Use the tool first. The design notes and the phase history are below them.
On a new machine, agent-assisted-setup.md hands the install to a coding agent. The manual version is install.md.
bin/idm with no arguments is the command reference. bin/apps --help is the
Identity Applications reference. When a page and the live help disagree, follow
the help.
| Guide | Read it when you want to |
|---|---|
| ../README.md | See what DirXMLDev is and copy the first commands |
| getting-started.md | Point an already-built bin/idm at a client tree and a vault |
| tree-layout.md | Understand driverset.xml, drivers/, cases/, and the secrets files |
| day-to-day.md | Change a policy, deploy, install a package, edit a form, operate a driver |
| examples/ | Copy sanitized, fictional snippets |
| walkthrough.md | Follow the same loop in one long narrative |
| agents.md | Point any agent at the tool (Cursor, Claude Code, Codex, others) |
| mcp.md | Optional MCP server: reads, dry-runs, and gated writes over bin/idm |
| agent-guide.md | The loop and the refusal rules that agent follows |
| agent-assisted-setup.md | Have a coding agent install DirXMLDev; paste a prompt |
| install.md | Build bin/idm from source, run bin/idm doctor, and see what CI runs |
| Job | Page |
|---|---|
What validate checks |
validation.md |
| Deploy, diff, snapshot, rollback, the production gate | vault-deploy.md (design note; commands are current) |
| Start, stop, cache, trace, submit | operate.md (design note; the gate table matches the code) |
| Attach a debugger: the simulator in process, a lab engine over JDWP, the Remote Loader | operate.md §Attaching a debugger |
| Packages | packages.md |
| JSON forms and PRDs | forms.md |
Workflow activities (flow.*) |
workflows.md |
| Entitlements | entitlements.md |
| Roles, resources, entities, the rest of AppConfig | appconfig.md |
Identity Applications REST (bin/apps) |
idapps-rest.md |
| Edit operations in detail | edit-operations.md |
| Job | Page |
|---|---|
| A new Designer project from a vault, without Designer connecting | howto-fresh-designer-project.md |
What export-project --new writes |
designer-new-project.md |
| Updating an existing Designer project | designer-roundtrip.md |
| Carry a customer's vault home as a lab clone | howto-clone-vault.md, vault-clone.md |
| Read the Event Logger's store; logged events as simulator cases | event-store.md |
| Read-only policy-flow viewer | vscode-extension-v1.md, ../extensions/dirxmldev-visual/README.md |
These describe how the tool was built. They are not the place to learn a command.
| Page | What it is |
|---|---|
| plan.md | Architecture, phases, decisions, safeguards |
| model.md | The typed model and the as-code file contract |
| spikes/ | Measurements that closed a question. The same facts are in .claude/skills/dirxml-dev/reference/facts.md (plain markdown; any agent can read it) |
How an agent is set up, for any product, is agents.md. Claude Code's loader for the same rules is ../.claude/skills/dirxml-dev/SKILL.md. Measured facts are ../.claude/skills/dirxml-dev/reference/facts.md.
The DirXMLDev source is licensed under the MIT License. Release notes are ../CHANGELOG.md.
- secrets.md — where credentials come from: the four forms, and the line for each secret manager (AWS, Azure, GCP, CyberArk, BeyondTrust, Bitwarden, Vault, 1Password).
- terraform.md — secrets from a manager by name; the
idm-environmentTerraform module.