NIIA 0.9.41 (niia CLI), OpenCLIs build
2026-07-19-210726. The executing binary, installed receipt, and public CDN
metadata agree on this release; the registry owns discovery copy and links.
Meet NIIA before the reference
See how one memory continues across AI CLIs; use these docs for the current command and security contract.
Start here
niia for the guide embedded in your installed binary. Use niia --version to identify the release that owns that guide.
One entry point, several owners
Capability map
Remember and search
niia index --sessions.
Investigate code and knowledge
niia code is the integrated façade. Use the standalone Monogram reference when you need region ranking, coupling audits, format planes, deep semantic analysis, or possibility-band worklists.
Use the standalone Monoflow command reference for temporal and cross-database drills or its typed 24-command MCP surface. Use Work Wiki for the full session, intent, artifact, knowledge-DB, file-biography, and convergence command set.
Carry the work-entry promise
gauge classifies TRIVIAL, MODERATE, HIGH, or CLAIM work and also
recognizes silent lookup, documentation, conversation, and continuation lanes.
An explicit user rung always wins. Risk language still produces [CONSENT],
and fan-out remains a proposal. In 0.9.41, ASCII signal words use word
boundaries, so add no longer fires inside address; Korean stems remain
substring-matched. Put all options before the trailing TASK text; tokens
after the task are not parsed as flags. --transcript <path> supplies an
ad-hoc or benchmark transcript when no hook event supplied one, allowing the
later audit to inspect that witness.
The command writes gauge.json under the repository’s
.niia/session-order/ directory, or under a cwd-hashed home path outside Git.
History is append-only, and a side-lane prompt preserves the active work rung
and [NEXT] chain. Only a session id carried by hook stdin may atomically move
the current pointer. A CLI --session <id> run writes that session’s witness
without stealing the live pointer, while ad-hoc and static probes remain
isolated. finish re-presents the promise, current Monogram sequence phase,
and HIGH-work ledger reminder before writing finish.json. audit-entry
writes audit-report.json and never blocks; escalation is an event, not a
violation. Claude JSONL is readable today, while Codex transcript auditing is
explicitly SUSPENDED until its reader ships.
Hook modes never fail the calling prompt because of an internal NIIA error:
they keep exit zero, write stderr plus ~/.niia/hook-error.log, and let
doctor expose the recent failure. doctor is the separate sub-second health
view. It checks WAL-aware database mtimes, prefers the watcher’s own dirty-pass
verdict when available, detects repeated launchd deferral, verifies all three
UserPromptSubmit/SessionStart/SessionEnd hook lanes, and checks witness
writability. Stale or failing rows carry a concrete [NEXT] recovery verb.
The complete command map documents
every option, rung, threshold, and audit class.
Close non-trivial code work as one loop
sequence start auto-runs define; there is
no separate sequence bind step. Exact routed entry IDs take priority. Use
monograph open only when no exact candidate was routed; that command chooses
the best Book for the symptom. Run finish only after the final Edit/Write,
read its closing review, and make no later source mutation.
Drive terminal sessions
Bridge MCP in both directions
key=value and structured key:=JSON arguments. Remote REST accepts scalar query arguments only. MCP, JSON-RPC, session, quota, authentication, and REST failures return a non-zero shell exit; --json keeps an MCP isError payload on stdout before that exit.
Observe and control the operating system
Reach another machine
remote exec is a diagnostic surface restricted to exact now, status, and --version requests. Terminal work uses the relay surface after reachability is proven. File transfer uses an exact Headless session rather than widening the diagnostic command allowlist.
Version 0.9.41 forwards Monosystem’s scoped remote-update contract. A dry-run
returns openclis.update-plan.v1 without installing or requiring the target’s
mutation gate. Applying an exact named scope or --all requires the target
device’s upgrade gate; openclis and openclis-vault remain local-only
because their keychain approval is interactive. Legacy remote upgrade means
NIIA only, never all tools.
Live public contract
The0.9.41 release has one command contract across all five published
platform fragments:
These counts describe different contracts. A source manifest, an installed binary, and a running MCP server are not interchangeable proof.
Release provenance and platform matrix
The public 0.9.41 build is2026-07-19-210726. Its latest.json pointer and
all five immutable platform fragments record source commit
21d3cfc0c5f6310d83b5357ed8e0f70ab2deaf94 with source_dirty: false.
The installed macOS binary’s human-readable --version suffix still reports
git 44a353a5b, the immediately preceding 0.9.40 commit. The 0.9.41 binary
nevertheless passes the new hook-owned pointer probe, and the CDN pointer plus
all platform fragments own the release-source claim above. Treat the suffix as
a disclosed build-stamp residue, not as a replacement source witness.
The corresponding payload SHA-256 values are
7c20e125186aaf808bcd490db0da1970eb940aa4b4aed630bcda2189ce6ecdb9
(macOS ARM64), 5e030d8d3c88cffcb4fa1c57b6471b765ef4771ca44611df68e49cc32863da93
(Linux x86-64), e970ce57890093f77bdbd4518a1ad6f5465cbb05c33005b72ea012c8253d55b7
(Linux ARM64),
33cf6db80464bb46daf04f075544291eb2be713e5f9464f3a7d0bad9b1a6ae12
(Windows x86-64), and
5fbb95bf57f2caf9fc54161c462ab994d4b444ce095a2e5068fe86df3cc5f9a5
(Windows ARM64). No Intel macOS archive is present in the 0.9.41 metadata.
Every fragment carries the current initiate.md/SKILL.md guide pair. After
text newline normalization, their source SHA-256 values are
d6411456f4a180773fe88ae9c1a2de2ac101d584b0d0e0bf7bd8b36456761ada
and c462e327cffb20ba97d2b3acec07c69be3103e6e566e8385ccc6916ee2b80fe9.
The Windows x64 checkout stores the text with CRLF; normalization, rather than
raw-byte equality across operating systems, is the relevant guide proof.
Install and update
setup use openclis makes ~/.niia/bin/niia a symlink to
~/.openclis/bin/niia on Unix, so later OpenCLIs updates flow through that
link. setup use monolex replaces it with a regular copy. Windows cannot use
that Unix selector: setup use openclis copies the current OpenCLIs executable
to $HOME\.niia\bin\niia.exe, and a regular copy is reported as monolex by
the current status detector. Run the newly installed executable explicitly
after each Windows update when the PATH-facing copy must be refreshed:
.niia-source ownership marker. Treat the
Unix symlink target or the Windows copied payload itself as the evidence, and
verify the active result with Get-Command niia plus niia --version.
Continue
NIIA overview
Identity, memory, and the integration model.
Complete command map
All top-level families, nested commands, gates, and ownership boundaries.
AI sessions
Read, search, and safely drive sessions across AI CLIs.
Security model
Authentication, MCP failure behavior, OS unlocks, and remote restrictions.
Claude account profiles
Save, switch, and isolate Claude Code accounts without making NIIA the credential owner.