Getting started

This guide installs the splice CLI, creates a project, installs an official skill, verifies it and runs one of its tools. It takes about five minutes.

Requirements: Node.js 22.18 or newer (Windows, macOS or Linux).

1. Install the CLI

The CLI is distributed on npm as @spliceloom/cli and installs the splice command:

npm install -g @spliceloom/cli
splice --version

Install: npm install -g @spliceloom/cli (Node.js >= 22.18). Contributors can instead use a local build (see releasing.md) or the source checkout:

npm install && npm run build
npm link -w @spliceloom/cli      # makes `splice` available globally

The scoped name is used because the unscoped npm name splice belongs to an unrelated package.

The CLI talks to the Splice registry at https://registry.spliceloom.com by default (see cli.md to use another registry).

2. Create a project

A Splice project is a directory with a splice.json file:

mkdir my-agent && cd my-agent
splice init

splice init only writes splice.json. splice.lock and the .splice/ folder appear with the first installed package.

3. Search the registry

splice search github
@splice/github
Official read-only GitHub tools over the public REST API (no token): …
latest: 0.1.0

4. Inspect a package

splice info @splice/github

info shows versions, the SHA-256 integrity, the permissions the package requests and every tool with its inputs. Read the permissions before installing.

5. Install

splice add @splice/github --accept-permissions

@splice/github requests network access to api.github.com, so it needs explicit consent (--accept-permissions). Packages without permissions (for example @splice/json) install without it.

During add, Splice resolves the version, downloads the artifact, verifies its SHA-256 and size against the registry metadata, validates the package, checks the permissions, and only then extracts it into .splice/packages/. No package code runs during installation.

6. Verify

splice verify @splice/github

verify re-downloads the published version and checks it end to end (SHA-256, size, package validity, registry metadata, provenance, the direct artifact URL) and compares the installed copy with the verified artifact. Exit code 1 means a check failed.

SHA-256 proves you received the bytes the registry recorded. It does not prove who wrote them; see security.md.

7. List installed packages

splice list

8. Discover tools

splice info @splice/github

Tools are referred to as <package>.<tool>, e.g. github.get-repo (or the full form @splice/github.get-repo). From code, splice.tools() returns the same descriptors (sdk.md); MCP clients see them through splice mcp (mcp.md).

9. Run a tool

splice run github.get-repo owner=spliceloom repo=splice-artifacts

key=value arguments are converted using the tool's input schema; --input '<json>' passes a JSON object instead. The tool runs in a separate, sandboxed Node.js process limited to the package's declared permissions (permissions.md). Output is printed as JSON; --json prints the full result envelope.

10. Update and remove

splice outdated
splice update
splice remove @splice/github

11. Live data — no keys needed to start

splice chain info                 # Robinhood Chain via the official public RPC (chain id verified live)
splice price ETH                  # CoinGecko keyless prices
splice market search robinhood    # DexScreener pairs
splice setup                      # what works without keys, and which free keys unlock more

splice setup --init creates ~/.splice/.env with every provider variable name (no values); fill in the keys you have and run splice providers to check them live. Keys there work from every folder; splice setup --template > .env.local makes a per-project file instead. The Quickstart tours every live data command. Without a key a feature answers UNAVAILABLE with a hint — never invented data. See data-providers.md.

Next steps