UiPath Platform — uip CLI Assistant
Comprehensive guide for UiPath Cloud / Orchestrator / Studio Web / Integration Service, end-to-end via the
CLI. For
lifecycle load
; for PDD/SDD design & task planning load
.
Route Diagnostic Intent Before Platform Work
Classify the requested outcome before running any command:
- Causal outcome → hand off immediately. User wants an explanation, diagnosis, or root cause for undesirable existing behavior → invoke the tool with uipath-troubleshoot (name exactly as it appears in your available-skills list) before running anything. No preliminary job/log/trace fetching — troubleshoot owns evidence collection. Prose telling the user to use troubleshoot is not a substitute for the call.
- Operational outcome → stay here. Inspect current state without a causal question, perform CRUD or lifecycle actions, validate an input before applying it, or execute an already-diagnosed platform fix.
- Mixed request → troubleshoot first. Hand off the diagnosis; return here only for the platform mutation that applies the confirmed fix.
- Sibling unavailable → degrade gracefully. State the handoff could not run; give the entity, scope, and time window needed to retry the investigation. Do not improvise a platform-only root cause.
Use the CLI. Don't roll your own REST.
Always reach for CLI commands first. The CLI covers auth, Orchestrator (folders, processes, jobs, machines, users, roles, sessions, calendars, settings, audit logs, credential stores, feeds, attachments), resources (assets, queues, queue items, storage buckets, bucket files, libraries, webhooks, triggers), Integration Service (connectors, connections, activities, IS triggers), traces, and licensing end-to-end.
Hand-rolling HTTP calls — reading
and POSTing to
or
— almost always misses something the CLI gets right: the
X-UIPATH-OrganizationUnitId
folder header, OData filter shape (
with escaped single quotes), pagination envelope, retry semantics, validation error shape, or
output contract.
Reach for raw REST only after you've searched references/uip-commands.md
for your task and confirmed no command covers it. The CLI is the source of truth.
If you find yourself about to
https://cloud.uipath.com/...
— stop. Search the command index first. Examples of what people often miss:
- "upload a file to a storage bucket" →
uip or bucket-files upload
(NOT a PUT /buckets/.../signedUrl
dance)
- "create an asset" → (NOT a )
- "start a job for a process" →
uip or jobs start <process-key>
(NOT POST /odata/Jobs/UiPath.Server.Configuration.OData.StartJobs
)
- "configure an Integration Service connection" →
uip is connections create <connector-key>
(NOT a hand-rolled OAuth flow)
- "attach a file to a Data Fabric record" →
uip df files upload <entity-id> <record-id> <field-name> --file <path>
(NOT / with the file value — the platform silently strips FILE columns and returns Success, see references/data-fabric/data-fabric.md
Rule 6)
When to Use This Skill
Load this skill BEFORE writing any code that talks to UiPath. Specific triggers:
-
Auth & tenant: login, logout, switch tenant, named login profiles via
,
, OAuth token, organization
-
Orchestrator core: folders (
list/get/create/edit/move/delete/runtimes
), processes/releases, jobs (
start/stop/logs/traces/healing-data
), packages (
), machines, users / roles / sessions (incl. DirectoryUser/DirectoryGroup/DirectoryRobot/DirectoryExternalApplication), licenses, calendars, settings, audit logs, credential stores, feeds, attachments
-
Resources (Orchestrator-scoped): assets (text/integer/bool/credential), queues + queue items, storage buckets + bucket files (
upload/download/get-download-url/get-upload-url
), libraries (
), webhooks (HMAC signing), triggers (time/queue/api)
-
Integration Service: connectors, connections (OAuth flow), activities, IS triggers, agent-workflow reference resolution
-
**Data Fabric **: UiPath's structured, typed data store. **⛔ STOP — before ANY
command, Read
references/data-fabric/data-fabric.md
.The reference carries Critical Rules (folder-scope prompt flow, irreversible-op gates, complex-field config), request-body schema, per-type operator matrix, and routes to topic files:
,
,
filter-platform-contract.md
,
,
,
. Surfaces:
- Entities — schemas with typed columns, per-type constraints (, / , ), choice-set / relationship / file fields, / / evolution.
- Records — insert / update / delete / list / get / with server-side filters, sorting, pagination, group-by, and aggregates (, , , , ).
- DF filter body uses
filterGroup.queryFilters[]
— full shape in .
- Files — binary attachments stored on -typed fields via
files upload / download / delete
(record-level writes silently strip FILE values; the dedicated verbs are mandatory).
- Choice sets — shared enumerations consumed by / fields; values use immutable integer s, not labels.
