September 10, 2026
Rush CLI 0.2.49
Install
macOS / Linux
curl -fsSL https://cdn.getrush.ai/install.sh | bashWindows
irm https://cdn.getrush.ai/install.ps1 | iexHomebrew
brew install phnx-labs/tap/rushDebian / Ubuntu
sudo apt install rush-cliAlready installed?
rush upgradeRemoved
rush cloud computersno longer lists your registered machines (PHNX-3751). The computers fleet endpoint is deleted from Rush Cloud, so the command now shows Rush Cloud compute only — warm agent-host pods and running cloud executions. Themachinesource row and the per-machine busy attribution are gone; a running execution that names a computer shows it in the DETAIL column instead.
Added
rush run --keep: keep the sandbox after the task so the run can be paused, resumed and sent follow-up messages. Without itrush rundispatches an ephemeral run, torn down when the task finishes (the API's own default stays resumable, and the hiddenrush cloud runstill uses it).rush artifactsis the Cloud artifact command.list,view, andsharetalk to/api/v1/artifacts.rush artifacts share <id>printshttps://share.getrush.ai/a/{id}. This is not the local session-directory group deleted in PHNX-4039.rush agentsverbs tightened (PHNX-4046). Barerush agentsnow lists saved agents (columns HANDLE, HARNESS, MODEL, EFFORT, NAME; the handle comes first because it is the only identifiershow/edit/rmresolve, and NAME is blank when it equals the handle) instead of printing help.rush agents new <name> [flags]is create's flag-driven form —--harness claude|codex|opencode(required outside a TTY),-m/--model,-e/--effort,--fast,--plugin(repeatable),--allow(repeatable),--browser,--computer,-f/--file agent.yaml|json— so a one-liner saves an agent without the interactive wizard; a TTY still falls into the wizard for whatever--harnessand friends leave unset.-f/--fileis the whole definition: combining it with any of the field flags is an error that names the extra flags (there is no merge precedence to guess). A--harnessthe catalog marks unavailable fails before any save with the same reason the wizard gives.rush agents showandrush agents rmare new names forview/archive.rush agents edit --set key=value(repeatable;model,effort,speed) applies a non-interactive edit without the wizard.create,list/ls,view, andarchiveremain registered as hidden aliases — nothing that scripts against the old verbs breaks.--from/-fnow also accepts a YAML file (.yaml/.yml), converted to the same JSON shape the API takes, soagent.yamlandagent.jsonboth work.- The run lifecycle is the top-level surface (PHNX-4046).
rush run,ps,logs,send,attach,stop,pause,resume,open,artifacts, andtranscriptreplacerush cloud <verb>inrush --help, which now shows four groups: Account, Agents, Runs, Other. Each verb is a thin command over the existingcloudimplementation — same dispatch, same log stream, same pickers. rush run <agent>[@version] [prompt]: the agent isclaude,codex,opencode, a full name (anthropic/claude-code), a pinnedclaude@2.1.263, or a saved agent handle fromrush agents; the prompt is the second positional or-f FILE(-f -for stdin).-r/--repo(repeatable) names the repository; when omitted, the GitHuboriginof the current checkout is used and printed. Flags:-b/--branch(was--base-branch),--pr N(was--on-pr),-m/--model,-e/--effort,--fast(was--speed fast),--account,--project, and-d/--detach, which prints the run id on stdout and returns instead of following the run.rush run --accountaccepts whatrush disconnectaccepts: an account id, a unique id prefix, a label,provider:label(anthropic:work), or a bare provider name unique in your pool. The reference is resolved throughresolveAccountRefbefore dispatch and the id is whatPOST /cloud-runsreceives; an ambiguous or unknown reference fails before any run starts, naming the exactprovider:labelforms to retype. When the reference was not the id itself,Using account <provider>:<label> (<id>)is printed on stderr. The hiddenrush cloud run --accountstill takes the id only.agents edit --set account=/--set repo=still error (no agent-profile field), now pointing atrush run --account/rush run -ras the per-run path.rush agents rm(and the hiddenarchive) take-y/--yesto skip the confirmation prompt, the same flaglogout,disconnectandupgradecarry.rush open <run> [--pr]: opens the run's console page (https://cloud.getrush.ai/console/runs/<id>) or, with--pr, its pull request in the default browser; prints the URL when there is no display or the opener fails, and says so when the run has no PR yet.rush artifacts <run> [NAME] [--get]: a run's output files, on the sameartifactscommand aslist|view|share;--getdownloads every artifact of the run (a NAME still downloads one;-ostill sets the destination).rush connect anthropic|openai [--subscription|--api-key] [--label] [--default](PHNX-4046): one noun per provider for every model-provider credential.