- Problem
- The opening catalogues dates before it says what the video is about.
- Now
- "Concrete is thousands of years old. Roman concrete is the strangest of all."
- Try
- Roman concrete gets stronger in seawater. Here is the chemistry that makes it work.
- Why
- The claim arrives in the first line, so the reason to keep watching is in view before the history starts.
Audit a YouTube script from your terminal
The Prepublish CLI runs the same audit as the site, from your terminal: an overall score with hook, structure and pacing breakdowns, the passages most likely to lose viewers, and a copy-paste rewrite for each one. One Go binary, no runtime dependencies.
Free without an account, three audits a day. The source is public and the license is MIT.
curl -fsSL https://prepublish.ai/install.sh | shWhat the terminal shows
The report renders to the width of your terminal, and --json prints the same response as a machine-readable struct. The excerpt below is the middle of one audit: where the draft scored, and the two fixes the model ranked first, each with the line it replaces and the reason the replacement works.
Illustrative example. The scores are a relative script-hold index over the draft, not a percentage of viewers and not a forecast of published retention. The audit reads text only; it cannot account for delivery, editing, thumbnail, topic or distribution.
Free without an account, more with one
The CLI works before you have an account, and it never insists on one. Signing in is what opens the rest of the report.
Free without an account
- Three audits a day, with no card and no signup.
- The first free audit asks for an email once, remembers it, and attaches it to the report so the follow-up can reach you.
- You get the overall score, the three breakdowns, the attention-risk map, and the biggest fix with its rewrite. The remaining rewrites stay gated.
hook,policyandauthenticityare free too, each with its own daily allowance.
Signed in
- Fifty audits a day, and the whole report: every rewrite, with its reason and its risk.
- Video and audio files can be audited as well as scripts. The CLI detects the media, transcribes it, and then runs the same report.
prepublish historylists everything the account has run, andprepublish report IDreopens any of them.
prepublish login opens the browser, then saves the key
- The CLI asks the API for a login request and prints a short code such as BCDF-GHJK.
- It opens
prepublish.ai/cli/loginwith that code already in the URL. An unknown browser goes through the email sign-in first, then returns to the approval page.--no-browserand a non-terminal print the code and the URL instead of opening anything, which is what a remote shell needs. - You approve this machine on that page. The CLI has been polling the whole time, so it receives the new key as soon as you approve it.
- The key is named CLI · prepublish-cli on <hostname> so you can recognise it in the dashboard, and it is saved locally with owner-only permissions. The request expires after ten minutes and is single use.
Audits this machine ran anonymously move onto the account at the end of the flow, so nothing is stranded under the anonymous id. prepublish logout revokes the stored key on the server first, then deletes it locally.
For CI there is no browser. Create a key in the dashboard and pipe it in once with printf '%s' "$KEY" | prepublish login --with-token, or set PREPUBLISH_API_KEY for a single run. The exported key outranks the stored file and is never written to disk for you.
Commands
Global flags work on every command: --json for machine-readable output, --no-input to never prompt, and --api-url to point one run at another API.
| Command | What it does |
|---|---|
prepublish audit [FILE|-] | The full audit. FILE is a script, or a video or audio file to transcribe on a signed-in account. Pass - to read the script from stdin. |
prepublish report ID | Print a stored report. The id is the share key, so this needs no credential, and a full report URL works in place of the id. |
prepublish history | List your audits. A pipe gets one line per audit, so a script can read the ids. |
prepublish hook [FILE|-] | Score a hook sentence by sentence, with rewrites. Free, with its own daily allowance. |
prepublish policy [FILE|-] | Pre-flight a script against YouTube’s advertiser and community guidelines, naming the published category behind each match. |
prepublish authenticity [FILE|-] | Check the inauthentic or reused-content risk in a draft. |
prepublish runtime [FILE|-] | Word count and speaking time, computed locally. No network at all, so it costs nothing. |
prepublish whoami | The account the CLI is acting as, the plan tier and today’s quota. |
prepublish login / logout | Browser sign-in with a short code. Logout revokes the stored key on the server, then deletes it locally. |
prepublish upgrade | Open the pricing page for the signed-in account. |
hook is one a day anonymously and three with an email; policy and authenticity are three a day each. A full audit already carries the authenticity and policy checks inside its report.
Scripts and CI
--json prints the API’s own response struct on stdout, two-space indented, and suppresses everything interactive: no prompts, no pager, no full-screen menu. Progress lines and warnings move to stderr, so stdout is always exactly one JSON document. Errors are JSON too, with a machine-readable code:
{
"error": {
"status": 402,
"code": "SUBSCRIPTION_REQUIRED",
"message": "Active subscription required to access this resource"
}
}prepublish audit script.md --title "Why the Roman concrete lasts" --json | jq .overall_score| Exit code | Meaning |
|---|---|
| 0 | Success. |
| 1 | A failure with no more specific code: a missing file, a 404, an unreachable API, an audit that outran --timeout. |
| 2 | The command line was wrong, and the message names the flag or the value that fixes it. |
| 3 | The API rejected the credential or the account. Run prepublish login. |
| 4 | A quota or plan limit. Upgrade, or wait for the daily reset. |
| 130 | Ctrl-C. The convention shells use for a process stopped by SIGINT. |
A key that was rejected exits 3 and a spent quota exits 4, so a wrapper can tell a bad credential from a spend limit without parsing the body. A queued audit is not a lost one either: --no-wait prints the id and the report URL, and report ID collects it later.