- Folder scoping — tenant-level OR folder-scoped via on every write, on / .
- CSV bulk import —
uip df records import <entity-id> --file <path.csv> --output json
. Basic field types only; complex fields (CHOICE_SET, RELATIONSHIP, FILE, AUTO_NUMBER) require records insert --file <json>
.
For Query / Create / Update / Delete / GetById connector nodes
inside a , hand off to
— that skill owns the in-flow node JSON,
, and connection-resource layout.
-
LLM Gateway — BYO product configurations:
uip llm-configuration byo-connections
(
list / get / create / update / delete / list-product-configs
). Register tenant-owned OpenAI / Azure OpenAI / AWS Bedrock / Google Vertex / Anthropic / OpenAI-compatible keys against UiPath product features (agents, agenthub, jarvis, IXP, agent builder, ECS). Two input shapes: single-mapping (for
features) and repeated
(required for
/
). Server-side validation is mandatory.
-
LLM Gateway — diagnose a failing BYO config: re-probe the underlying IS connection with
byo-connections get <id> --force-refresh
, force a fresh server-side probe with an idempotent
, audit the tenant with
list --include-connection-details
filtered on
connectionState != Enabled
, check catalog drift with
, and cross-reference trace evidence with
uip traces spans get <trace-id>
. The gateway does
not expose per-request invocation logs via CLI — diagnosis is current-state + trace evidence only. See
references/llmgateway/byo-connections.md
§ Diagnostics. For tenant-wide AI Trust Layer policy that may be overriding routing, see
uipath-governance.
-
AI Trust Layer — BYO guardrail (BYOG) configurations:
uip guardrails byo-configurations
(
list / list-validators / probe / create / update / delete
) — manage tenant-registered external guardrail validator providers (e.g. Azure AI Content Safety, Databricks AI Guardrails), each backed by an Integration Service connection.
is tenant-unique and is the only value agents reference (
ByoValidator(<ValidatorName>)
— the connection resolves server-side). Before creating,
(the name must be free) and
(for
);
always probes the connection/validator pair server-side and aborts if the probe fails, with no skip flag, and
re-probes whenever
changes.
and
test a pairing without saving anything;
merges supplied fields and can flip
/
;
requires
; no
verb. See
references/guardrails/byo-configurations.md
. For authoring a guardrail against one of these configurations (low-code or coded), see
uipath-agents.
-
Traces:
uip traces spans get <trace-id>
(LLM/agentic execution observability)
-
Context grounding: knowledge indexes for semantic search / RAG —
(
from a bucket or connection
to poll ingestion status
). Agents and flows consume these indexes as tools. See
references/context-grounding/index-management.md
.
-
Platform licensing: tenant license allocations, user/group bundle assignments, consumables reporting (
uip platform tenants licenses
,
,
,
— the only consumables verb; summary/daily/folders are
values)
-
CLI tooling itself:
uip tools list/search/install
,
For
lifecycle (init / pack / publish / deploy / activate / upload) and CI/CD pipelines that build and deploy UiPath solutions, load
.
Auth token location
The default login stores credentials at
:
UIPATH_URL=https://cloud.uipath.com
UIPATH_ORGANIZATION_NAME=my_org
UIPATH_TENANT_NAME=my_tenant
UIPATH_ACCESS_TOKEN=eyJ...
UIPATH_ORGANIZATION_ID=...
UIPATH_TENANT_ID=...
Named profiles store credentials at
~/.uipath/profiles/<name>/.auth
. Use named profiles when the user asks to keep multiple UiPath logins on the same machine:
bash
uip login --profile dev --output json
uip login status --profile dev --output json
uip login which --profile dev --output json
Rules:
- is a global option. Pass it on every command that should use that login, for example
uip --profile dev or folders list --output json
.
- means the built-in unprofiled login and maps back to .
- Profile names may contain only letters, numbers, , , and . Never use paths like .
- and auth-command are mutually exclusive. Use one or the other.
- A missing named profile does not fall back to or Robot credentials. Tell the user to run
uip login --profile <name>
.
These tokens can be reused for direct Orchestrator REST API calls when CLI commands don't cover a use case. If a named profile is active, read the path from
uip login which --profile <name> --output json
rather than assuming
.
Quick Start
Step 1 — Authenticate
Before interacting with Orchestrator, solutions, or Integration Service, the user must be logged in.
Always check first — most sessions are already authenticated:
bash
uip login status --output json
If it reports
, skip the rest of this step. There is no
flag —
is the verification subcommand.
If the user names a profile, check that profile explicitly:
bash
uip login status --profile dev --output json
Interactive login (browser OAuth2): opens a browser window on the user's machine and blocks until they complete it. In a non-interactive or automated session, do NOT run it yourself — tell the user to run it and wait.
