{"_id":"@biological-sovereignty-protocol/cli","name":"@biological-sovereignty-protocol/cli","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@biological-sovereignty-protocol/cli","version":"1.0.0","description":"Official CLI for the Biological Sovereignty Protocol — manage BEOs, IEOs, consent, and health data from the terminal","bin":{"bsp":"dist/index.js"},"main":"dist/index.js","scripts":{"build":"tsc","dev":"ts-node src/index.ts","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"keywords":["bsp","biological-sovereignty","cli","health-data","arweave","longevity","lgpd","gdpr"],"author":{"name":"Ambrósio Institute"},"license":"Apache-2.0","repository":{"type":"git","url":"git+https://github.com/Biological-Sovereignty-Protocol/bsp-cli.git"},"homepage":"https://biologicalsovereigntyprotocol.com","bugs":{"url":"https://github.com/Biological-Sovereignty-Protocol/bsp-cli/issues"},"engines":{"node":">=18.0.0"},"dependencies":{"@biological-sovereignty-protocol/sdk":"^1.0.0","chalk":"^5.3.0","commander":"^12.0.0"},"devDependencies":{"@types/node":"^20.0.0","typescript":"^5.4.0"},"gitHead":"c781c4b5727ac190f725d4dee2b0fedc082c318e","types":"./dist/index.d.ts","_id":"@biological-sovereignty-protocol/cli@1.0.0","_nodeVersion":"24.13.0","_npmVersion":"11.6.2","dist":{"integrity":"sha512-WrDmtcG4y87iGESSyPvZJcOvqZ/iyLXrmfrjHf8I0P45Nb8SuohYNVHz+tkPn1I8nJkGN3MpyybqbEZTtZzUGA==","shasum":"0c8090e20d55254fbd7dc812570378383a949ebb","tarball":"https://registry.npmjs.org/@biological-sovereignty-protocol/cli/-/cli-1.0.0.tgz","fileCount":21,"unpackedSize":55801,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIBqAF4LOvu88cnelxtuonHQtztZ90jQrv2DxFcQ1t7BhAiAVOkzOTLcZDUolAjiTKB204ZiqpTYOclNtZ3a3mYPhDA=="}]},"_npmUser":{"name":"ambrosiocompany","email":"gestaoambrosio@outlook.com"},"directories":{},"maintainers":[{"name":"ambrosiocompany","email":"gestaoambrosio@outlook.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/cli_1.0.0_1775607020317_0.5842543248436876"},"_hasShrinkwrap":false}},"time":{"created":"2026-04-08T00:10:20.260Z","1.0.0":"2026-04-08T00:10:20.457Z","modified":"2026-04-08T00:10:20.691Z"},"maintainers":[{"name":"ambrosiocompany","email":"gestaoambrosio@outlook.com"}],"description":"Official CLI for the Biological Sovereignty Protocol — manage BEOs, IEOs, consent, and health data from the terminal","homepage":"https://biologicalsovereigntyprotocol.com","keywords":["bsp","biological-sovereignty","cli","health-data","arweave","longevity","lgpd","gdpr"],"repository":{"type":"git","url":"git+https://github.com/Biological-Sovereignty-Protocol/bsp-cli.git"},"author":{"name":"Ambrósio Institute"},"bugs":{"url":"https://github.com/Biological-Sovereignty-Protocol/bsp-cli/issues"},"license":"Apache-2.0","readme":"[![npm version](https://img.shields.io/npm/v/@bsp/cli.svg)](https://www.npmjs.com/package/@bsp/cli)\n[![License](https://img.shields.io/badge/license-Apache%202.0-blue.svg)](LICENSE)\n[![TypeScript](https://img.shields.io/badge/TypeScript-5.x-blue.svg)](https://www.typescriptlang.org)\n[![Node.js](https://img.shields.io/badge/Node.js-%3E%3D18-green.svg)](https://nodejs.org)\n[![BSP](https://img.shields.io/badge/BSP-v0.2_Protocol-0066CC.svg)](https://biologicalsovereigntyprotocol.com)\n[![Built on Arweave](https://img.shields.io/badge/Permanent_Storage-Arweave-222222.svg)](https://arweave.org)\n\n<br />\n\n# @bsp/cli\n\nOfficial command-line interface for the [Biological Sovereignty Protocol](https://biologicalsovereigntyprotocol.com).\n\nCreate and manage biological identities (BEOs), institutional entities (IEOs), consent tokens, and health data — directly from the terminal. 22 commands covering the full protocol lifecycle.\n\n> Your biology, your keys, your terminal.\n\n---\n\n## Installation\n\n```bash\nnpm install -g @bsp/cli\n```\n\nOr run without installing:\n\n```bash\nnpx @bsp/cli --help\n```\n\nRequires Node.js >= 18.\n\n---\n\n## Quick Start\n\n```bash\n# 1. Configure the network\nbsp config set network testnet\n\n# 2. Create your biological identity\nbsp create andre.bsp\n# ✓ BEO created: andre.bsp\n#\n#   Domain       andre.bsp\n#   BEO ID       tx_abc123...\n#   Public Key   7f3a8b2c...\n#\n# ⚠️ CRITICAL — Store these securely. They are shown ONCE.\n#\n#   Private Key: 4e8f...128chars...\n#   Seed:        a7b3...64chars...\n\n# 3. Save your private key\nbsp config set private-key 4e8f...\n\n# 4. Verify on-chain\nbsp resolve andre.bsp\n# ✓ BEO found: andre.bsp\n#\n#   BEO ID       tx_abc123...\n#   Status       ACTIVE\n#   Key Version  1\n#   Created      2026-04-07T20:00:00Z\n```\n\n---\n\n## Commands\n\n### Identity (BEO)\n\n| Command | Description |\n|---------|-------------|\n| `bsp create <domain>` | Create a new BEO — generates Ed25519 keypair locally |\n| `bsp resolve <domain>` | Look up a BEO by its .bsp domain |\n| `bsp lock <beoId>` | Emergency lock — freezes all operations |\n| `bsp unlock <beoId>` | Unlock a locked BEO |\n| `bsp rotate-key <beoId>` | Rotate Ed25519 key (generates new keypair) |\n| `bsp destroy <beoId> --confirm` | **IRREVERSIBLE** — Permanent erasure (LGPD/GDPR) |\n\n#### Destroy — Sovereign Cryptographic Erasure\n\n```bash\nbsp destroy <beoId> --confirm\n```\n\nWhat happens on-chain:\n1. Public key nullified (cryptographic erasure)\n2. All ConsentTokens revoked\n3. `.bsp` domain released\n4. Recovery config wiped\n5. Status set to `DESTROYED` — no undo\n\nThis implements LGPD Art. 18 (Brazil) and GDPR Art. 17 (EU) right to erasure at the protocol level.\n\n---\n\n### Consent\n\n| Command | Description |\n|---------|-------------|\n| `bsp consent grant <beoId> <ieoId>` | Issue a ConsentToken to an institution |\n| `bsp consent revoke <tokenId> <beoId>` | Revoke a single token |\n| `bsp consent revoke-all <beoId> --confirm` | Emergency — revoke ALL tokens |\n| `bsp consent verify <tokenId>` | Check if a token is valid |\n| `bsp consent list <domain>` | List all tokens for a BEO |\n\n#### Grant consent with scope\n\n```bash\nbsp consent grant <beoId> <ieoId> \\\n  --intents SUBMIT_RECORD,READ_RECORDS \\\n  --categories BSP-LA,BSP-GL,BSP-HM \\\n  --days 365\n```\n\n| Flag | Required | Description |\n|------|----------|-------------|\n| `--intents <list>` | Yes | Comma-separated: `SUBMIT_RECORD`, `READ_RECORDS`, `ANALYZE_VITALITY`, `REQUEST_SCORE`, `EXPORT_DATA`, `SYNC_PROTOCOL` |\n| `--categories <list>` | No | Comma-separated BSP categories (e.g. `BSP-LA,BSP-CV`) |\n| `--days <n>` | No | Expiration in days (default: permanent) |\n\n---\n\n### Institution (IEO)\n\n| Command | Description |\n|---------|-------------|\n| `bsp ieo create <domain>` | Register a new IEO on the protocol |\n| `bsp ieo get <ieoId>` | Get IEO details by UUID |\n| `bsp ieo list` | List IEOs with filters |\n| `bsp ieo lock <ieoId>` | Emergency lock |\n| `bsp ieo unlock <ieoId>` | Unlock |\n| `bsp ieo destroy <ieoId> --confirm` | **IRREVERSIBLE** — Destroy IEO |\n\n```bash\nbsp ieo create fleury.bsp --type LAB --name \"Fleury Laboratórios\"\nbsp ieo list --type LAB --status ACTIVE --cert ADVANCED\n```\n\nIEO types: `LAB`, `HOSPITAL`, `WEARABLE`, `PHYSICIAN`, `INSURER`, `RESEARCH`, `PLATFORM`\n\n---\n\n### Health Data (Exchange)\n\n| Command | Description |\n|---------|-------------|\n| `bsp records submit <beoId>` | Submit BioRecords from a JSON file |\n| `bsp records read <beoId>` | Read BioRecords with filters |\n| `bsp export <beoId>` | Sovereign data export (GDPR Art. 20 portability) |\n\n```bash\n# Submit lab results\nbsp records submit <beoId> --token <tokenId> --file results.json\n\n# Read with filters\nbsp records read <beoId> --token <tokenId> --categories BSP-LA,BSP-CV --json\n\n# Export everything in FHIR R4 format\nbsp export <beoId> --token <tokenId> --format FHIR_R4 > my-health-data.json\n```\n\nExport formats: `JSON`, `CSV`, `FHIR_R4`\n\n---\n\n### Configuration\n\n| Command | Description |\n|---------|-------------|\n| `bsp config set <key> <value>` | Set a config value |\n| `bsp config get <key>` | Read a config value |\n| `bsp config show` | Show all configuration |\n| `bsp config path` | Print config file path |\n\n```bash\nbsp config set registry https://api.biologicalsovereigntyprotocol.com\nbsp config set network testnet          # mainnet | testnet | local\nbsp config set private-key <hex>\nbsp config set ieo-domain fleury.bsp\n```\n\nConfig stored at `~/.bsp/config.json`.\n\n| Key | Default | Description |\n|-----|---------|-------------|\n| `registry` | `https://api.biologicalsovereigntyprotocol.com` | Registry API URL |\n| `network` | `testnet` | Target network |\n| `private-key` | — | Ed25519 private key (128 hex chars) |\n| `ieo-domain` | — | Your IEO domain (for institutional commands) |\n\n---\n\n## Architecture\n\n```\n┌──────────────┐    signed payload    ┌──────────────────┐    Arweave TX    ┌──────────┐\n│              │ ──────────────────→  │                  │ ──────────────→  │          │\n│   bsp CLI    │    Ed25519 sig       │  Registry API    │    pays gas      │ Arweave  │\n│   (local)    │                      │  (gasless relay)  │                  │ (on-chain)│\n│              │ ←──────────────────  │                  │ ←──────────────  │          │\n└──────────────┘    JSON response     └──────────────────┘    state read    └──────────┘\n       ↑\n       │ @bsp/sdk\n       │ Ed25519 signing\n       │ type definitions\n```\n\n- **Keys never leave your machine** — all cryptographic operations happen locally\n- **The relayer is a gas payer, not an authority** — it cannot forge or modify your actions\n- **Smart contracts verify every signature on-chain** — even a compromised relayer cannot cheat\n\n---\n\n## Complete Example — Lab Integration\n\n```bash\n# ── Institution setup (done once) ────────────────────────────────\nbsp ieo create sunrise-lab.bsp --type LAB --name \"Sunrise Diagnostics\"\n# Store the private key securely\nbsp config set private-key <lab-private-key>\nbsp config set ieo-domain sunrise-lab.bsp\n\n# ── Patient