CLI

npx trlay@latest init registers the organisation, sends the sign-in link, and offers the first identity.

npx trlay@latest init --region eu --handle acme

Commands

trlay init --region <eu|us> --handle <handle> [--name <name>] [--email <email>] [--label <label>] [--no-identity]

Register the organisation, send the sign-in link, and offer the first identity.

trlay login [--region <eu|us>] [--email <email>]

Sign in over the device grant, print the code, and store the session.

trlay pass issue --label <label> --org <org>

Issue a pass under an organisation. Writes its signing key once and prints the path.

trlay pass revoke <mid>

Revoke a pass.

trlay pass token <mid>

Mint the interim identity token for a pass.

trlay pass list [--limit <n>] [--cursor <c>]

List the signed-in organisation's passes.

trlay identities create --label <label> --org <org>

Issue an identity under an organisation. Writes its signing key once and prints the path.

trlay mandates set <mid> --usd-per-day <usd> [--usd-per-call-max <usd>] [--sellers-allow <a,b>] [--sellers-deny <a,b>] [--rails <x402,mpp>]

Set a mandate's constraints.

trlay mandates propose <mid> --usd-per-day <usd> [--usd-per-call-max <usd>] [--budget <usd>] [--sellers-allow <a,b>] [--sellers-deny <a,b>] [--rails <x402,mpp>] [--not-before <iso>] [--not-after <iso>]

Propose a new version of an identity's open mandate, for an approver to sign.

trlay mandates versions <mid> [--limit <n>] [--cursor <c>]

List an identity's open mandate versions, newest first.

trlay mandates sign <mid> <version> [--yes]

Review a proposed version and sign it on the trusted surface. Needs trlay login first.

trlay mandates refuse <mid> <version> [--yes]

Review a proposed version and refuse it on the trusted surface. Needs trlay login first.

trlay record [--month <YYYY-MM>] [--limit <n>] [--cursor <c>] [--csv]

Read the record. --csv walks every page and writes it as CSV.

trlay trust evaluate (--did <did> | --credential <vc> | --envelope <json>) --seller <seller> --endpoint <endpoint> --amount-usd <usd> --rail <x402|mpp> [--settlement-ref <ref>]

Run a test call against the gate a seller's layer calls before serving.

trlay verifiers keys --label <label> [--id <id>] [--test] [--out <path>]

Mint a verifier key. Founder-keyed. Prints the key once; writes it to a file only with --out.

Every command takes --json for a machine-readable answer.

Credentials

A credential comes from one of, in this order:

  1. --api-key
  2. TRLAY_API_KEY
  3. TRLAY_TOKEN
  4. ~/.trlay/credentials.json

This build talks to api.trlay.dev against the contract's documented shapes. It has not been verified against a live deployment.