Install dependencies
qndaCli only depends on requests and jmespath, on Python 3.8+.
cd bigpeng-java/cli
pip install requests jmespath
python -m qndacli --helpqndaCli is the unified command-line tool for the Qingniu Dunan visitor system. Configure once and sign in with API credentials, then query parks, visitors and appointments from your terminal — built for ops inspection, second-party development and automation.
From install to self-check, connect to production (prod) in minutes.
qndaCli only depends on requests and jmespath, on Python 3.8+.
cd bigpeng-java/cli
pip install requests jmespath
python -m qndacli --helpSet the gateway host and the admin clientId; --use makes it the default profile.
qndaCli configure --profile prod \
--host https://qnapi.peishen.com.cn \
--client-id <admin clientId> --useSecretId / SecretKey are generated on the mini-app "API Credentials" page; they are written only to a local 0600 credentials file and never to config or logs.
qndaCli configure --profile prod \
--secret-id <SecretId> --secret-key <SecretKey> --useWith AK/SK configured, sign-in auto-signs to exchange a token; doctor should report all green.
qndaCli auth login --profile prod
qndaCli auth doctor --profile prodRead-only query commands are open today, covering parks, visitors, appointments and certificate ciphertext. Write operations and decryption APIs open progressively per review cadence.
qndaCli visit list --park <parkId> --status 1Appointment list: filter visitor appointments by park and statusqndaCli visit get <appointmentId>Appointment detail: query a single appointment by Base62 IDqndaCli visit maintenance-certs <appointmentId>Certificate ciphertext list for maintenance appointmentsqndaCli park listPark listqndaCli park get <parkId>Park detailqndaCli user list --appType 3User list: filter by app-typeqndaCli user get <userId>User detailqndaCli meta commandsShow the command tree (write commands marked W, not yet enabled)qndaCli meta refreshRefresh the descriptor onlineqndaCli is built around API credentials (AK/SK). No plaintext password is ever exposed, consistent with the zero-knowledge privacy architecture of Qingniu Dunan.
At sign-in, SecretKey signs secretId + timestamp + nonce with HMAC-SHA256; the server verifies and issues a token — the password never leaves your machine.
AK/SK and token live only in ~/.qndacli/credentials.json (mode 0600, isolated per profile); the SK is never written to config or logs.
Same as the mini-app: the platform keeps only ciphertext, keys belong to you; the CLI only queries and passes through, never touching sensitive plaintext.
All commands output JSON by default and pair with jmespath filtering, ready to drop into scripts and pipelines.
--query <jmespath>Filter / project the result with a jmespath expression, e.g. pick only certain fields
--output jsonOutput format (P0 is JSON only), for piping into jq and friends
--dry-runOnly print the request that would be sent (method / URL / params) without executing — for rehearsal and debugging
-v / --verbosePrint more detailed request and response logs
The following are on the roadmap. Not available in the current release; docs update with each launch.
Appointment create / update / cancel, and park & user management writes (opened after review)
Sensitive-field decryption (reason + audit + production confirmation required), for authorized roles only
Table-level inspection, column diff, certificate-gap scanning and other ops tools
Wrap qndaCli as a Model Context Protocol (MCP) service for AI assistants to call