CLI Reference & Script Automation
9. CLI Mastery (didis)
Section titled “9. CLI Mastery (didis)”The standalone CLI (crates/didis-cli) embeds resolver-core as a direct Rust dependency, requiring zero network daemons.
Installation & Setup
Section titled “Installation & Setup”# Build and install directly from sourcecargo install --path crates/didis-cli
# Verify installationdidis --versionCommand Reference
Section titled “Command Reference”didis <COMMAND>
Commands: resolve Resolve a DID to JSON (--w3c for standard W3C output; --no-cache bypasses cache) verify Print human-readable verdict, evidence dimensions, and keys inspect Print verdict and full microsecond telemetry trace (--json for JSON output) dereference Dereference a DID URL fragment, service, or version parameter verify-credential Verify a Verifiable Credential file (Data Integrity JSON or compact JWT) policy Evaluate a policy JSON file against a DID (and optional credential) mcp inspect Audit a Streamable HTTP MCP server endpoint a2a inspect Audit and verify an A2A agent card URL agents verify-chain Verify a Delegation Receipt v1 chain file (--tool <name> to check auth) history Display historical observations recorded in SQLite (requires --db) diff Compute semantic diff between two observations (requires --db) backup Create a consistent standalone SQLite snapshot in a new private fileAutomated Scripts & Exit Codes (0, 1, 2)
Section titled “Automated Scripts & Exit Codes (0, 1, 2)”The CLI returns deterministic POSIX exit codes:
0: Success / Verified. The check completed successfully and the result is positive (VALID,RESOLVED,PASS).1: Check Negative / Indeterminate. The operation completed normally, but the evidence failed the verification threshold (e.g. invalid signature, expired cert, or policyFAIL).2: Operational Failure. Malformed input syntax, file not found, upstream network unreachable.
CI/CD Pipeline Automation Script
Section titled “CI/CD Pipeline Automation Script”#!/usr/bin/env bashset -e
DID="did:web:identity.foundation"POLICY="production-policy.json"
echo "Evaluating policy against $DID..."if didis policy "$DID" --policy "$POLICY"; then echo "✅ Ingress policy PASSED." exit 0else CODE=$? if [ $CODE -eq 1 ]; then echo "❌ Identity failed policy requirements." else echo "⚠️ Operational error executing didis (Exit code: $CODE)." fi exit $CODEfiAtomic Database Backups (VACUUM INTO)
Section titled “Atomic Database Backups (VACUUM INTO)”When running with SQLite persistence (--db /data/observations.sqlite):
# Create an atomic, consistent standalone SQLite snapshotdidis --db /data/observations.sqlite backup /var/backups/didis-snapshot-$(date +%s).sqlite- Uses SQLite’s
VACUUM INTOcommand. - Guarantees complete snapshot integrity, including uncommitted WAL transactions.
- Destination file is created with exclusive
0600permissions on Unix. Existing destination files are never overwritten.