Importing a REDCap project
Select a Managed Session and authorized Study, then upload project information JSON, metadata JSON and records EAV CSV from the client:
ahri-tre --risk high --study HDSS ingest redcap project \
--domain REDCap \
--project-info-path ./project.json \
--metadata-path ./metadata.json \
--records-eav-path ./records.csv \
--dataset-prefix survey --format json
Use repeated --form or --skip-form selectors. --no-register-dictionary
materializes typed forms without creating dictionary entries or variable links.
Compression/encryption default to enabled. Inputs are read by the client and
transferred as three bounded, integrity-checked roles.
Artifacts retain explicit ingest risk; derived forms are High. Inspect
form_outcomes for partial results before starting another acquisition. Dataset
content still requires separate disclosure admission. Live API acquisition also feeds this workflow.
For a live export, replace the three paths with --api-url and explicitly choose
client acquisition/upload or direct Trusted acquisition. Supply a fresh token
on nonterminal stdin using the sensitive-input options:
ahri-tre --risk high --study HDSS --acquisition trusted \
--source-auth redcap --source-material-stdin ingest redcap project \
--api-url https://redcap.example/api/ --domain REDCap \
--dataset-prefix survey --form demographics --format json
Use --acquisition client for client-side fetch/upload. No source registration is
needed; the endpoint must satisfy deployment outbound policy. Never put the token
in command arguments, public request JSON or the endpoint. The runtime discards
it after acquisition and requires fresh material next time; there is no service
credential fallback. Both paths use the same authorized Study/Domain and writer.
--response-encoding utf8|iso88592, --max-attempts 1..5 and
--timeout-secs 1..120 control live exports within the acquisition’s overall
budget. Project/metadata bodies are capped at 8 MiB each. Redirects and compressed
responses are refused; interrupted writers never replay automatically. The C
acquire_https functions accept the same public live intent and separate token.