On this page
Reference · 13
CLI & vocabulary
The user-facing CLI commands in practical groups, followed by the state labels and controlled vocabulary used throughout Keydris.
Install and update#
The npm package is the easiest cross-platform installation. It requires Node.js 20+ and selects a native binary for Windows, macOS, or Linux on x64 or ARM64.
npm
npm install --global @keydris/clikeydris version # confirm the installed buildNote
--omit=optional; the platform binary is delivered as an optional dependency.On macOS or Linux, the native installer is an alternative that does not require Node.js:
native stable-channel installer
curl -fsSL https://get.keydris.com/keydris-cli/install.sh | bashUpdate with the same package manager that installed Keydris:
updates
npm install --global @keydris/cli@latest # npm-managed installationkeydris upgrade # native installer; stays on its configured channelSetup and identity#
agent setup
keydris init # interactive: choose a harness and enter an Agent IDkeydris init claude-code <agent-id> # configure Claude Codekeydris init codex <agent-id> # configure OpenAI Codexkeydris init claude-desktop <agent-id> # configure Claude Desktop (macOS)keydris init codex-desktop <agent-id> # configure the Codex desktop app (macOS)Use the Agent ID created in the Keydris console. The policy is assigned there; the CLI does not select or override it. On a fresh machine, init opens browser sign-in and binds the local device identity to that agent. A valid identity already bound to the same agent is reused.
Claude Code setup is strict by default: Keydris enables the sandbox, fails if it is unavailable, and disables the unsandboxed escape. Add --trust-store to either explicit init command only when native tools need the Keydris CA in the operating system trust store. That change may require elevated privileges.
identity
keydris login # sign in again or renew the local identitykeydris login --no-browser # print the sign-in URL for a remote shellkeydris whoami # show the stored user, device, agent, and expirykeydris logout # remove the local identityNote
init, not a separate login. If init reports that sign-in is incomplete, run login before keydris proxy up.Proxy and sessions#
day-to-day commands
keydris proxy up # start the proxy in the backgroundkeydris status # check identity, scope, harness config, and control planekeydris proxy scope list # show policy-derived governed originsclaude # Claude Code: configured hooks own the sessionkeydris codex [args...] # Codex: wrapper owns the sessionkeydris claude-desktop # Claude Desktop: one governed sessionkeydris codex-desktop # Codex desktop app: one governed sessionkeydris run -- <command> [args...] # wrap another command in a Keydris sessionkeydris proxy down # stop the background proxyproxy up backgrounds itself and prints its log path; no trailing & is needed. Proxy scope is detected from the agent's assigned policy and refreshed at session start, so there is no manual scope list to maintain.
keydris run -- is the harness-independent path. It opens a session, runs the command through the configured Keydris data plane, and revokes the session when the command exits.
Inspect and remove#
inspection and cleanup
keydris logs # print the local evidence ledger and verify its chainkeydris status # diagnose the current setupkeydris help # show built-in command helpkeydris version # print the build versionkeydris deinit claude-code # remove Keydris entries from Claude Codekeydris deinit codex # remove Keydris entries from Codexkeydris deinit claude-desktop # remove the Claude Desktop integrationkeydris deinit codex-desktop # remove the Codex desktop integrationkeydris doctor # detailed read-only status and recovery guidancekeydris skill [--brief] # read the bundled agent skill or session briefingkeydris telemetry [status|on|off] # show or change anonymous install telemetrykeydris reset --dry-run # preview removal of local setup and certificateskeydris reset # reset the local setup and certificates, leaving the harness aloneDeinit preserves unrelated harness settings, but clears the stored Agent ID and detected policy scope. It leaves the generated CA files in place for a later setup. If you used --trust-store, remove that operating-system trust entry separately when it is no longer needed.
Files the CLI changes#
- ~/.keydris.toml
- Release-channel and control-plane defaults installed by npm or the native installer.
- ~/.keydris-data/
- Local identity, Agent ID, CA, session state, proxy log, and the hash-chained evidence ledger.
- ~/.claude/settings.json
- Claude Code sandbox, CA environment, and lifecycle and command hooks written by
keydris init claude-code.
Take care
~/.keydris-data as sensitive. It contains the local private identity material, and evidence or proxy logs can include action parameters and request bodies. Do not commit or share it.State labels#
A governed action resolves to exactly one of three decisions: ALLOW, REJECT, or APPROVAL REQUIRED. The labels below are supporting states and reasons that can appear alongside a decision:
Vocabulary#
- Agent
- an operator-managed identity for an AI workload.
- Device
- an enrolled installation on which an agent runs.
- KIT
- the short-lived runtime identity for one agent session.
- Local proxy
- the CLI's TLS-terminating egress proxy; it matches each governed request to a route before anything reaches the network.
- Broker
- the legacy authorization path in your environment, on the agent's side.
- Reader
- optional enforcement on your MCP servers, on the receiving side.
- Policy
- operator-authored rules governing an agent's actions.
- Integration
- an organization connection to an external system.
- Resource
- a selected repository, channel, MCP tool or resource, or other governable target.
- Decision
- what Keydris concluded about one governed action: ALLOW, REJECT, or APPROVAL REQUIRED. Exactly these three.
- Reason
- why a decision came out that way (for example scope mismatch, or authority verified). A reason travels under a decision; it is never the decision.
- Outcome
- what happened when an allowed operation was attempted, recorded separately from the decision.
- Control plane
- the Keydris service that makes the authority decision against current policy and revocation state.
- Authority context
- the decision inputs the Reader sends: the KIT, the action, the tool, the scope, and the resource.
- Governed
- resources you enroll + the policy you assign, for supported actions.
- Stateless MCP
- independent governed MCP exchanges without retained session continuity.
- Stateful MCP
- governed MCP exchanges that retain continuity across a related multi-step session.