Quickstart
Install the binary, sign in, pick a Build, and read its Audit. Five minutes, nothing charged.
You end this page with the current Audit of one Build in your terminal, the same Audit its Builder sees in the app. Nothing here consumes tokens.
1. Install
The installer detects macOS or Linux, verifies the release checksum, and installs bworlds into $HOME/.local/bin.
curl -fsSLO https://docs.bworlds.co/install.sh
sh install.sh
bworlds --versionPin BWORLDS_VERSION in automation and set BWORLDS_INSTALL_DIR when you want another directory. Details in Installation and updates.
2. Sign in
If you are operating a Build owned by someone else, ask its Workspace Owner to invite you first from Workspace sharing at https://app.bworlds.co/account/team, and accept the invitation with the identity you will use here. Your own Builds need no invitation.
bworlds auth loginThe browser signs you in and the CLI stores the session in your user configuration directory, readable only by you. Check what the server sees:
bworlds auth statusIdentity: Lea Marchand (@lea)
Workspaces: 2
8f1c2a7e-3b4d-4c5e-9f60-1a2b3c4d5e6f Lea Marchand (owner)
a1b2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d Atelier Nord (member)
Builds: 53. Pick the Build
bworlds repo listOperator: @lea Environment: prod
SLUG NAME WORKSPACE WORKSPACE ID LOCAL
storefront Storefront Atelier Nord a1b2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d -
inventory Inventory Desk Atelier Nord a1b2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d -Every Build command takes the slug from this list. Before acting on one, confirm what you are looking at:
bworlds build info storefrontOperator: lea (member)
Workspace: Atelier Nord (a1b2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d)
Build: storefront (3d9e7f10-2b4c-4d8e-9a1f-6c7d8e9f0a1b), builder maxime
Authorized areas: security, operations
Token balance: 1240 tokens
GitHub: connected to atelier-nord/storefront (installation 4821931)One screen tells you who you are for this Build, whether its Builder connected a repository, how many tokens the Workspace holds, and in which areas the Builder authorized BWorlds to fix code.
4. Read the Audit
bworlds audit show storefrontResults (17 Controls):
FAIL (2):
app-open-access FAIL
Found: Signed-out visitors can reach content identified as private.
Why: Requiring a sign-in stops anyone with the link from seeing private information or using paid features.
Fix: Require a signed-in session on private pages and redirect other visitors to sign-in.
privacy-policy FAIL
Found: A published privacy policy was not found on the app pages checked.
Why: A clear privacy policy tells people what information the app collects and how it is used.
Fix: Publish a privacy policy and link it from the footer.
pending (3):
data-backup pending
code-ownership-clean pending
version-control pending
pass (12):
secrets-exposed pass
database-not-public pass
https-enabled pass
...Every failed Control comes with what BWorlds found, why it matters, and how to fix it. This is the Audits screen of the Build in the app, and reading it is free. Pending Controls are still running or wait for the Builder's answer to a question in the app.
Next
- Hand this to a coding agent: Coding agent workflows.
- Rerun the Audit, reevaluate one Control after a fix, correct a verdict: Audits and Controls.
- See what breaks in production: Production evidence.
- Run unattended with a personal token: Agents and automation.