
Modes
| Mode | What it may do without asking |
|---|---|
| manual | Nothing beyond what your rules already allow. |
| edit | Change files inside the project; commands still ask. |
| plan | Only read, and write a plan for you to approve. |
| auto | Everything. Reachable only through /mode, which asks. |
Shift+Tab cycles manual → edit → plan. On an approval card, e lets you correct a command before it runs and r refuses it and tells the model why.
The prompt
/lists commands, filtered as you type.@completes files and attaches them —@file#10-20for lines.!commandruns a shell command and hands its output to the model with your next message.- While it works you can keep talking: a message sent mid-task goes in at the next step.
Sessions
Every conversation is a session, kept per project and searchable. /sessions opens the picker: Enter opens one, Ctrl+D deletes the highlighted one. /new starts afresh, /delete removes the current one, and /sessions delete opens the picker to choose one to delete.
Snapshots and git
/undo and /redo step through every prompt’s snapshot; /checkpoint [name] keeps a named one that outlives the session. /diff, /commit and /branch do what they say.
All keys and commands: Keys and commands.
Key configuration
Everything lives in ~/.config/lembas/:
| File | What |
|---|---|
connections.yaml | Your LLM connections and models. Global only — a project can never override it. Keep it chmod 600. |
config.yaml | Defaults: model, mode, search, voice, permissions, personality, instructions, updates, the remote link. |
AGENTS.md | Instructions for every project. |
commands/, agents/, skills/, themes/ | Your own slash commands, subagents, skills and colour themes. |
schema/ | JSON Schemas so an editor with a YAML language server completes and checks both files. |
# ~/.config/lembas/connections.yaml
connections:
local:
dialect: openai-chat # openai-chat | responses | anthropic | gemini | ollama
base_url: http://localhost:8080/v1
api_key: "{env:LOCAL_KEY}" # or "{file:~/.secrets/k}", or key_cmd: "pass show llm/local"
models:
coder: { context: 131072, efforts: [low, medium, high], effort: medium, tools: true }# ~/.config/lembas/config.yaml
model: local/coder
mode: manual # manual | edit | auto | plan
personality: pragmatic # concise | pragmatic | optimistic | funny | formal | socratic | custom
instructions: |
I know Python well and TypeScript a little.
permission:
bash: { "npm test *": allow, "npm publish *": deny }/settings lists every setting with where its value comes from, and changes it for the session, globally or for the project. From a shell: lembas config list | get <key> | set <key> <value> [--project].
Every key: CLI configuration reference.
Source and licence
MIT licensed. TypeScript on Bun, rendered with OpenTUI, shipped as one compiled binary. It builds on OpenCode, OpenTUI and Hermes Agent, and shares one harness design with the LLeMbas server — the same tools, permission rules and prompt texts.
- github.com/LLeMbas/LLeMbas-CLI — releases, issues
- git.houmeres.sk/LLeMbas/LLeMbas-CLI (where it is developed)