--subscriptionruns the provider's own sign-in (claude setup-token/codex login);--api-keyvaults a pasted key via a hidden prompt or stdin — never a--key/--tokenflag value. With neither flag in a TTY, an interactive picker asks "Your subscription / Your API key / Cancel"; non-interactively it errors naming the flags.grok/cursor/copilotnow accept the same--api-key/--label/--defaultflags (their existing--keyflag still works);--subscriptionon them errors with "no subscription sign-in for<provider>" (they have none).githubis unchanged. Every account prints one line on success:✓ <id> · <provider> · subscription|api key · <label> · <identity>[ · default]— this replacesgrok/cursor/copilot's old"<label> API key stored — cloud runs for this provider will use it"line; a script grepping the old string needs updating. The prompt reads the key with echo off on a terminal (golang.org/x/termReadPassword); a pipe is read as one line.grok/cursor/copilothold one key per provider server-side, so runningconnect <provider>again rotates that key in place and prints✓ reconnected <id> · <provider> · api key · <label>[ · default]; the existing label is kept unless--labelis passed, and--defaultstill applies.rush accounts: one table for every credential Rush Cloud can dispatch with — thecloud_user_accountspool (claude, claude-api-key, codex, openai-api-key, grok, cursor, copilot) plus the GitHub App installation. Columns: ID, PROVIDER, TYPE, LABEL, IDENTITY, DEFAULT, USED BY (--jsonfor machine-readable output). Footer: "Anything not listed runs on Rush credits."accounts listandconnect view/statusare now hidden aliases of the same table.rush disconnect <account>: accepts an account id, a unique id prefix, a label,provider:label, or a bare provider name unique in your pool. Several accounts of that provider list the candidates and ask (a TTY) or fail with the exactprovider:labelform to retype (a script).disconnect githubis unchanged. Prints✓ <id> removed · <provider> · <type> · <label>.resolveAccountRef(internal/cli/cloud_accounts.go) is the one exported resolver behinddisconnectand--account/--agentflags other commands add later — id | unique id-prefix | label |provider:label| bare-provider-if-unique. An id prefix shared by more than one account is an error listing the candidates, fordisconnectand forcloud accounts view|edit|removealike; an exact id or label still resolves outright.
Changed
rush run [AGENT] [PROMPT]: the documented syntax no longer carries a harness version pin. AGENT is a saved agent or a built-in harness; the pod runs the current harness version and the run detail shows which version ran.claude@2.1.263is still accepted for existing scripts.agents edit's non-interactive save prints<handle> · revision N(no longer "Updated ... · revision N" or the next-run hint, which only applies to a fresh create).agents rm's confirmation and success text changed from "Archive ... New runs will be blocked" / "Archived ..." to "Retire ...? Runs already started keep their snapshot" / "retired", matching the new verb name;agents archive(hidden alias) shares the text.rush cloudand every subcommand,rush ssh, andrush httpstay registered and unchanged but are hidden fromrush --help.rush sshno longer aliasesattach;rush attachis its own top-level command with the same implementation. On the hiddencloud run,-mstill means--mode; onrush runit is--model.- No-paste BYOS sign-in:
rush cloud accounts add --provider claude|codexnow runs the provider's native login (claude setup-token/codex login) and vaults the captured token — no manual paste.--token/--from-fileremain explicit overrides that skip the sign-in;claude-api-key/openai-api-keystill prompt for the key. rush cloud accountsand the pre-4046rush connect codex|grok|cursor|copilotspellings stay registered but are now hidden — superseded byrush accounts/rush connect <provider>. Rewordedcloud accounts' stale help text: a subscription account added with a captured token (the normalclaude setup-token/codex loginflow) dispatches through the per-user vault since BYOS (commit 7bf317c62); only a bare, tokenless registration is still a non-dispatchable reference marker.
Removed (never added)
agents new/agents edit --setdeliberately ship no--accountor--repoflag (and--set account=/--set repo=/--set harness=are rejected with a specific error).agent_profiles(rush/cloud/migrations/161_agent_profiles.sql) and theAgentProfileCreateRequest/AgentProfilePatchRequestcontract (rush/cloud/src/cloud/agent-profile-contract.ts) carry no account or repo field, andharnessis immutable once a profile is saved (ProfilePatchnever serializes it). Adding these flags now would invent API surface that doesn't exist yet. For the same reason the bare-agentslist ships HANDLE/HARNESS/MODEL/EFFORT/NAME only, not the ACCOUNT/REPO columns floated for it — every row would show the same unbacked "Rush credits"/empty value today.
Downloads
| Platform | Binary | SHA-256 |
|---|---|---|
| macOS · Apple Silicon | download | — |
| macOS · Intel | download | — |
| Linux · x64 | download | — |
| Linux · arm64 | download | — |
| Windows · x64 | download | — |
| Windows · arm64 | download | — |
Checksums are published for the current latest release. Verify older binaries against rush --version after install.