Model Locally with the CLI
One command turns a directory into a local modeling workspace, with a local Publisher serving your model against your real warehouse
cred init sets up a directory for local Malloy modeling. It logs you in, connects the directory to a Credible environment, installs the modeling skills, and starts a local Malloy Publisher serving your model. Your local Publisher sends its queries through Credible, so it reads the same warehouse your published models do. No warehouse credentials are stored on your machine.
It works with any coding agent that reads a project directory: Claude Code, Codex, Cursor, Gemini CLI and others.
Prerequisites
- Node.js 20+ and the CLI (
npm install -g @credibledata/cred-cli) - A Credible organization, and an environment whose connections your admin has set up. See Connect a Database
Get Started
Run it in an empty directory, or in an existing Malloy package:
mkdir my-model && cd my-model
cred initcred init asks for anything it doesn't know yet:
- Log in, if you aren't already.
- Pick an organization and environment. The choice is saved in the directory, so later commands there use the same pair.
- Write the workspace files (listed below), including a local proxy for each of the environment's connections.
- Install the modeling skills.
- Start the local Publisher at
http://localhost:4000and open it in your browser. Edits to.malloyfiles reload as you save.
The first run downloads the Publisher, which takes about 30 seconds. If the environment has no connections yet, the Publisher still starts, but your model has nothing to query. Ask an admin to add a connection in Credible, then run cred dev again.
Press Ctrl-C to stop the Publisher. To start it again later, run this in the same directory:
cred devcred dev reuses the saved organization and environment, refreshes the skills, and starts the Publisher in the foreground.
If a coding agent is already running in the directory, restart it after cred init so it picks up the new MCP servers. Claude Code asks once whether to trust them.
What It Writes
| File | What it is |
|---|---|
publisher.json | The package manifest, if the directory doesn't have one. The package is named after the directory |
.mcp.json | Two MCP servers: malloy, your local Publisher's MCP endpoint at http://127.0.0.1:4040/mcp, and credible, your published models |
CLAUDE.md, AGENTS.md | A short briefing for the agent: which environment, which connections, and which MCP server to use for what. Added as a marked section, so your own text is kept |
.claude/skills/, .agents/skills/ | The modeling skills |
.claude/rules/credible-modeling.md | A rule telling the agent to read the skills before modeling. Also .cursor/rules/credible-modeling.mdc when the directory has a .cursor/ folder |
.credible/config.json | This directory's saved organization, environment, ports and skills version |
In a Git repository, cred init adds .credible/ and the skill folders to .gitignore, because they belong to you rather than to the repository. cred publish leaves every file in this table except publisher.json out of the package.
Skills
cred init installs Credible's open-source skills. They go in two places:
.claude/skills/, where Claude Code finds them.agents/skills/, for Codex, Gemini CLI and other agents
It also writes a short rule file, .claude/rules/credible-modeling.md, that tells the agent to read the skills before it starts modeling. If the directory has a .cursor/ folder, it writes a Cursor rule as well.
Which skills: the modeling-ide set, the same set the VS Code extension installs. The Credible deployment you're signed in to decides which version you get, so everyone on that deployment gets the same skills. cred status --json shows the versions installed in a directory.
When skills update: every cred init and cred dev checks for a newer version of the skills. When there is one, cred replaces the files it installed last time. It never touches skills it didn't install, except as described under Keep below. When the skills are already current, nothing is written. If the skills can't be fetched, the Publisher starts anyway and the next cred dev tries again. Fully offline, cred init and cred dev stop earlier, with exit code 1, because they read the environment's connections from Credible before starting the Publisher.
Skills that were already there: a directory made with npm create @malloy-publisher/malloy-package comes with its own skills. The first time, cred init asks what to do with them:
- Replace (recommended): moves them to
.credible/replaced-skills/and installs Credible's set. Credible's set includes the same Malloy skills. Nothing is deleted. - Keep: installs Credible's set alongside them. A skill with the same name as one of Credible's is overwritten, and a later update removes it. Skills from
npm create @malloy-publisher/malloy-packageshare names with Credible's, so choose Replace for those. - None: installs no skills, and later runs remember that. Run
cred dev --skills replaceorcred dev --skills keepto start installing them.
Bring Your Own Connections
If the directory already has a publisher.config.json from a local Publisher setup, cred init offers to copy its warehouse connections into your Credible environment. Credible tests each connection before adding it, and a connection that fails its test is not added. If you named connections with --connections and any of them fails its test, none are added, so you can fix the list and run it again. A connection whose name the environment already has is not replaced: change it with cred update connection instead. DuckDB connections aren't copied: publish their files with the package instead.
Use It from an Agent or Script
Every question cred init asks has a flag. Without a terminal, cred init asks nothing. If it's missing an answer, it exits with code 2 and names the flag to pass.
# A new environment, no connections to copy, Publisher not started yet
cred init -o acme -e my-env --create-environment --connections none --no-start
# Start the Publisher in the background, then wait until it serves the package.
# -y skips the "Use organization...?" question in an interactive shell.
# The first run downloads the Publisher, so this can take about 30 seconds.
cred dev --no-open -y &
until cred status --json | jq -e '.publisher.ready' > /dev/null; do sleep 2; done| Option | Command | What it does |
|---|---|---|
-o, --organization <name> | init, dev | Use this organization, and save it for the directory |
-e, --environment <name> | init, dev | Use this environment, and save it for the directory |
--create-environment | init, dev | With -e: create the environment if it doesn't exist |
--connections <all|none|names> | init | Which connections from a local publisher.config.json to copy into Credible |
--skills <replace|keep|none> | init, dev | What to do with skills that cred didn't install |
--package <dir> | init, dev | Which package to serve, when publisher.config.json lists several |
--no-start | init | Write the files, but don't start the Publisher |
--no-open | init, dev | Start the Publisher, but don't open a browser |
-d, --directory <path> | init | Set up another directory instead of the current one |
-y, --yes | dev | Use the directory's saved organization and environment without asking. Implied without a terminal |
Publish
When the model is ready, publish it from the same directory:
cred publish --dry-run # list what would be uploaded, and upload nothing
cred publishBesides the workspace files above, the upload leaves out credential files and anything listed in a .credignore file. See the CLI reference for the full list, and Publishing for versions and setting the latest version.