The connector takes an optional config path (defaults to `config.yaml`):

```bash
opex-flow                 # run with ./config.yaml
opex-flow /etc/opexmx/config.yaml
opex-flow --help
```

Validate transforms from the UI (**Check**) or the API
(`POST /api/transform/validate`) rather than a separate CLI subcommand. Set secrets via
environment variables and reference them as `${VAR}` in the config.