For a named interactive login:
bash
uip login --profile dev --output json
For a custom authority (e.g., alpha.uipath.com):
bash
uip login --authority "https://alpha.uipath.com/identity_" --it --output json
For non-interactive (CI/CD) scenarios, use client credentials:
bash
uip login --client-id "<ID>" --client-secret "<SECRET>" --tenant "<TENANT>" --output json
Step 2 — Select a Tenant
List available tenants and set the active one:
bash
uip login tenant list --output json
uip login tenant set "<TENANT_NAME>" --output json
Step 3 — Explore Orchestrator
List folders to orient yourself:
bash
uip or folders list --output json
Step 4 — Work with Orchestrator Resources
Choose the appropriate operation from the Task Navigation table below. For
ops, load
.
Task Navigation
| I need to... | Read these |
|---|
| Authenticate / manage tenants | references/uip-commands.md |
| Set up folders, users, machines | references/orchestrator/setup-environment.md |
| Run and monitor jobs | references/orchestrator/run-jobs.md |
| Manage sessions and runtimes | references/orchestrator/manage-sessions.md |
| Tenant settings, calendars, audit logs | references/orchestrator/tenant-admin.md |
| Understand Orchestrator concepts | references/orchestrator/orchestrator.md |
| Manage assets | references/orchestrator/manage-assets.md |
| Work with queues and queue items | references/orchestrator/process-queues.md |
| Work with storage buckets and files | references/orchestrator/work-with-storage.md |
| Set up triggers and webhooks | references/orchestrator/triggers-and-webhooks.md |
| Develop / pack / publish / deploy / activate solutions; set up CI/CD | /uipath:uipath-solution |
| Debug LLM/agent traces (spans) | references/traces/traces.md |
| Annotate traces with feedback | references/traces/feedback.md |
| Use Integration Service | references/integration-service/integration-service.md |
| Use Data Fabric — entities, records, files, choice sets | references/data-fabric/data-fabric.md |
| Build an entity schema / add fields / complex field types | references/data-fabric/entity-schema.md |
| Query records — filters, pagination, aggregates, choice/relationship semantics | references/data-fabric/records-query.md |
| Filter operator support matrix per field type | references/data-fabric/filter-platform-contract.md |
| Manage choice sets and choice-set values | references/data-fabric/choice-sets.md |
| Upload / download / delete file attachments on records | references/data-fabric/file-attachments.md |
| Bulk import records from CSV | references/data-fabric/bulk-import.md |
| Configure BYO LLM keys (OpenAI / Azure OpenAI / Bedrock / Vertex / Anthropic) | references/llmgateway/byo-connections.md |
| Diagnose / audit / re-probe a BYO LLM configuration | references/llmgateway/byo-connections.md#diagnostics |
| Manage BYO guardrail (BYOG) configurations (list/create/update/delete) | references/guardrails/byo-configurations.md |
| Test whether a connection can serve a BYOG validator (probe / list-validators) | references/guardrails/byo-configurations.md#validation-mandatory-before-save |
| Diagnose a BYO guardrail (dead connection, disabled config) | references/guardrails/byo-configurations.md#diagnostics |
| Allocate licenses to tenants | references/licensing/tenant-allocations.md |
| Assign user/group license bundles | references/licensing/user-licenses-allocations.md |
| Report on license consumption | references/licensing/consumables-report.md |
| Understand licensing concepts | references/licensing/licensing.md |
| Full CLI command reference | references/uip-commands.md |
| Build/run/validate coded workflows | /uipath:uipath-rpa |
Resolving UiPath Studio
Some operations (creating projects, validating, running workflows, packing) require UiPath Studio. When Studio is needed:
-
Check for a running instance first:
bash
rpa-tool list-instances --output json
-
If no instance is running, try the standard install location:
bash
rpa-tool start-studio --output json
-
If that fails (version too old, not found, etc.) — ASK THE USER where their Studio build is located. Do NOT search the entire filesystem. Common locations include:
C:\Program Files\UiPath\Studio
- A dev build directory (e.g.,
dev4/Studio/Output/bin/Debug
)
- A custom install path
-
Once you have the path, pass it explicitly:
bash
rpa-tool start-studio --studio-dir "<STUDIO_DIR>" --output json
Never spend time searching for Studio automatically. If the default doesn't work, ask immediately — the user knows where their build is.
