---
title: CLI
description: npx trlay@latest init registers the organisation, sends the sign-in link, and offers the first identity.
canonical: https://tollrelay.com/docs/cli
lastmod: 2026-09-15
---

# CLI

npx trlay@latest init registers the organisation, sends the sign-in link, and offers the first identity.

```sh
npx trlay@latest init --region eu --handle acme
```

## Commands

```sh
trlay init --region <eu|us> --handle <handle> [--name <name>] [--email <email>] [--label <label>] [--no-identity]
```

Register the organisation, send the sign-in link, and offer the first identity.

```sh
trlay login [--region <eu|us>] [--email <email>]
```

Sign in over the device grant, print the code, and store the session.

```sh
trlay pass issue --label <label> --org <org>
```

Issue a pass under an organisation. Writes its signing key once and prints the path.

```sh
trlay pass revoke <mid>
```

Revoke a pass.

```sh
trlay pass token <mid>
```

Mint the interim identity token for a pass.

```sh
trlay pass list [--limit <n>] [--cursor <c>]
```

List the signed-in organisation's passes.

```sh
trlay identities create --label <label> --org <org>
```

Issue an identity under an organisation. Writes its signing key once and prints the path.

```sh
trlay mandates set <mid> --usd-per-day <usd> [--usd-per-call-max <usd>] [--sellers-allow <a,b>] [--sellers-deny <a,b>] [--rails <x402,mpp>]
```

Set a mandate's constraints.

```sh
trlay mandates propose <mid> --usd-per-day <usd> [--usd-per-call-max <usd>] [--budget <usd>] [--sellers-allow <a,b>] [--sellers-deny <a,b>] [--rails <x402,mpp>] [--not-before <iso>] [--not-after <iso>]
```

Propose a new version of an identity's open mandate, for an approver to sign.

```sh
trlay mandates versions <mid> [--limit <n>] [--cursor <c>]
```

List an identity's open mandate versions, newest first.

```sh
trlay mandates sign <mid> <version> [--yes]
```

Review a proposed version and sign it on the trusted surface. Needs trlay login first.

```sh
trlay mandates refuse <mid> <version> [--yes]
```

Review a proposed version and refuse it on the trusted surface. Needs trlay login first.

```sh
trlay record [--month <YYYY-MM>] [--limit <n>] [--cursor <c>] [--csv]
```

Read the record. --csv walks every page and writes it as CSV.

```sh
trlay trust evaluate (--did <did> | --credential <vc> | --envelope <json>) --seller <seller> --endpoint <endpoint> --amount-usd <usd> --rail <x402|mpp> [--settlement-ref <ref>]
```

Run a test call against the gate a seller's layer calls before serving.

```sh
trlay verifiers keys --label <label> [--id <id>] [--test] [--out <path>]
```

Mint a verifier key. Founder-keyed. Prints the key once; writes it to a file only with --out.

Every command takes `--json` for a machine-readable answer.

## Credentials

A credential comes from `--api-key`, `TRLAY_API_KEY`, `TRLAY_TOKEN`, `~/.trlay/credentials.json`, in that order.

This build talks to api.trlay.dev against the contract's documented shapes. It has not been verified against a live deployment.
