Skip to content
Registry StackDocsDevelopment (unreleased)

evidencectl keygen secret command reference

View as Markdown

One random raw secret file, 32 bytes (audit or subject-binding HMAC).

This page is generated from the public Clap command tree. Hidden implementation commands are omitted.

One random raw secret file, 32 bytes (audit or subject-binding HMAC). This is HMAC key material, not a credential a source will accept: the bytes are arbitrary and an HTTP header value rejects most of them. Use keygen token for a bearer token.

evidencectl keygen secret --out <OUT>
OptionAlways requiredDefaultValuesEnvironmentDescription
--out <OUT>Yesn/an/an/aOutput file for the raw secret (written 0600)
-h, --helpNon/an/an/aPrint help (see a summary with ‘-h’)

Run npm run generate from docs/site after changing a public command, argument, option, default, environment binding, or help description.