creates identity ─────────────────────────────────────\nbsp create andre.bsp\n# Patient stores their private key\n\n# ── Patient grants consent to the lab ────────────────────────────\nbsp config set private-key <patient-private-key>\nbsp consent grant <patientBeoId> <labIeoId> \\\n  --intents SUBMIT_RECORD,READ_RECORDS \\\n  --categories BSP-LA,BSP-GL,BSP-HM \\\n  --days 365\n\n# ── Lab submits results ──────────────────────────────────────────\nbsp config set private-key <lab-private-key>\nbsp records submit <patientBeoId> \\\n  --token <consentTokenId> \\\n  --file blood-test-results.json\n\n# ── Patient reads their data ─────────────────────────────────────\nbsp config set private-key <patient-private-key>\nbsp records read <patientBeoId> --token <consentTokenId> --json\n\n# ── Patient exports for another doctor ───────────────────────────\nbsp export <patientBeoId> --token <consentTokenId> --format FHIR_R4\n\n# ── Patient revokes access ───────────────────────────────────────\nbsp consent revoke <consentTokenId> <patientBeoId>\n\n# ── Emergency: lock everything ───────────────────────────────────\nbsp lock <patientBeoId>\nbsp consent revoke-all <patientBeoId> --confirm\n```\n\n---\n\n## Security\n\n| Property | Implementation |\n|----------|---------------|\n| **Key storage** | `~/.bsp/config.json` — local, never transmitted |\n| **Signing** | Ed25519 via `@bsp/sdk` (tweetnacl) — deterministic, auditable |\n| **Transport** | Only signed payloads cross the network |\n| **Replay protection** | Nonce (16+ chars) + timestamp (max 5 min) on every request |\n| **Destructive ops** | `--confirm` flag required — no accidental erasure |\n| **LGPD/GDPR** | `destroy` implements cryptographic erasure at protocol level |\n\n---\n\n## Error Handling\n\nThe CLI prints human-readable errors and exits with code 1 on failure:\n\n```\n✗ BEO not found\n✗ Invalid Ed25519 signature\n✗ nonce already used — replay detected\n✗ request timestamp is too old (max 5 minutes)\n✗ No private key configured. Run: bsp config set private-key <hex>\n```\n\n---\n\n## Related Packages\n\n| Package | Description |\n|---------|-------------|\n| [@bsp/sdk](https://github.com/Biological-Sovereignty-Protocol/bsp-sdk-typescript) | TypeScript SDK — programmatic access |\n| [bsp-sdk-python](https://github.com/Biological-Sovereignty-Protocol/bsp-sdk-python) | Python SDK |\n| [@bsp/mcp](https://github.com/Biological-Sovereignty-Protocol/bsp-mcp) | MCP server — connect AI agents to BSP |\n| [bsp-id-web](https://github.com/Biological-Sovereignty-Protocol/bsp-id-web) | Web identity app |\n| [bsp-spec](https://github.com/Biological-Sovereignty-Protocol/bsp-spec) | Protocol specification |\n| [bsp-docs](https://github.com/Biological-Sovereignty-Protocol/bsp-docs) | Documentation |\n\n---\n\n## Contributing\n\n```bash\ngit clone https://github.com/Biological-Sovereignty-Protocol/bsp-cli\ncd bsp-cli\nnpm install\nnpm run build\nnode dist/index.js --help\n```\n\n---\n\n## License\n\nApache 2.0 — [Ambrósio Institute](https://ambrosioinstitute.org)\n\nDocs: [biologicalsovereigntyprotocol.com/developers/cli](https://biologicalsovereigntyprotocol.com/developers/cli) · Protocol: [bsp-spec](https://github.com/Biological-Sovereignty-Protocol/bsp-spec)\n","readmeFilename":"README.md","_rev":"1-7938d06b449d607c830a65f0ca028523"}