AUTHRA

Everything the console can do, from the terminal.

authra issues delegations, redeems them, revokes them, and reads the same audit trail the console renders. It goes through the exact same non-custodial API, never a shortcut around it. This page is the complete reference: every command, every flag. Nothing about using it lives anywhere else.

GETTING IT

Install it

authra-cli is a real, public npm package. Every key it ever touches (your owner key, session keys) is generated and stored locally in ~/.authra/config.json and never leaves your machine. Write commands relay through Authra's own backend, so there's no bundler credential of your own to configure.

# install once
npm i -g authra-cli
# then use it
authra config set --base-url https://your-authra-deployment
authra signup
authra issue --cap 5

Set AUTHRA_API_URL and AUTHRA_OWNER_KEY as environment variables instead of config set if you'd rather not persist them to disk. Env vars always override the config file.

SETUP

Local config

Everything below persists to ~/.authra/config.json. Secrets are masked whenever the file is printed, never shown in full after the moment they're generated.

authra config

Show the local config file, with every secret masked (never printed in full).

authra config set --base-url <url>

Point the CLI at an Authra deployment. Persists to ~/.authra/config.json.

ISSUE (the hiring side)

Grant scoped, revocable authority

authra signup

Prove ownership of a wallet with one signature, that alone creates a workspace and mints a scoped issuer key. No console visit, no admin approval.

authra issue --cap <usdc> [--name <str>] [--token 0x…] [--policy-file <path>]

Issue a root delegation: a capped, expiring authority you grant to yourself, off your own owner key. Prints the address to fund with test USDC.

--cap <usdc>
: Daily spend cap in human USDC, e.g. 5 for 5 USDC/day. Ignored if --policy-file is set.
--name <str>
: Label shown in the console and in `authra list`. Default: "authra-cli root".
--token 0x…
: ERC-20 to cap. Default: this deployment's verified Base Sepolia test USDC.
--policy-file <path>
: Escape hatch: a full custom policy JSON (any shape the policy engine understands, e.g. a DEX router target with erc20BalanceCap instead of a plain transfer cap) instead of the built-in transfer-cap shape.
authra deploy [--token 0x…]

Warm up both smart accounts in the root chain (a real UserOp deploys them). Needed once before a redemption can validate the full signature chain back to the root.

authra hire --cap <usdc> [--name <str>] [--token 0x…] [--policy-file <path>] [--parent <id>]

Redelegate a narrower, capped slice of the last-issued root to a freshly generated hired-agent identity. The child is checked to be a provable subset of the parent before it's ever issued.

--cap <usdc>
: Must attenuate the parent's own cap; issuance fails if it doesn't.
--parent <id>
: Delegation id to hire under. Default: the last root `issue` stored locally.
--policy-file <path>
: Same escape hatch as `issue`: full custom policy for the child.
authra revoke [--id <delegationId>]

The kill switch. Cascades: revoking a root immediately cuts off everything hired under it, even though the child delegation itself is never touched directly.

authra balance [--address 0x…] [--token 0x…]

Read an ERC-20 balance. Defaults to the root delegator, the account funds actually move from, so you can confirm funding before running deploy/transfer/demo.

authra pull [--key 0x…] [--select <delegationId>]

Discover delegations already granted to a key you hold (e.g. one issued through the console rather than the CLI) by proving ownership via a signature and storing the match as "hired".

--key 0x…
: The private key to prove ownership with. Default: the CLI's stored owner key.
--select <id>
: Pick a specific delegation when more than one comes back. Default: the first.
REDEEM (the hired-agent side)

Act inside exactly what was granted

authra transfer --amount <usdc> [--to 0x…] [--as root|hired] [--token 0x…]

Spend under a delegation, a real ERC-20 transfer. Prints ALLOWED with a tx hash, or DENIED with the exact failed caveat.

--as root|hired
: Which stored delegation to redeem under. Default: hired.
--to 0x…
: Recipient. Default: your own owner address.
authra execute --to 0x… [--data 0x…] [--value <wei>] [--as root|hired]

The general escape hatch: redeem any policy-allowed encoded call, not just a plain transfer. transfer and swap are both just this with the calldata pre-built for you.

authra swap --amount <usdc> [--token-in 0x…] [--token-out 0x…] [--recipient 0x…] [--as root|hired]

A real Uniswap V3 exactInputSingle swap, the same pool this project's own trading demo verified live (Base Sepolia test USDC to WETH, 0.05% fee tier). Requires a delegation whose policy already allows the router: issue/hire one with --policy-file, or use `demo --scenario swap` which builds it for you.

AUDIT TRAIL

Read what happened, not just cause it

authra events [--limit <n>]

Recent activity for the workspace, the same feed the console's Activity page shows, read from the terminal.

authra forensics <eventId>

The full record for one event, exactly as the console's forensic drawer renders it. Every field is trust-tagged chain-verified, authra-attested, or agent-reported, never presented as fact beyond what's actually verifiable.

WORKSPACE

See everything, and run the ACP watcher

authra list

Every identity and delegation in the workspace, not just the last one the CLI happens to remember locally.

authra acp watch [--ceiling <usdc>]

Enable this workspace's automatic ACP issuance watcher. Reads the ACP contract's own events directly (no dependency on Virtuals' registration-gated notification feed), auto-issues a delegation the moment a job's budget is set, and auto-revokes on completion, rejection, or expiry.

--ceiling <usdc>
: Tripwire: the watcher refuses to issue if its dedicated address's real balance exceeds this. Default: 10.
authra acp status

Show every configured watcher for this workspace and its last sweep.

DEMO

The full loop, narrated

authra demo [--dry-run] [--amount <usdc>]

The full loop, narrated: signup → issue → deploy → hire → spend → revoke → the SAME spend retried and denied, proving revocation cascades without the child ever being touched directly.

authra demo --scenario swap [--amount <usdc>]

The trading version of the same loop. Builds a router-scoped policy for you (an erc20BalanceCap on the Uniswap router, not a plain transfer cap) so it works standalone, then B trades on Uniswap instead of transferring.

Honest about scope, not glossed over: the CLI is EVM (Base Sepolia) only today. swap is scoped to the one pool this project has actually verified live, Base Sepolia test USDC to WETH, not arbitrary tokens. Identities that were never assigned a smart-account address at all (a separate, smaller data gap, not an authra pull issue) still won't resolve. Every automatic action still stays inside the caveats a human actually authorized; the CLI is a faster way to operate Authra, never a way around it.