Skip to content
Registry StackDocsv0.38.0

evidencectl keygen client-assertion command reference

View as Markdown

Keypair a source’s clientAssertionKeyRef points at, for a token endpoint that authenticates the client by signed assertion.

This page is generated from the public Clap command tree for Registry Stack source version 0.38.0 and catalog SHA-256 cd13c658f65af295f9df3c6db86dc045ac06e9e040afc1f5f5b27c3184ab653d. Hidden implementation commands are omitted.

evidencectl keygen client-assertion [OPTIONS] --output-dir <OUTPUT_DIR>
OptionAlways requiredDefaultValuesEnvironmentDescription
--output-dir <OUTPUT_DIR>Yesn/an/an/aSecret directory receiving the private JWK file (created 0700)
--public-output <PUBLIC_OUTPUT>Non/an/an/aPublic JWK output path; defaults to a file inside the secret directory
--private-name <PRIVATE_NAME>Non/an/an/aName of the private JWK file, which is the secret:file/NAME a source’s clientAssertionKeyRef points at; defaults to one naming the algorithm. The public half follows it as NAME-public.jwk.json
--algorithm <ALGORITHM>Noes384es384, rs384n/aSignature algorithm the assertion is signed with
--format <output_format>Nohumanhuman, json, junitn/aSelect human-readable or machine-readable output. junit is accepted only by fixture runs (test and fixtures run)
-h, --helpNon/an/an/aPrint help (see a summary with ‘-h’)

Run npm run generate from docs/site after changing a public command, argument, option, default, environment binding, or help description.