Unreleased documentation. These pages follow the main branch and can change before the next release. For supported guidance, use v0.26.1.
evidencectl access client add command reference
Add one local client and generate its private key.
Contract status
Section titled “Contract status”This page is generated from the public Clap command tree for Registry Stack source version 0.34.0 and catalog SHA-256 c9eb944fbb64b3beca0250dc0dee945ea12d5c5f92ffeab2f7c21d9eeb888c6c. Hidden implementation commands are omitted.
evidencectl access client add [OPTIONS] --policy <POLICY> --generate-local-key <CLIENT>Constraints
Section titled “Constraints”| Condition | Requirement |
|---|---|
--grant-bootstrap-resource <GRANT_BOOTSTRAP_RESOURCE> is present | --grant-bootstrap-scope <GRANT_BOOTSTRAP_SCOPE> is required. |
--first-party-bootstrap-scope <FIRST_PARTY_BOOTSTRAP_SCOPE> is present | All of --first-party-bootstrap-resource <FIRST_PARTY_BOOTSTRAP_RESOURCE>, --first-party-issuer <FIRST_PARTY_ISSUER> are required. |
--first-party-bootstrap-resource <FIRST_PARTY_BOOTSTRAP_RESOURCE> is present | All of --first-party-issuer <FIRST_PARTY_ISSUER>, --first-party-bootstrap-scope <FIRST_PARTY_BOOTSTRAP_SCOPE> are required. |
--first-party-issuer <FIRST_PARTY_ISSUER> is present | All of --first-party-bootstrap-resource <FIRST_PARTY_BOOTSTRAP_RESOURCE>, --first-party-bootstrap-scope <FIRST_PARTY_BOOTSTRAP_SCOPE> are required. |
| Command invocation | --first-party-bootstrap-scope <FIRST_PARTY_BOOTSTRAP_SCOPE> and --grant-bootstrap-scope <GRANT_BOOTSTRAP_SCOPE> cannot be used together. |
Arguments
Section titled “Arguments”| Argument | Always required | Default | Values | Environment | Description |
|---|---|---|---|---|---|
<CLIENT> | Yes | n/a | n/a | n/a | Lowercase client identifier |
Options
Section titled “Options”| Option | Always required | Repeatable | Default | Values | Environment | Description |
|---|---|---|---|---|---|---|
--policy <POLICY> | Yes | Yes | n/a | n/a | n/a | Access policy assigned to this client. Repeat for more than one |
--generate-local-key | Yes | No | n/a | n/a | n/a | Generate an owner-only P-256 key for local client authentication |
--grant-bootstrap-scope <GRANT_BOOTSTRAP_SCOPE> | No | No | n/a | n/a | n/a | Use institutional task exchange with this one bootstrap scope |
--grant-bootstrap-resource <GRANT_BOOTSTRAP_RESOURCE> | No | No | n/a | n/a | n/a | Bootstrap resource audience. Omit to use the shared issuer owner’s default |
--first-party-bootstrap-scope <FIRST_PARTY_BOOTSTRAP_SCOPE> | No | No | n/a | n/a | n/a | Use a signed first-party context with this one bootstrap scope |
--first-party-bootstrap-resource <FIRST_PARTY_BOOTSTRAP_RESOURCE> | No | No | n/a | n/a | n/a | Exact resource for the first-party bootstrap credential |
--first-party-issuer <FIRST_PARTY_ISSUER> | No | No | n/a | n/a | n/a | Exact trusted issuer of the signed first-party context |
--format <output_format> | No | No | human | human, json | n/a | Select human-readable or machine-readable output |
-h, --help | No | No | n/a | n/a | n/a | Print help |
Generation contract
Section titled “Generation contract”Run npm run generate from docs/site after changing a public command, argument, option, default, environment binding, or help description.