Key Concepts
UiPath Platform Hierarchy
Organization
└── Tenant(s)
└── Folder(s) ← Orchestrator folders (logical containers)
├── Processes ← Published automation packages
├── Assets ← Key-value configuration (Text, Bool, Integer, Credential, Secret)
├── Queues ← Work item queues for distributed processing
├── Jobs ← Running/completed process executions
├── Triggers ← Event-based or queue-based job triggers
├── Schedules ← Time-based job scheduling (cron)
├── Storage Buckets ← File storage for automation data
├── Machines ← Robot execution environments
└── Robots ← Attended/Unattended execution agents
Robot Types
| Type | Description | Use Case |
|---|
| Attended | Runs alongside a human user, triggered via UiPath Assistant | Front-office tasks, user-assisted automation |
| Unattended | Runs autonomously in virtual environments, managed by Orchestrator | Back-office tasks, scheduled processing, 24/7 operations |
Folder Types
| Type | Description |
|---|
| Standard | Default folder for organizing automations |
| Personal | User-specific workspace |
| Virtual | Logical grouping without physical separation |
| Solution | Folder created by solution deployment |
| DebugSolution | Debug variant of a solution folder |
Asset Types
| Type | Description |
|---|
| Text | Plain text value |
| Bool | Boolean (true/false) |
| Integer | Numeric integer value |
| Credential | Username + password pair |
| Secret | Encrypted secret value |
| DBConnectionString | Database connection string |
| HttpConnectionString | HTTP connection string |
| WindowsCredential | Windows credential pair |
CLI Overview
The UiPath CLI (
) is a unified command-line tool for interacting with the UiPath platform:
| Command Group | Prefix | Description | Status |
|---|
| Authentication | , | OAuth2, client credentials, PAT, tenant management | Available |
| Orchestrator | | Folders, jobs, processes, releases | Available |
| Resource | | Assets, queues, queue items, storage buckets, bucket files | Available |
| Integration Service | | Connectors, connections, activities, resources | Available |
| Data Fabric | | Entities, records, files, choice sets () | Available |
| Tools | | CLI tool extension management | Available |
| MCP | | Model Context Protocol server | Available |
| Coded Agents | | Python agent lifecycle (setup, exec) | Available |
| RPA | | RPA workflow management (create, compile, validate, execute) | Available |
Global Options
| Option | Description | Default |
|---|
| Output format: , , , | (interactive), (non-interactive) |
--output-filter <expression>
| JMESPath expression to filter JSON output | -- |
| Use a named auth profile from ~/.uipath/profiles/<name>/.auth
| built-in default login |
| Enable verbose/debug logging | Off |
| / | Display help for the command | -- |
| / | Display CLI version | -- |
Always use when calling
commands programmatically. JSON is compact and machine-readable.
To narrow results, use the noun's own filter flag (
,
,
,
,
,
). The backend filters before sending; pagination stays correct. Per-noun flags:
references/uip-commands.md. Never list-everything-then-filter-mentally.
Use (JMESPath) for output reshaping or for fields with no server-side flag — e.g.,
--output-filter "Data[].{id: id, name: name}"
, or filtering by a derived/computed value. Don't reach for it when the server already has a filter for that attribute.
Deployment Notes
- Starting jobs requires runtimes. If you get error 2818 "no runtimes configured", the target folder needs machine templates with Unattended/Development runtimes assigned.
- For pack / publish / deploy / activate flows, load . This skill owns the auth and Orchestrator surface those flows depend on; the solution skill owns the lifecycle commands.
- Fallback: direct REST API. When CLI tools don't support an operation, use the Orchestrator REST API with the access token from . See references/orchestrator/orchestrator.md - REST API.
References
- CLI Command Reference — Every command with workflow links
- Orchestrator — Concepts, folders, jobs, processes, machines, users
- Resources — Assets, queues, buckets, triggers, libraries, webhooks
- Solutions — Solution lifecycle (
uip solution init/pack/publish/deploy/activate
)
- Planner — PDD/SDD design + multi-skill task planning (Process → Solution Design Document → task list)
- Traces — Spans — LLM execution trace observability
- Traces — Feedback — Annotate traces with sentiment and comments
- Integration Service — Connectors, connections, activities, resources
- Data Fabric — Entity schemas, records CRUD, query filters and aggregates, choice sets, file attachments, CSV bulk import, folder scoping
- LLM Gateway — BYO Connections — Register tenant-owned LLM keys against UiPath products
- Guardrails — BYOG Configurations — Manage tenant-registered bring-your-own guardrail (BYOG) configurations and diagnose their underlying Integration Service connections
- Licensing — Tenant allocations, user/group bundles, consumables reporting
- Coded Workflows — Building coded automation projects
Trouble? If something didn't work as expected, use
to send a report.