Skip to content

kindgi key

Manage Ed25519 signing keys: the local pairs under ~/.kindgi/keys/, and the runtime's trust list.

Generate a new Ed25519 keypair under ~/.kindgi/keys/.

Terminal window
kindgi key create <keyId> [--env <name>] [--home <dir>]

Flags:

  • --env <value>: Also print the signingKey and signerKeyId lines to add to this env block in kindgi.config.ts.
  • --home <value>: The home directory whose .kindgi/keys/ holds the keys. Default: $HOME.

Print the PUBLIC key material for a local key. Never exports the private key.

Terminal window
kindgi key export <keyId> [--format=pem|base64|raw-hex] [--home <dir>]

Flags:

  • --format <value>: The public key's encoding: pem (default), base64 or raw-hex.
  • --home <value>: The home directory whose .kindgi/keys/ holds the keys. Default: $HOME.

List local Ed25519 keys under ~/.kindgi/keys/.

Terminal window
kindgi key list [--home <dir>]

Flags:

  • --home <value>: The home directory whose .kindgi/keys/ holds the keys. Default: $HOME.

Add a local key's public key to the runtime's trust list, so the runtime accepts deploys the key signs.

Terminal window
kindgi key trust <keyId> [--label <text>] [--home <dir>]

Flags:

  • --home <value>: The home directory whose .kindgi/keys/ holds the keys. Default: $HOME.
  • --label <value>: A label the runtime keeps with the key (up to 200 characters).

Remove a key from the runtime's trust list: the runtime refuses new deploys it signs.

Terminal window
kindgi key revoke <keyId> [--reason <text>]

Flags:

  • --reason <value>: Why, kept with the key as revokedReason.

Every command also takes the global flags.