Commands that print tokens or manage secrets can affect gateway access. Read the warning near the command before running it.
pioneer install
Install or replace the managed gateway binary and optionally start the service.
Release install requires published gateway assets and a matching
SHA256SUMS file for your OS, architecture, and gateway variant.pioneer update
Alias: pioneer self-update
Update the managed gateway binary using the same installer flow.
-computer-use asset name.
pioneer start
Start the current-user gateway service.
pioneer start validates that a systemd --user service can survive logout. If systemd linger is disabled and cannot be enabled by the current user, the command fails with linux_linger_required in JSON install failures and tells you to run:
pioneer start --json can return warnings for direct script/manual installs because the current service modes start at user login, not before login.
pioneer status
Show service and gateway reachability status.
- service name
- listen address
- service active state
- gateway reachable state
- runtime home
- install state if present
pioneer issue-superuser-token
Generate and print a JWT for privileged clients.
pioneer secrets status
Show keystore status without printing secret values.
- keystore path
- encryption mode
- total secret entry count
- counts by secret kind
- runtime directory and keystore file permission health
- MCP orphan secret status
gateway.db does not exist yet, MCP orphan status is reported as unavailable.
pioneer secrets garbage-collection
Clean orphan MCP secret values from the gateway keystore.
gateway.db. It only deletes MCP secret values, and it refuses to run when gateway.db is missing. Use --dry-run to inspect counts without deleting anything.
pioneer secrets rotate-jwt-token superuser
Rotate the singleton superuser JWT signing material.
pioneer issue-superuser-token afterwards to issue a fresh token.
pioneer stop
Stop and unregister the current-user gateway service.
The current CLI uses
stop for service removal. There is no separate uninstall command.pioneer task-invariants
Scan a gateway SQLite database for task runtime invariant violations.
--json for automation and --stale-turn-after-seconds to tune stale turn detection.
pioneer version
Print CLI version information.
pioneer help
Show CLI help.
Install source options
Release asset names include the OS, architecture, and optional gateway variant suffix. Standard headless assets use names like
pioneer-gateway-linux-x86_64.gz; computer-use assets use names like pioneer-gateway-linux-x86_64-computer-use.gz.
Install behavior
The native installer flow:- Resolves the asset and checksum file.
- Verifies the asset checksum.
- Stages the new binary.
- Stops the current service if needed.
- Atomically replaces the binary.
- Exposes the CLI command.
- Optionally starts the service.
- Checks gateway health.
- Rolls back on failure.
--json is used, install/start output can include warnings. Treat these as service lifecycle caveats that did not prevent the gateway from starting. Linux headless persistence failures are blocking for script/manual installs because a systemd --user service without linger will stop when the login session ends.
Further reading
- Gateway Architecture explains what the service does after
pioneer start. - Secret Storage explains
pioneer secretsandissue-superuser-token. - Persistence explains the SQLite state inspected by
pioneer task-invariants.