CLI & Subcommands¶
kasas is a single binary with a handful of subcommands. The default is serve.
-config path— path to a TOML config file. Also read fromKASAS_CONFIG. Configuration can come entirely from environment variables, so the flag is optional.- Every subcommand loads configuration and sets up logging first.
serve¶
The default. Runs the HTTP server (REST API, MCP, dashboard) and the
background sync scheduler, plus the retention pruners, the
webhook dispatcher, the plugin manager,
and the daily update check — each only if enabled. Runs until
SIGINT/SIGTERM, then shuts down gracefully (see
lifecycle).
sync¶
Runs exactly one sync and exits — useful for a cron job or a one-shot backfill. Applies the same insert/refresh/rules logic as a scheduled run.
migrate¶
Applies the embedded goose migrations
for the active dialect and exits. Migrations also run automatically on serve, so
this is for running them explicitly.
migrate-postgres¶
Copies the current SQLite ledger into a Postgres database and exits — the one-time move from the default embedded backend to Postgres. It applies the kasas schema to the target, then copies every table (accounts, transactions, rules, events, history, settings, …) with ids preserved, and prints a per-table row count. See the migration guide for the full walkthrough (the same thing is available from the dashboard's Settings → Migrate to Postgres panel).
The target DSN may be passed as the first argument or with -dsn. Requirements:
- the active
database.drivermust besqlite(there must be a ledger to copy from); - the target Postgres database must be empty (kasas refuses a non-empty one rather than risk a half-merged ledger);
- the source SQLite database is only read — it is left untouched, so you can verify Postgres before switching.
It does not change your configuration: after it succeeds, set
database.driver=postgres and database.dsn (or KASAS_DATABASE_DRIVER /
KASAS_DATABASE_DSN) and restart kasas to run on Postgres.
mcp¶
Serves the MCP server over stdio, for desktop MCP
clients that launch a subprocess. (Over HTTP, MCP is mounted at /mcp by serve.)
healthcheck¶
Probes the local /healthz endpoint and exits non-zero on failure. It backs the
container HEALTHCHECK, which can't shell out in a scratch image.
self-update¶
kasas self-update # download, verify, and replace the running binary
kasas self-update -check # report whether a newer release exists; install nothing
Fetches the latest GitHub release, downloads the asset matching your OS/arch,
verifies it against the published .sha256 (refusing to proceed on a mismatch or
missing checksum), and atomically replaces the binary. You need write access to its
directory; restart afterwards to run the new version. A dev/source build that
isn't a released version is reported rather than overwritten.
See Deployment → Updating for the
Docker, dashboard, and config (update.check, update.allow_apply) angles.
version¶
Prints the build version and exits. The version is stamped at build time via
-ldflags "-X main.version=…".