1. Install and sign in
npx.cmd when an execution policy
blocks the npx.ps1 shim. This applies to one-off npx commands; the global
archal commands below are unchanged.
Keep the stored control-plane credential out of source code and test subprocesses.
2. Choose a starting state
sample show --raw verifies the packaged artifact hash before printing it.
3. Create a sandbox
sessionId, provider URL, and a
scoped credential that expires with the sandbox.
4. Call the environment
Useenvironments.github.apiBaseUrl as the provider base URL. Apply every
header in environments.github.credentials.headers to provider requests.
Do not substitute the Archal workspace key. The data plane rejects it.
The TypeScript client applies these returned headers automatically:
