Versioned archive. You are viewing v0.38.0. For the latest released guidance, use Latest release. Report archive issues on GitHub.
evidencectl keygen command reference
Generate Evidence Gateway deployment key material as owner-only files.
Contract status
Section titled “Contract status”This page is generated from the public Clap command tree for Registry Stack source version 0.38.0 and catalog SHA-256 cd13c658f65af295f9df3c6db86dc045ac06e9e040afc1f5f5b27c3184ab653d. Hidden implementation commands are omitted.
evidencectl keygen [OPTIONS] <COMMAND>Commands
Section titled “Commands”| Command | Description |
|---|---|
signing | P-256 ES256 signing keypair as private and public JWK files |
secret | One random raw secret file, 32 bytes (audit or subject-binding HMAC) |
token | One random bearer token file, printable and header-safe |
holder | P-256 ES256 holder keypair for SD-JWT VC confirmation binding |
client-assertion | Keypair a source’s clientAssertionKeyRef points at, for a token endpoint that authenticates the client by signed assertion |
Options
Section titled “Options”| Option | Always required | Default | Values | Environment | Description |
|---|---|---|---|---|---|
--format <output_format> | No | human | human, json, junit | n/a | Select human-readable or machine-readable output. junit is accepted only by fixture runs (test and fixtures run) |
-h, --help | No | n/a | n/a | n/a | Print help |
Generation contract
Section titled “Generation contract”Run npm run generate from docs/site after changing a public command, argument, option, default, environment binding, or help description.