Registry stack documentation: machine-readable Markdown.
Index of all pages: https://docs.registrystack.org/v/0.38.0/llms.txt
Full corpus: https://docs.registrystack.org/v/0.38.0/llms-full.txt

# evidencectl keygen client-assertion command reference

> Generated syntax and options for evidencectl keygen client-assertion.

{/* Generated from Clap command definitions by scripts/generate-cli-reference.mjs. Run npm run generate. */}

Keypair a source's `clientAssertionKeyRef` points at, for a token endpoint that authenticates the client by signed assertion.

## Contract status

This page is generated from the public Clap command tree for Registry Stack source version `0.38.0` and catalog SHA-256 `cd13c658f65af295f9df3c6db86dc045ac06e9e040afc1f5f5b27c3184ab653d`. Hidden implementation commands are omitted.

## Usage

```text
evidencectl keygen client-assertion [OPTIONS] --output-dir <OUTPUT_DIR>
```

## Options

| Option | Always required | Default | Values | Environment | Description |
| --- | --- | --- | --- | --- | --- |
| `--output-dir <OUTPUT_DIR>` | Yes | n/a | n/a | n/a | Secret directory receiving the private JWK file (created 0700) |
| `--public-output <PUBLIC_OUTPUT>` | No | n/a | n/a | n/a | Public JWK output path; defaults to a file inside the secret directory |
| `--private-name <PRIVATE_NAME>` | No | n/a | n/a | n/a | Name of the private JWK file, which is the `secret:file/NAME` a source's `clientAssertionKeyRef` points at; defaults to one naming the algorithm. The public half follows it as `NAME-public.jwk.json` |
| `--algorithm <ALGORITHM>` | No | `es384` | `es384`, `rs384` | n/a | Signature algorithm the assertion is signed with |
| `--format <output_format>` | No | `human` | `human`, `json`, `junit` | n/a | Select human-readable or machine-readable output. `junit` is accepted only by fixture runs (`test` and `fixtures run`) |
| `-h, --help` | No | n/a | n/a | n/a | Print help (see a summary with '-h') |

## Generation contract

Run `npm run generate` from `docs/site` after changing a public command, argument, option, default, environment binding, or help description.