CLI
npx trlay@latest init registers the organisation, sends the sign-in link, and offers the first identity.
npx trlay@latest init --region eu --handle acmeCommands
trlay init --region <eu|us> --handle <handle> [--name <name>] [--email <email>] [--label <label>] [--no-identity]Register the organisation, send the sign-in link, and offer the first identity.
trlay login [--region <eu|us>] [--email <email>]Sign in over the device grant, print the code, and store the session.
trlay pass issue --label <label> --org <org>Issue a pass under an organisation. Writes its signing key once and prints the path.
trlay pass revoke <mid>Revoke a pass.
trlay pass token <mid>Mint the interim identity token for a pass.
trlay pass list [--limit <n>] [--cursor <c>]List the signed-in organisation's passes.
trlay identities create --label <label> --org <org>Issue an identity under an organisation. Writes its signing key once and prints the path.
trlay mandates set <mid> --usd-per-day <usd> [--usd-per-call-max <usd>] [--sellers-allow <a,b>] [--sellers-deny <a,b>] [--rails <x402,mpp>]Set a mandate's constraints.
trlay mandates propose <mid> --usd-per-day <usd> [--usd-per-call-max <usd>] [--budget <usd>] [--sellers-allow <a,b>] [--sellers-deny <a,b>] [--rails <x402,mpp>] [--not-before <iso>] [--not-after <iso>]Propose a new version of an identity's open mandate, for an approver to sign.
trlay mandates versions <mid> [--limit <n>] [--cursor <c>]List an identity's open mandate versions, newest first.
trlay mandates sign <mid> <version> [--yes]Review a proposed version and sign it on the trusted surface. Needs trlay login first.
trlay mandates refuse <mid> <version> [--yes]Review a proposed version and refuse it on the trusted surface. Needs trlay login first.
trlay record [--month <YYYY-MM>] [--limit <n>] [--cursor <c>] [--csv]Read the record. --csv walks every page and writes it as CSV.
trlay trust evaluate (--did <did> | --credential <vc> | --envelope <json>) --seller <seller> --endpoint <endpoint> --amount-usd <usd> --rail <x402|mpp> [--settlement-ref <ref>]Run a test call against the gate a seller's layer calls before serving.
trlay verifiers keys --label <label> [--id <id>] [--test] [--out <path>]Mint a verifier key. Founder-keyed. Prints the key once; writes it to a file only with --out.
Every command takes --json for a machine-readable answer.
Credentials
A credential comes from one of, in this order:
--api-keyTRLAY_API_KEYTRLAY_TOKEN~/.trlay/credentials.json
This build talks to api.trlay.dev against the contract's documented shapes. It has not been verified against a live deployment.