authra configShow the local config file, with every secret masked (never printed in full).
authra issues delegations, redeems them, revokes them, and reads the same audit trail the console renders. It goes through the exact same non-custodial API, never a shortcut around it. This page is the complete reference: every command, every flag. Nothing about using it lives anywhere else.
authra-cli is a real, public npm package. Every key it ever touches (your owner key, session keys) is generated and stored locally in ~/.authra/config.json and never leaves your machine. Write commands relay through Authra's own backend, so there's no bundler credential of your own to configure.
Set AUTHRA_API_URL and AUTHRA_OWNER_KEY as environment variables instead of config set if you'd rather not persist them to disk. Env vars always override the config file.
Everything below persists to ~/.authra/config.json. Secrets are masked whenever the file is printed, never shown in full after the moment they're generated.
authra configShow the local config file, with every secret masked (never printed in full).
authra config set --base-url <url>Point the CLI at an Authra deployment. Persists to ~/.authra/config.json.
authra signupProve ownership of a wallet with one signature, that alone creates a workspace and mints a scoped issuer key. No console visit, no admin approval.
authra issue --cap <usdc> [--name <str>] [--token 0x…] [--policy-file <path>]Issue a root delegation: a capped, expiring authority you grant to yourself, off your own owner key. Prints the address to fund with test USDC.
authra deploy [--token 0x…]Warm up both smart accounts in the root chain (a real UserOp deploys them). Needed once before a redemption can validate the full signature chain back to the root.
authra hire --cap <usdc> [--name <str>] [--token 0x…] [--policy-file <path>] [--parent <id>]Redelegate a narrower, capped slice of the last-issued root to a freshly generated hired-agent identity. The child is checked to be a provable subset of the parent before it's ever issued.
authra revoke [--id <delegationId>]The kill switch. Cascades: revoking a root immediately cuts off everything hired under it, even though the child delegation itself is never touched directly.
authra balance [--address 0x…] [--token 0x…]Read an ERC-20 balance. Defaults to the root delegator, the account funds actually move from, so you can confirm funding before running deploy/transfer/demo.
authra pull [--key 0x…] [--select <delegationId>]Discover delegations already granted to a key you hold (e.g. one issued through the console rather than the CLI) by proving ownership via a signature and storing the match as "hired".
authra transfer --amount <usdc> [--to 0x…] [--as root|hired] [--token 0x…]Spend under a delegation, a real ERC-20 transfer. Prints ALLOWED with a tx hash, or DENIED with the exact failed caveat.
authra execute --to 0x… [--data 0x…] [--value <wei>] [--as root|hired]The general escape hatch: redeem any policy-allowed encoded call, not just a plain transfer. transfer and swap are both just this with the calldata pre-built for you.
authra swap --amount <usdc> [--token-in 0x…] [--token-out 0x…] [--recipient 0x…] [--as root|hired]A real Uniswap V3 exactInputSingle swap, the same pool this project's own trading demo verified live (Base Sepolia test USDC to WETH, 0.05% fee tier). Requires a delegation whose policy already allows the router: issue/hire one with --policy-file, or use `demo --scenario swap` which builds it for you.
authra events [--limit <n>]Recent activity for the workspace, the same feed the console's Activity page shows, read from the terminal.
authra forensics <eventId>The full record for one event, exactly as the console's forensic drawer renders it. Every field is trust-tagged chain-verified, authra-attested, or agent-reported, never presented as fact beyond what's actually verifiable.
authra listEvery identity and delegation in the workspace, not just the last one the CLI happens to remember locally.
authra acp watch [--ceiling <usdc>]Enable this workspace's automatic ACP issuance watcher. Reads the ACP contract's own events directly (no dependency on Virtuals' registration-gated notification feed), auto-issues a delegation the moment a job's budget is set, and auto-revokes on completion, rejection, or expiry.
authra acp statusShow every configured watcher for this workspace and its last sweep.
authra demo [--dry-run] [--amount <usdc>]The full loop, narrated: signup → issue → deploy → hire → spend → revoke → the SAME spend retried and denied, proving revocation cascades without the child ever being touched directly.
authra demo --scenario swap [--amount <usdc>]The trading version of the same loop. Builds a router-scoped policy for you (an erc20BalanceCap on the Uniswap router, not a plain transfer cap) so it works standalone, then B trades on Uniswap instead of transferring.
swap is scoped to the one pool this project has actually verified live, Base Sepolia test USDC to WETH, not arbitrary tokens. Identities that were never assigned a smart-account address at all (a separate, smaller data gap, not an authra pull issue) still won't resolve. Every automatic action still stays inside the caveats a human actually authorized; the CLI is a faster way to operate Authra, never a way around it.