Registry stack documentation: machine-readable Markdown.
Index of all pages: https://docs.registrystack.org/v/0.38.0/llms.txt
Full corpus: https://docs.registrystack.org/v/0.38.0/llms-full.txt

# evidencectl access client add command reference

> Generated syntax and options for evidencectl access client add.

{/* Generated from Clap command definitions by scripts/generate-cli-reference.mjs. Run npm run generate. */}

Add one local client and generate its private key.

## Contract status

This page is generated from the public Clap command tree for Registry Stack source version `0.38.0` and catalog SHA-256 `cd13c658f65af295f9df3c6db86dc045ac06e9e040afc1f5f5b27c3184ab653d`. Hidden implementation commands are omitted.

## Usage

```text
evidencectl access client add [OPTIONS] --policy <POLICY> --generate-local-key <CLIENT>
```

## Constraints

| Condition | Requirement |
| --- | --- |
| `--grant-bootstrap-resource <GRANT_BOOTSTRAP_RESOURCE>` is present | `--grant-bootstrap-scope <GRANT_BOOTSTRAP_SCOPE>` is required. |
| `--first-party-bootstrap-scope <FIRST_PARTY_BOOTSTRAP_SCOPE>` is present | All of `--first-party-bootstrap-resource <FIRST_PARTY_BOOTSTRAP_RESOURCE>`, `--first-party-issuer <FIRST_PARTY_ISSUER>` are required. |
| `--first-party-bootstrap-resource <FIRST_PARTY_BOOTSTRAP_RESOURCE>` is present | All of `--first-party-issuer <FIRST_PARTY_ISSUER>`, `--first-party-bootstrap-scope <FIRST_PARTY_BOOTSTRAP_SCOPE>` are required. |
| `--first-party-issuer <FIRST_PARTY_ISSUER>` is present | All of `--first-party-bootstrap-resource <FIRST_PARTY_BOOTSTRAP_RESOURCE>`, `--first-party-bootstrap-scope <FIRST_PARTY_BOOTSTRAP_SCOPE>` are required. |
| Command invocation | `--first-party-bootstrap-scope <FIRST_PARTY_BOOTSTRAP_SCOPE>` and `--grant-bootstrap-scope <GRANT_BOOTSTRAP_SCOPE>` cannot be used together. |

## Arguments

| Argument | Always required | Default | Values | Environment | Description |
| --- | --- | --- | --- | --- | --- |
| `<CLIENT>` | Yes | n/a | n/a | n/a | Lowercase client identifier |

## Options

| Option | Always required | Repeatable | Default | Values | Environment | Description |
| --- | --- | --- | --- | --- | --- | --- |
| `--policy <POLICY>` | Yes | Yes | n/a | n/a | n/a | Access policy assigned to this client. Repeat for more than one |
| `--generate-local-key` | Yes | No | n/a | n/a | n/a | Generate an owner-only P-256 key for local client authentication |
| `--grant-bootstrap-scope <GRANT_BOOTSTRAP_SCOPE>` | No | No | n/a | n/a | n/a | Use institutional task exchange with this one bootstrap scope |
| `--grant-bootstrap-resource <GRANT_BOOTSTRAP_RESOURCE>` | No | No | n/a | n/a | n/a | Bootstrap resource audience. Omit to use the shared issuer owner's default |
| `--first-party-bootstrap-scope <FIRST_PARTY_BOOTSTRAP_SCOPE>` | No | No | n/a | n/a | n/a | Use a signed first-party context with this one bootstrap scope |
| `--first-party-bootstrap-resource <FIRST_PARTY_BOOTSTRAP_RESOURCE>` | No | No | n/a | n/a | n/a | Exact resource for the first-party bootstrap credential |
| `--first-party-issuer <FIRST_PARTY_ISSUER>` | No | No | n/a | n/a | n/a | Exact trusted issuer of the signed first-party context |
| `--format <output_format>` | No | No | `human` | `human`, `json`, `junit` | n/a | Select human-readable or machine-readable output. `junit` is accepted only by fixture runs (`test` and `fixtures run`) |
| `-h, --help` | No | No | n/a | n/a | n/a | Print help |

## Generation contract

Run `npm run generate` from `docs/site` after changing a public command, argument, option, default, environment binding, or help description.