Skip to content

Install and update the agent ​

Requirements ​

  • Node.js 20 or later.
  • npm or npx for the current user.
  • A released QA Studio capability if you intend to connect it to QA Studio.

No administrator account or global installation is required.

Start with the published package ​

Use the published package from a regular terminal:

bash
npx @xyva/agent login
npx @xyva/agent start

Complete authentication only through the approved interactive flow. Do not put tokens, API keys, or credentials in command arguments, URLs, tickets, chat messages, or public issues.

Check and update ​

Use the agent's status command to confirm its local sign-in state:

bash
npx @xyva/agent status

To receive a later published version, end the running process and run the same npx @xyva/agent command again. Confirm compatibility before updating a product connection.

The prepared Flow agent/contract candidate is not an installation path: an npm next release and Flow consumer are not yet published.

Diagnose ​

Check the login and provider state without printing credentials:

bash
npx @xyva/agent status
npx @xyva/agent provider status

Do not paste command history, local paths, model prompts, or provider details into a public report. The Provider Preview requires a published compatible release, an invited Flow session, entitlement, product-specific pairing, and a local grant for the exact provider. Even then, it is separate from workflow execution and capped at 32 output tokens.

The compatible Flow pairing path automatically requests a 60-second, one-time grant from the signed-in HttpOnly Flow session and binds it to the exact local pairing-token challenge. The Agent independently requires a valid local license and creates a Flow-only session family for at most five minutes. Never copy a pairing token or entitlement grant into a URL, command argument, log, ticket, chat, screenshot, or public issue.

Stop and uninstall ​

Stop a foreground agent with Ctrl+C, then remove the local product session:

bash
npx @xyva/agent logout

Delete each provider configuration you no longer want the agent to retain:

bash
npx @xyva/agent provider delete ollama --yes
npx @xyva/agent provider delete lmstudio --yes
npx @xyva/agent provider delete openai --yes
npx @xyva/agent provider delete claude --yes
npx @xyva/agent provider delete gemini --yes

The documented npx path does not install a global agent package. If you separately installed it globally, remove that installation as your regular user with npm uninstall -g @xyva/agent; do not use administrator privileges.

Prepared product-neutral provider setup ​

The reviewed candidate adds a product-neutral provider CLI so Flow will not require QA Studio for initial local setup:

bash
npx @xyva/agent provider status
npx @xyva/agent provider configure ollama --model MODEL_ID
npx @xyva/agent provider configure openai --model MODEL_ID
npx @xyva/agent provider grant ollama --product flow --yes

Replace MODEL_ID with an identifier shown by the approved provider readiness flow; this guide does not promise a current model name.

Cloud keys are requested only through a hidden interactive terminal prompt and verified through the provider's fixed model-list endpoint before storage. They are not accepted in command arguments, pipes, URLs, or provider-specific environment variables.

Configuration does not authorize Flow. Every provider starts with flow=denied; the local user must grant one exact configured provider with provider grant <provider> --product flow --yes. provider revoke <provider> --product flow --yes removes that consent without deleting QA Studio settings. A cloud-key replacement removes the corresponding Flow grant and requires new consent. Product login, entitlement and Flow pairing remain separate mandatory gates. These commands become an installation path only after the matching agent compatibility notice is published.

QA Studio · Flow · Shared local agent · Provider readiness