| 73 | /// Available agent subcommands. |
| 74 | #[derive(Debug, Subcommand)] |
| 75 | pub enum AgentCommands { |
| 76 | /// Create an agent identity and delegate to it. |
| 77 | /// |
| 78 | /// Generates a keypair, creates a delegated identity, signs a certificate |
| 79 | /// with your key, enrolls it with the server, and binds it in config so |
| 80 | /// hooks pick it up. One command, because every one of those steps is |
| 81 | /// useless without the others. |
| 82 | /// |
| 83 | /// # Examples |
| 84 | /// |
| 85 | /// ```text |
| 86 | /// # An agent that can record and push to two projects for 30 days |
| 87 | /// atomic identity agent create claude \ |
| 88 | /// --agent-type claude-code \ |
| 89 | /// --projects acme/api,acme/web \ |
| 90 | /// --can read,record,push |
| 91 | /// |
| 92 | /// # A read-only agent, no server enrollment |
| 93 | /// atomic identity agent create reviewer --can read --local |
| 94 | /// ``` |
| 95 | Create(Create), |
| 96 | |
| 97 | /// List agent identities and the state of their delegations. |
| 98 | /// |
| 99 | /// # Examples |
| 100 | /// |
| 101 | /// ```text |
| 102 | /// atomic identity agent list |
| 103 | /// atomic identity agent list --include-expired |
| 104 | /// atomic identity agent list --json |
| 105 | /// ``` |
| 106 | List(List), |
| 107 | |
| 108 | /// Show one agent in full: identity, certificate, scope, status. |
| 109 | Show(Show), |
| 110 | |
| 111 | /// Reissue an agent's current scope with a new expiry. |
| 112 | /// |
| 113 | /// A convenience over `atomic identity grant new`: it carries the existing |
| 114 | /// `--can` and `--projects` forward so you need only say how long. The key |
| 115 | /// does not change, so nothing is re-enrolled, and like every issuance it |
| 116 | /// reaches no server. |
| 117 | Renew(Renew), |
| 118 | |
| 119 | /// Withdraw an agent's authority. |
| 120 | /// |
| 121 | /// Bumps the agent's epoch — killing every grant issued to it so far, |
| 122 | /// including ones this machine has never seen — and deny-lists the grants |
| 123 | /// it does know, each with a signed revocation. |
| 124 | /// |
| 125 | /// Unlike issuing, this must reach the server: a credential the holder |
| 126 | /// possesses cannot prove its own withdrawal. The identity and its past |
| 127 | /// work stay, so attribution for changes already recorded does not |
| 128 | /// evaporate. |
| 129 | Revoke(Revoke), |
| 130 | } |
| 131 | |
| 132 | impl Command for Agent { |
nothing calls this directly
no outgoing calls
no test coverage detected