Released docs. You are viewing the documentation published with v0.34.0. Development docs are available at Latest.
evidencectl keygen client-assertion command reference
Keypair a source’s clientAssertionKeyRef points at, for a token endpoint that authenticates the client by signed assertion.
Contract status
Section titled “Contract status”This page is generated from the public Clap command tree for Registry Stack source version 0.34.0 and catalog SHA-256 521175a69262e60df96745886392348e5bb8d82e63cdd24bdf4baa80d46e5ff4. Hidden implementation commands are omitted.
evidencectl keygen client-assertion [OPTIONS] --output-dir <OUTPUT_DIR>Options
Section titled “Options”| Option | Always required | Default | Values | Environment | Description |
|---|---|---|---|---|---|
--output-dir <OUTPUT_DIR> | Yes | n/a | n/a | n/a | Secret directory receiving the private JWK file (created 0700) |
--public-output <PUBLIC_OUTPUT> | No | n/a | n/a | n/a | Public JWK output path; defaults to a file inside the secret directory |
--private-name <PRIVATE_NAME> | No | n/a | n/a | n/a | Name of the private JWK file, which is the secret:file/NAME a source’s clientAssertionKeyRef points at; defaults to one naming the algorithm. The public half follows it as NAME-public.jwk.json |
--algorithm <ALGORITHM> | No | es384 | es384, rs384 | n/a | Signature algorithm the assertion is signed with |
--format <output_format> | No | human | human, json | n/a | Select human-readable or machine-readable output |
-h, --help | No | n/a | n/a | n/a | Print help (see a summary with ‘-h’) |
Generation contract
Section titled “Generation contract”Run npm run generate from docs/site after changing a public command, argument, option, default, environment binding, or help description.