▣ mandare
Reference

CLI reference

Every mandare command — verification, certificates, issuance, the kill switch, the witness.

Exit codes everywhere: 0 success/valid · 1 invalid or error · 2 usage. Add --json for machine-readable output where noted.

mandare verify --db <path>

Hash chain, door signatures, RFC 6962 tree head.

FlagMeaning
--spendspend trail + budget-counter invariant (counters == fresh replay)
--door-key <hex>out-of-band door key → authorship, not just consistency
--key-directory <path|url>JWKS key directory (multi-door, rotation windows)
--prev-head <size>:<root>recorded head → rollback/rewrite detection
--witness <url> --witness-key <hex>check against the external witnessed head history (truncation/rewrites); pair with --door-key so the lookup is bound to your door — otherwise it is labeled a self-declared source. Outcomes: CONSISTENT, TRUNCATION DETECTED, FORK DETECTED, SOURCE MISMATCH, TIMELINE VIOLATION, UNAVAILABLE
--prove <seq>inclusion proof for one entry (selective disclosure)
--jsonfull machine-readable report

Without an out-of-band key source, verification is self-anchored: it proves internal consistency, not authorship — the CLI says so on every run.

mandare certify / mandare certify verify <file>

Build the integrity certificate (chain valid · witnessed · anchored) over owner-selected entries (--disclose 3,17,42); undisclosed entries stay salted hashes. certify verify re-derives every proof-backed check with no ledger access; recorder-attested claims are labeled, never silently passed.

mandare kill · mandare reinstate

mandare kill <agent-did> [--reason <text>]
mandare kill --mandate <id>     # the permission slip dies; the agent survives
mandare kill --all              # halt the whole door
mandare reinstate <agent-did>

Local, offline, fail-closed. Writes the revocation entry + flips the projection in one transaction, revokes the actor's vault tokens, revokes bound virtual cards (and best-effort cancels them at Stripe). The gateway refuses the subject on its next request.

Issuance

mandare passport issue --agent-name <label> [--valid-days n] [--json]
mandare mandate issue --agent <did:key> --out <file> \
  [--per-tx u] [--per-day u] [--per-task u] [--total u] \
  [--approval-above u] [--valid-hours h] [--currency EUR] [--json]
mandare token issue --actor <did> --mandate <id> [--ttl seconds] [--json]

Cap flags are WHOLE currency units. Token TTL ceiling is 30 minutes; the pop_secret prints exactly once.

mandare witness serve

The open reference witness: content-free head submissions (consistency-enforced), signed acks, aggregate anchoring (--anchor ots|mock), optional static hosting of the key directory and the IETF status list. Prints its public key at startup — distribute it out-of-band.

mandare vault · mandare directory

vault import-env bootstraps provider keys into the encrypted vault (then remove them from .env); vault list shows names only. directory builds the RFC 9421 key-directory JWKS from door key PEMs.