Skip to content

CLI Reference & Script Automation

The standalone CLI (crates/didis-cli) embeds resolver-core as a direct Rust dependency, requiring zero network daemons.

Terminal window
# Build and install directly from source
cargo install --path crates/didis-cli
# Verify installation
didis --version

didis <COMMAND>
Commands:
resolve Resolve a DID to JSON (--w3c for standard W3C output; --no-cache bypasses cache)
verify Print human-readable verdict, evidence dimensions, and keys
inspect Print verdict and full microsecond telemetry trace (--json for JSON output)
dereference Dereference a DID URL fragment, service, or version parameter
verify-credential Verify a Verifiable Credential file (Data Integrity JSON or compact JWT)
policy Evaluate a policy JSON file against a DID (and optional credential)
mcp inspect Audit a Streamable HTTP MCP server endpoint
a2a inspect Audit and verify an A2A agent card URL
agents verify-chain Verify a Delegation Receipt v1 chain file (--tool <name> to check auth)
history Display historical observations recorded in SQLite (requires --db)
diff Compute semantic diff between two observations (requires --db)
backup Create a consistent standalone SQLite snapshot in a new private file

The CLI returns deterministic POSIX exit codes:

  • 0: Success / Verified. The check completed successfully and the result is positive (VALID, RESOLVED, PASS).
  • 1: Check Negative / Indeterminate. The operation completed normally, but the evidence failed the verification threshold (e.g. invalid signature, expired cert, or policy FAIL).
  • 2: Operational Failure. Malformed input syntax, file not found, upstream network unreachable.
#!/usr/bin/env bash
set -e
DID="did:web:identity.foundation"
POLICY="production-policy.json"
echo "Evaluating policy against $DID..."
if didis policy "$DID" --policy "$POLICY"; then
echo "✅ Ingress policy PASSED."
exit 0
else
CODE=$?
if [ $CODE -eq 1 ]; then
echo "❌ Identity failed policy requirements."
else
echo "⚠️ Operational error executing didis (Exit code: $CODE)."
fi
exit $CODE
fi

When running with SQLite persistence (--db /data/observations.sqlite):

Terminal window
# Create an atomic, consistent standalone SQLite snapshot
didis --db /data/observations.sqlite backup /var/backups/didis-snapshot-$(date +%s).sqlite
  • Uses SQLite’s VACUUM INTO command.
  • Guarantees complete snapshot integrity, including uncommitted WAL transactions.
  • Destination file is created with exclusive 0600 permissions on Unix. Existing destination files are never overwritten.