These are sample scripts showing how to extend the REPL without touching its main code
(src/index.ts, src/commands.ts). Each one is a small, self-contained example of a task built on
top of the KeeperSdk — a starting point to copy and adapt for your own workflows.
Run any of them from inside the REPL with the built-in run command:
run scripts/<file>.ts [args...]
run loads the file with require() (so it's re-compiled by ts-node on the fly — no build step)
and calls its default export with the live, already-authenticated vault plus whatever arguments
followed the file path on the command line.
A script is any .ts file with a default export matching:
export default async function myScript(vault: KeeperVault, args: string[]): Promise<void> {
// ...
}vaultis the sameKeeperVaultinstance the REPL logged in with — already authenticated and synced, so there's no separate login/sync step to write.argsis everything typed after the script path, split on whitespace (e.g.run scripts/lock_unlock_user.ts unlock alice@example.com→args = ['unlock', 'alice@example.com']).- Errors thrown from the script are caught by the
runcommand and printed withlogger.warn— the REPL session keeps going either way, so it's safe to experiment.
get_online_controllers.ts— calls the PAM router directly (pamGetOnlineControllersMessage) to list connected gateways, independent of the built-inget_online_controllerscommand.send_controller_message.ts— sends aRouterControllerMessageto a specific gateway and pretty-prints its (doubly-JSON-encoded) reply. Shows how to call a lower-levelkeeperapirestMessages.tshelper directly from a script.lock_unlock_user.ts— locks or unlocks one or more enterprise users viavault.actionUsers(...), reusing the same formatting helpers as thesdk_exampleCLI.
None of these are REPL commands — they're the "customize without recompiling the tool" escape
hatch. If something you build here turns out to be useful as a permanent command, promote it into
src/commands.ts instead.