Released docs. You are viewing the documentation published with v0.34.0. Development docs are available at Latest.
evidencectl keygen secret command reference
One random raw secret file, 32 bytes (audit or subject-binding HMAC).
Contract status
Section titled “Contract status”This page is generated from the public Clap command tree for Registry Stack source version 0.34.0 and catalog SHA-256 521175a69262e60df96745886392348e5bb8d82e63cdd24bdf4baa80d46e5ff4. Hidden implementation commands are omitted.
Description
Section titled “Description”One random raw secret file, 32 bytes (audit or subject-binding HMAC). This is HMAC key material, not a credential a source will accept: the bytes are arbitrary and an HTTP header value rejects most of them. Use keygen token for a bearer token.
evidencectl keygen secret [OPTIONS] --output <OUTPUT>Options
Section titled “Options”| Option | Always required | Default | Values | Environment | Description |
|---|---|---|---|---|---|
--output <OUTPUT> | Yes | n/a | n/a | n/a | Output file for the raw secret (written 0600) |
--format <output_format> | No | human | human, json | n/a | Select human-readable or machine-readable output |
-h, --help | No | n/a | n/a | n/a | Print help (see a summary with ‘-h’) |
Generation contract
Section titled “Generation contract”Run npm run generate from docs/site after changing a public command, argument, option, default, environment binding, or help description.