init | Lifecycle | Generates node keys, creates config.json, mines PoW, and publishes the initial descriptor. Supports --manifest and --peering. |
run | Lifecycle | Starts the node daemon, binds the relay face, opens control.sock, and ticks on cadence. |
retire [--revoke] | Lifecycle | Leaves the mesh in order: hands over asserted shards, withdraws claims, stops, and optionally publishes kind 11802 key revocation. |
status [--json] | Inspection | Identity, face port, stored events, active grants, pending changes, and last evaluated windows. |
health [--json] | Diagnostics | Relay connection status, drop counts, refused sessions, handler exceptions, and active throttles. |
capacity [--json] | Diagnostics | Configured aggregate ceilings, current pressure, engaged load-shedding rungs, and historical peak. |
subsystems [--json] | Diagnostics | Per-compartment status across all 20 core compartments and whichever of the 6 optional ones (p2p, gossip, compute, bridge, dvm, updates) the config enables, including compartment refusals. |
refusals [--last N] | Diagnostics | Structured log of every refused request and transaction, with specific failure reasons. |
events [--since N] [--topics ...] [--last N] | Diagnostics | The most recent event-bus envelopes the daemon still holds in memory (windows evaluated and repriced, sessions completed, grants issued, peers connected, reports read), with sequence numbers to resume from. |
subscribe [--since N] [--topics ...] | Diagnostics | Hold the control socket open and print one line per bus event as it happens; --since replays what the ring still holds first, and a slow reader is told how many envelopes it missed. The surface an out-of-process plugin follows. |
strain [--json] | Diagnostics | Survived environmental anomalies by direction, reserve multiples, and dominant share flag-tree warnings. |
whoami [--json] | Inspection | DID, pubkey, npub, encryption keys, declared endpoints, and descriptor PoW status. |
check [--json] | Verification | Validates directory permissions (0600), config schema, descriptor digest, and SQLite database integrity. |
peers [--json] | Peering | All peered nodes, active tiers in both directions, clean window streaks, and shard pulls. |
grant <peer> [--json] | Accounting | Inspects bilateral grants with a specific peer: limits, cadence, scope, and envelope history. |
windows <peer> [--last N] | Accounting | Evaluated windows for a peer: measured vs. claimed counters, receipts sent/received, and severity rating. |
scheduled [--json] | Inspection | Displays every scheduled pull, when it last ran, active throttles, capacity holds, and declines. |
descriptor [--republish] | Inspection | Displays the local node kind 11801 descriptor event; --republish resends it. |
peer <peer> --shard NAME --filter JSON | Config | Adds a shard pull from a peer to config.json, on the operator's cadence. The daemon reconciles state on the next tick. |
unpeer <peer> [--shard NAME] | Config | Removes the pull from config.json. The grants stay live; terminate ends the peering. |
trust [peer] [--tier] | Config / Inspection | Inspects active trust decisions across peers, or seeds an operator trust tier in config.json. |
coverage list|add|remove | Config | Manages shard coverage claims published across the mesh as kind 30803 events. |
pull <peer> <shard> | Action | Triggers an immediate Negentropy synchronization cycle with a designated peer. |
terminate <peer> | Action | Cleanly terminates an active peering: zeroes both grants and notifies the peer. |
withdraw <peer> <window> | Action | Withdraws an adverse finding or report about a specific window epoch on the complaint thread. |
standing <peer> <target> | Action | Queries the peer local standing ledger about a third node over standing/1.0. |
reports <target> | Action | Fetches kind 30802 dispute reports about a node from relays, weighted by the local node ledger. |
tick [--json] | Action | Forces an immediate scheduler evaluation and housekeeping tick. |
api [--json] | Inspection | Introspects the control socket protocol, available commands, and dispatch schema. |
watch [--every N] [--quiet] | Telemetry | Runs automated health and invariant checks, returning structured exit codes for monitoring agents. |
bridge [action] [--relay URL] [--event JSON] [--filter JSON] | Bridge | Interacts with the Universal Nostr Relay Bridge: status, publish, add-relay, remove-relay, sync, and range-bounded reconcile backfill. |
gossip [action] [--name N] [--member PK]... [--ttl S] [--topic ID] [--event JSON|@file] | Gossip | gossip/1.0 group topics: status, topics, create (signs and publishes a kind 30804 roster for <node pk>:<name>; --no-relay keeps it local), admit another admin's roster that names this node (a roster published to the relays by a peer this node holds a grant with is admitted on its own; admit is for one handed over by other means), leave, and publish a sealed NIP-59 wrap into a topic mesh. GET /gossip on the relay face is the read-only view of the same rosters. |
compute [action] [--engine] [--rate] [--ask] | Compute | Inspects or interacts with the compute market and order book: status, show, book, offer, match, and receipts. |
dvm [action] [--request JSON] | Compute | Interacts with the NIP-90 Data Vending Machine Gateway: status, show telemetry, process, and delegate compute requests. |
cluster [action] [--nodes N] [--topology T] | Cluster | Manages a local multi-node testnet cluster: start, status, stop, and sync across mesh, star, ring, or line topologies. |
settle [action] [--ask ID] [--amount N] [--rail R] | Settlement | Inspects settlement rails and escrows: status, create, hold, settle, nwc-pay, cashu-swap, and cashu-melt. |
strfry [action] [--url URL] [--event JSON] | Bridge | The strfry relay bridge: status, the write-policy plugin (with --enforce-grants and --shadow), eval of one event against it, and export / import of JSONL over the pipe. |
enclave [action] [--type p256|secp256k1] [--message M] [--sig S] [--pub P] | Transport | Hardware enclaves and passkeys: status, generate a key, sign a message, verify a signature against a multikey. Exits 1 on a verification that fails. |
iroh [action] [--host H] [--port P] [--ticket T] [--to PK] [--message M] | Transport | iroh QUIC transport diagnostics: status, probe and punch a remote endpoint, send a payload to a ticket or pubkey. |
fips [action] [--sock PATH] [--port P] [--peer PK] [--message M] | Transport | FIPS Native Datagram API control: status, probe the control socket, listen on an FSP port, connect a flow to a peer, send a framed datagram, and list flows. |