# CI: the key comes from the environment, so nothing is written to disk.
export PREPUBLISH_API_KEY="$PREPUBLISH_CLI_KEY"
cat script.md | prepublish audit - --title "$TITLE" --json > report.json
jq -e '.overall_score >= 60' report.json > /dev/null || exit 1The JSON is the API’s own struct and its field names are stable. The rendered report is for people and can change between releases, so parse --json rather than the screen.
Other ways to install
The installer supports macOS and Linux on amd64 and arm64, verifies the archive against the release’s own checksums.txt, and never needs sudo. By default the binary lands in $HOME/.local/bin.
curl -fsSL https://prepublish.ai/install.sh | PREPUBLISH_VERSION=v0.1.0 shcurl -fsSL https://prepublish.ai/install.sh | PREPUBLISH_INSTALL_DIR="$HOME/bin" shPREPUBLISH_DOWNLOAD_BASE points the installer at a mirror instead of GitHub Releases.
With Go, no installer
The module path is the repository, so a Go toolchain can build the same binary anywhere, including Windows.
go install github.com/prepublish/prepublish-cli/cmd/prepublish@latestWindows
There is no install script for Windows. Download prepublish_windows_amd64.zip or prepublish_windows_arm64.zip from GitHub Releases, unzip it, and put the folder on PATH.
curl -fsSL https://prepublish.ai/install.sh -o install.sh && less install.shThe same file is attached to every GitHub release, so the one prepublish.ai serves can be compared against the one in the release before either runs.
Security and privacy
- The key is stored for your user only. It lives in credentials.json inside the CLI config directory, which is created 0700 while the file is written 0600 and written atomically, so an interrupted run cannot leave a half-written file behind.
- The key belongs to the API that issued it. The file records that origin and the key is only sent back to it. Point the CLI at another API with
--api-urland it runs signed out rather than handing a production key to whatever host that flag, a shell profile or a project file named. - Exported keys are the deliberate exception.
PREPUBLISH_API_KEYoutranks the stored file, and that is the pairing that makes CI work against a staging API.logoutwill not touch it: unset it instead. - Plain http is refused. The API and app URLs must be https, or http on a loopback address, and the check applies to the flag, the environment, the config file and
config setalike. - Every key is revocable.
prepublish logoutrevokes the key on the server and then deletes it locally, and the dashboard page lists every key with its own revoke action. - The audit runs server-side. A script leaves your machine to be analysed by the same API the site uses, over HTTPS, and the stored report can be reopened later from its id. See the privacy policy.
- The source is public. The CLI is MIT licensed at github.com/prepublish/prepublish-cli, and the installer ships with every release.
Common questions
Is the CLI free?
Yes. Without an account you get three audits a day: the first one asks for an email and remembers it, and the rewrites for the remaining fixes stay gated. A signed-in Creator account raises the allowance to fifty audits a day and opens the whole report, video and audio uploads, and thumbnail checks. The plan is $29 a month, or $290 a year.
Does it predict retention?
No. Every command reads text only and maps relative attention risk inside a draft that has not been recorded. The score is a script-hold index over the draft, not a percentage of viewers, and it cannot account for delivery, editing, thumbnail, topic or distribution. Nothing it prints is a forecast of published behavior.
Does it run on Windows?
Not through the install script, which covers macOS and Linux on amd64 and arm64. On Windows, download prepublish_windows_amd64.zip or prepublish_windows_arm64.zip from GitHub Releases, unzip it, and put the folder on PATH. Go users on any platform can run go install github.com/prepublish/prepublish-cli/cmd/prepublish@latest instead.
Is the CLI open source?
Yes. The source is public at github.com/prepublish/prepublish-cli under the MIT license, and every release archive is built from that source. The installer is attached to each release too, so the file prepublish.ai/install.sh serves can be read and compared against the one in the release before it runs.
Where is my API key stored?
In credentials.json inside the CLI config directory: ~/.config/prepublish on Linux and ~/Library/Application Support/prepublish on macOS. The directory is created 0700 and the file is written 0600, so only your user can read it. The file records which API issued the key, and the key is only ever sent back to that origin. prepublish logout revokes it on the server before deleting it locally, and any key can be revoked from the dashboard.
Run it before you record
Install the CLI and audit the draft you have open, or paste it into the browser tool with no account at all. The whole report, with every rewrite and reason, is a Creator subscription at $29 a month, or $290 a year.