Registry stack documentation: machine-readable Markdown.
Index of all pages: https://docs.registrystack.org/llms.txt
Full corpus: https://docs.registrystack.org/llms-full.txt

# bregctl import-authority open command reference

> Generated syntax and options for bregctl import-authority open.

{/* Generated from Clap command definitions by scripts/generate-cli-reference.mjs. Run npm run generate. */}

Open one bounded authority for an `import` grant of the active package.

## Contract status

This page is generated from the public Clap command tree for Registry Stack source version `0.39.0` and catalog SHA-256 `253866140eb693976375943a07adfce3e3efb9724c0b0fcdff8b37aed3ac7280`. Hidden implementation commands are omitted.

## Usage

```text
bregctl import-authority open [OPTIONS] --runtime-config <ABSOLUTE_FILE> --entity <ENTITY> --profile <PROFILE> --max-items <COUNT> --operator-reference <REFERENCE> --reason <TEXT>
```

## Options

| Option | Always required | Repeatable | Default | Values | Environment | Description |
| --- | --- | --- | --- | --- | --- | --- |
| `--runtime-config <ABSOLUTE_FILE>` | Yes | No | n/a | n/a | n/a | Absolute Base Registry Engine runtime configuration file. A symbolic link at any component of this path is refused. |
| `--entity <ENTITY>` | Yes | No | n/a | n/a | n/a | Entity the authority admits creates for |
| `--profile <PROFILE>` | Yes | No | n/a | n/a | n/a | Access profile holding the entity's `import` grant |
| `--max-items <COUNT>` | Yes | No | n/a | n/a | n/a | Most records every run under the authority may create, together |
| `--expires-in <DURATION>` | No | No | `7d` | n/a | n/a | How long the authority stays open: whole minutes, hours, or days (`90m`, `12h`, `7d`), at most 30 days. There is no extension |
| `--input-sha256 <SHA256>` | No | Yes | n/a | n/a | n/a | SHA-256 input digest a run must announce, as `bregctl data validate` reports it. The client computes it and the run records it; the server does not recompute it over the written items. Repeat to allow several; omit to admit any |
| `--operator-reference <REFERENCE>` | Yes | No | n/a | n/a | n/a | Operator change reference recorded as a keyed hash |
| `--reason <TEXT>` | Yes | No | n/a | n/a | n/a | Reason recorded as a keyed hash, never in clear |
| `--format <FORMAT>` | No | No | `human` | `human`, `json` | n/a | Emit the selected command's report in this format |
| `-h, --help` | No | No | n/a | n/a | n/a | Print help |

## Generation contract

Run `npm run generate` from `docs/site` after changing a public command, argument, option, default, environment binding, or help description.